Live engine · 150 deterministic checks · 0 network connections
Continuous network security assurance

Every config, every vendor,
measuredcited to the linefixed and verifieddefensible in audit.

Rakasec reads the running-config of every switch, router and firewall you own — sixteen platforms — and tells you what an auditor would: which control fails, on which line, on which device, and what happens if nobody fixes it. Then it can fix it, prove the fix took, and roll back if it didn't.

Air-gapped & agentless 16 platforms + cloud posture Evidence-cited, zero false positives*
rakasec · edge-01 · Cisco IOS-XE 17.9
CGT-CHK-004 telnet · CIS 2.1.1 · NIST AC-17(2) · PCI 2.2.7CGT-CHK-010 default SNMP · PCI 2.2.2CGT-CHK-P05 any/any · NIST SC-7(5)
0
Deterministic checks
0
Vendor platforms + cloud
0%
False positives*
0
Zero-trust capabilities scored

Audits configuration across sixteen enterprise network platforms — and cloud / SASE posture

Cisco IOS-XECisco NX-OSCisco IOS-XRCisco ASA Juniper JunosArista EOSPalo Alto PAN-OSFortinet FortiOS Aruba AOS-CXHuawei VRPHPE ComwareMikroTik RouterOS Check Point GaiaSonicWall SonicOSExtreme EXOSUbiquiti EdgeOS ZscalerMerakiAWSAzureCisco ACICatalyst Center
Watch it work

Measured, not surveyed. Fixed, then proven.

Two things no spreadsheet audit does: Rakasec rebuilds each device's routing and policy from its config and measures which segments can reach which; and when you approve a fix, it pushes it, re-pulls the config, and only marks it fixed if the finding is actually gone.

Lateral reachability — measured from configs

Staff
Guest
Servers
Mgmt
Staff →
·
445
443
22
Guest →
445
·
3389
22
Servers →
445
any
·
22
Mgmt →
22
any
22
·
reachable on a lateral-movement portblocked by a rule the engine can cite
12 of 12 segment pairs reachable · lateral index 100 · risk index 100. Every red cell names the interface, the missing ACL, and the line to add.

Remediation push — verified, or rolled back

change #2 · edge-01
1

Stage from the finding

The engine's diff becomes exact commands, with the sub-mode context taken from the evidence.

line vty 0 4
no transport input telnet ssh
transport input ssh
2

Pre-flight on the stored config

Simulated and re-audited offline before anyone approves.

closes the finding · no new findings · 26 → 25
3

Four-eyes approval

The approver cannot be the requester. Dry run shows exactly what will be sent.

4

Push over SSH, save

Pinned host key. Output kept on the request.

sent 3 lines in 0.45s · write memory [OK]
5

Re-pull, re-audit

Finding gone → verified. Still there → rollback sent, request says so.

verify: re-pulled — finding is gone
How it works

From running-config to a signed-off control, without a questionnaire.

01

Collect

02

Audit

03

Measure

04

Remediate

05

Prove

    Why Rakasec

    Compliance you can defend in an audit.

    Most config reviews are a spreadsheet and a long weekend. Rakasec makes them continuous, evidence-backed, and repeatable.

    Continuous compliance

    Re-audit on every change and get real-time visibility into where the fleet drifts out of policy — before an auditor finds it.

    Evidence, not opinions

    Every finding cites the exact offending lines and the control it violates. Deterministic — the same config always yields the same result.

    AI-assisted remediation

    Sentinel drafts the fix per platform with rollback, clusters related findings by root cause, and briefs leadership in plain English.

    The engine

    Deterministic audit, zero network access

    • You send configs — plain-text exports, one file per device or a whole folder. No credentials, ever.
    • 150 deterministic checks run across the management plane, AAA, crypto, SNMP, routing integrity, logging and software lifecycle.
    • Known-CVE & end-of-life flagging surfaces devices running unsupported code.
    Devices assessed17
    Checks executed150 / device
    Critical findings2
    End-of-life images3
    Network connections made0
    Sentinel AI

    An analyst layer that explains, never decides

    • Executive briefing — a leadership-ready summary of posture and top risks.
    • Ask questions in plain English about your own results.
    • Root-cause clustering groups related findings so systemic issues are fixed once.
    Which devices still allow Telnet?
    Two: fw-edge-01 and core-tlv. Both violate CIS 1.2.1 (critical). Want the remediation diff for each?
    Summarize posture for the CISO.
    Fleet at 84/100, up 4 this week. Risk concentrates at the edge — 2 criticals, both insecure management access. Fixing them raises posture to ~90.
    Software verification

    Verify every device runs safe, supported software

    • Baseline check — each running release is verified against a maintained baseline: recommended, minimum-safe, and end-of-life.
    • CVE correlation — versions are matched to known vulnerabilities, so you see exploitable exposure, not just "out of date."
    • Exact upgrade path — the target release per platform, and why, ready for your maintenance window.
    DeviceRunningStatusTarget
    core-iad-01IOS-XE 17.9.3Below-min17.12.4
    leaf-pdx-07NX-OS 9.3(2)End-of-life10.3(4a)
    fw-fra-01PAN-OS 11.1.3Recommended
    Threat coverage

    The misconfigurations attackers actually exploit.

    Rakasec maps every finding to the attack it enables and the control it breaks — the management plane, weak crypto, broken access control, routing integrity, segmentation, and known-CVE exposure.

    Exposed management plane

    Telnet, cleartext HTTP, SSHv1, and management reachable from 0.0.0.0/0 — the fastest path to full device takeover.

    CIS 1.2NIST AC-17DISA STIG

    Weak & legacy cryptography

    SNMP v1/v2c communities, default "public/private", weak SSH ciphers & key exchange, no SNMPv3 auth+priv.

    PCI 2.2.2NIST SC-8CIS 2.8

    Broken access control

    Local-only accounts, no centralized AAA/TACACS+, missing least-privilege and VTY access-class ACLs.

    NIST AC-2NIST AC-6CIS 1.3

    Routing & control-plane integrity

    Unauthenticated OSPF/BGP adjacencies, missing control-plane policing (CoPP), IP source-routing enabled.

    NIST SC-5NIST SC-8

    Firewall segmentation gaps

    any/any/allow rules, permissive zones, and allow policies with no threat-prevention or SSL inspection.

    NIST SC-7PCI 1.2

    Known-CVE & end-of-life exposure

    Running releases correlated to known CVEs and the CISA KEV catalog, plus end-of-life images a config scan alone misses.

    NIST RA-5CISA KEV

    Logging & visibility gaps

    No remote syslog/NetFlow export and no NTP source — the blind spots that make an incident impossible to reconstruct.

    NIST AU-6NIST AU-8

    Cloud & SASE posture

    Zscaler, AWS, Azure, Meraki and Strata — open security groups, missing MFA, permissive policy — in the same report.

    CIS CloudNIST AC-3

    NAC & zero-trust readiness

    Access ports with no 802.1X, or NAC failing open in monitor mode — Rakasec proposes the zero-trust design: deny-by-default, per-identity VLAN/dACL/SGT, RADIUS CoA, east-west microsegmentation.

    NIST AC-4Zero TrustCMMC

    MPLS, multicast & route policy

    MPLS VRFs without route-targets (cross-VPN leak), PIM with no RP, and ACL / route-map / prefix-list hygiene — permit-any and accept-all filters that break segmentation.

    NIST SC-7SC-8

    Cisco ACI fabric & contracts

    APIC posture and any/permit-all contracts between EPGs — over-broad east-west policy that turns the fabric into a flat network.

    NIST SC-7ACI
    AI network-operations copilot

    Not just an auditor — a copilot for your network team.

    Rakasec reads your configs and reasons about them: it triages incidents, advises on designs, guards changes, and onboards devices — every answer grounded in the real config, so it's a true positive, not a guess.

    AI incident resolution

    Pull an incident from ServiceNow (or paste the symptoms) and Rakasec triages it against the device — likely causes, what to check, and the exact verification show-commands. Path-aware: it narrows "latency between rtr1 and rtr2" to the suspect hop.

    Design advisor

    Talk through a change — "route between me and my ISP", "segment PCI traffic", "set up MPLS VRFs" — and get design options tailored to the platform, with sample config and best practices.

    Change-window intelligence

    Before a change lands: blast-radius impact, a pre-flight "will this even apply?" check, ITSM validation, and alerts auto-muted for the device and its neighbours. Before/after diff surfaces only what the change actually broke.

    Zero-touch onboarding

    Onboard by vendor or auto-discovery. Test connection, pull the config, and get a first assessment — detected version and prioritized findings — in one guided flow. Credentials live in an encrypted vault, never typed inline.

    Beyond the checklist

    Advanced analysis, not just a config linter.

    Rakasec reasons about how the network actually behaves — reachability, drift, your own policy — well past pattern-matching for insecure keywords.

    Firewall path analysis

    Trace a flow hop-by-hop across the firewalls on its path — is it reachable, where is it blocked, and the exact rule to change. Deterministic, no packets sent.

    Configuration drift detection

    Snapshot every device and report the finding delta since last sweep — catch the risky change the moment it lands, not at the next audit.

    AI config review & golden-policy

    Describe a rule in plain English and Rakasec writes the regex or Lua. Or point it at a device — it reads your BGP/OSPF neighbours, ACLs, MPLS and NAC config and proposes the exact tests, each grounded in a real line.

    Change-window intelligence

    Before a change lands, the AI agent reads the rollout config, learns the affected neighbours and rates the blast radius. It validates your ITSM change number, mutes alerts for the device and its neighbours, and diffs the config before vs after — so only what the change actually broke ever pages you.

    CVE exposure mapping

    Correlates each device's platform and release to known CVEs, surfacing exploitable exposure a keyword-based config scan alone will always miss.

    Blast-radius scoring

    Findings are ranked by reach and role, not just severity — a critical on an internet-facing edge firewall outranks the same on an isolated lab switch.

    Air-gapped deployment

    Runs entirely on-prem inside your management VRF — bundled weights, no egress, no phone-home. FedRAMP-aligned for sovereign environments.

    Built for this decade

    Not another config-backup box with compliance bolted on.

    Legacy tools were built to archive configs and diff them. Rakasec is built to prove the network is secure — evidence-first, AI-native, and aware of the cloud your traffic actually crosses.

    Legacy config tools

    Backup-era, on-box scripting

    • Hand-write every compliance rule in regex or Lua
    • Keyword pattern-matching — false positives you can't defend
    • No CVE / end-of-life correlation
    • Device configs only — blind to Zscaler, AWS, Azure, Meraki
    • Backup-first; the audit is an afterthought

    Rakasec

    Evidence-first, AI-native, cloud-aware

    • Describe a check in plain English — Rakasec writes the rule (regex or Lua) for you
    • Deterministic, line-cited findings — 0% false positives on our validation suite
    • CVE + end-of-life + blast-radius scoring, not just keyword hits
    • Cloud & SASE posture — Zscaler, AWS, Azure, Meraki, ACI, Strata in the same report
    • Audit-first, air-gap ready, mapped to the frameworks your auditor already uses
    Alerting & workflow

    Only verified true positives reach your on-call.

    Rakasec re-evaluates every new finding and confirms it's a genuine true positive before it pages anyone. And during a maintenance window, alerts for the device under change — and its neighbours — are muted automatically, so planned work never pages on-call. Verified findings route straight into the tools you already run.

    1 New finding detected on a sweep
    2 Auto re-check & verify — confirm it's a true positive
    Verified → alert fires with evidence, control & remediation

    False positives and accepted-risk suppressions are filtered out before routing — no noise, no alert fatigue, an on-call queue you can trust.

    Routes verified findings to
    ServiceNowPagerDutyOpsgenie Grafana OnCallSlackMicrosoft Teams JiraEmail / SMTPWebhook
    Alert precisionverified true-positive only
    Payloadfinding + evidence + control + fix
    Severity routingcritical → page · else → ticket
    Operations & platform

    Enterprise-ready from day one — not just an engine.

    Everything an operations team needs to run Rakasec in production: access control, identity, reporting, team dashboards, and lifecycle management — on-prem, air-gap ready.

    RBAC & enterprise SSO

    Admin / Read-Write / Read-Only roles, per-user scoping, and directory group→role mapping. Authenticate with SAML, OIDC, TACACS+ or RADIUS — each with a built-in test-connection.

    Reports — predefined & custom

    Executive summary, full compliance, version-impact KPI and audit trail out of the box — or build your own by section and severity. Export PDF / CSV / JSON, or email to stakeholders.

    Team dashboards

    Per-user, drag-to-arrange widgets with role-based views — NOC, Engineering and Management — switchable from a dropdown so every team sees the signal that matters to them.

    Encrypted credential vault

    Device credentials live in a passphrase-locked, in-memory vault — devices reference them by name, never inline. Nothing sensitive is written to disk or persisted in the browser.

    Lifecycle & system management

    Backup-before-upgrade with release notes, NTP, and encrypted backup to S3 / SFTP / NFS / Azure / GCS — each with test-connection. Export appliance telemetry to SolarWinds, PRTG or Prometheus, read-only.

    Non-intrusive collection

    Rate-limited, off-hours-aware config collection that never overloads a device or its control plane — with an immutable audit trail of who changed what, exportable for compliance.

    Standards mapping

    Every finding maps to a control.

    Hand the report to your auditors as-is. Four framework packs are scored from findings — and each says exactly which controls it covers, because a config cannot decide a procedural control.

    CISBenchmarks · pack
    NIST800-53 Rev 5 · pack
    PCI DSSv4.0 · pack
    DISASTIG · SRG families
    CISAZTMM 2.0 · zero trust
    NISTSP 800-207 · zero trust
    CISAKEV · exposure
    NVDCVE 2.0 · exposure
    Engagements

    Start with one audit. Grow into continuous assurance.

    From a one-time assessment to always-on, air-gapped deployment. Tell us about your network and we'll scope it with you.

    Spot assessment

    Send us your configs — we return a full, auditor-ready report with prioritized remediation. Nothing to deploy.

    Continuous assurance

    Scheduled re-audit, drift alerting and change-window intelligence across the whole fleet.

    On-prem / sovereign

    Air-gapped appliance inside your management VRF — no egress, no phone-home, FedRAMP-aligned.

    Where it stands

    Against the ways this gets done today.

    We'd rather you compare than take our word. The incumbents are good at what they do; this is where the lines fall.

    CapabilityRakasecConfig backup & compliance suitesSpreadsheet / consultant auditZero-trust questionnaires
    Findings cited to the exact line, with a measured false-positive rate 0% FP on a published ground-truth corpus*partialrule hits; FP rate not publishedmanualone weekend, one auditor's eyes
    Lateral reachability measured from configs, per segment pair 16 platforms, undetermined is never called safeself-reported
    Zero-trust readiness scored on fleet coverage, not "configured somewhere" 31 capabilities, CISA ZTMM pillarsopinionsurvey
    Remediation push with pre-flight, four-eyes, re-audit and rollback off by default; never marks fixed on trustpush, no verify
    Framework packs scored from findings (CIS · NIST 800-53 · PCI DSS · STIG) says exactly what it coversoften the strongest suitmapped by handself-attested
    Fleet CVE exposure from CISA KEV, NVD and vendor PSIRTs, with alerting 30-minute refresh, KEV always pagessome
    Air-gapped, agentless, no LLM in the audit pathvaries
    Hundreds of device types, decades of field validation 16 platforms, and a per-platform validation ledger you run yourselftheir home ground
    AI that explains — grounded to engine facts, cites every claim engine decides, model narratesemerging

    What we will say

    • 0% false positives, 100% recall on our ground-truth corpus — reproducible with cogent validate.
    • Every finding cites the line, the control, and the blast radius.
    • Reachability is computed, and "undetermined" is reported as such, never as safe.
    • A fix is only "verified" after a re-pull shows the finding gone.

    What we won't

    • That a pack score means you're "compliant with CIS" — it covers what a config can decide.
    • That we support your platform until a real pull of it succeeded on your appliance — the ledger says which.
    • That an AI reviewed your network — the engine did; the AI only explains it.
    • That nobody can beat it.

    See what an auditor would — before they do.

    Tell us about your network and we'll scope an assessment with you. Start with a free audit of five devices — no cost, no obligation.

    Offline analysis · configs deleted after delivery · NDA available on request