Controlio, Azure aboneliklerinizi salt-okunur erişimle bağımsız olarak değerlendirir; yanlış yapılandırmaları bulur, bulguları güvenlik çerçevelerine eşler ve yönetime ya da denetçiye sunabileceğiniz denetime hazır bir rapor üretir. Microsoft'un araçlarının yerine geçmez — onların söylediğini bağımsız olarak doğrular. Controlio independently assesses your Azure subscriptions with read-only access: it finds misconfigurations, maps findings to security frameworks and produces an audit-ready report you can hand to management or an auditor. It does not replace Microsoft's tools — it independently verifies what they say.
NET-01 İnternetten RDP/SSH açık NSG kurallarıNSG rules exposing RDP/SSH to the internet KRİTİKCRITICALKV-01 Key Vault purge protection kapalıKey Vault purge protection disabled YÜKSEKHIGHLOG-01 Activity Log export tanımsızNo Activity Log export configured YÜKSEKHIGHBCK-01 Backup korumasız üretim VM'leriProduction VMs without backup İNCELEREVIEWMCSB · NIST · ISO her bulgu çerçeve maddelerine eşlenirevery finding maps to framework clausesAzure size ne yapmanız gerektiğini söyleyen araçlar sunar. Ama üç soru açıkta kalır:Azure gives you tools that tell you what to do. Three questions remain open:
Platformun kendi kendine verdiği not, yönetim kurulu ve denetçi için tek başına kanıt değildir. Bağımsız üçüncü göz, aynı gerçeği dışarıdan doğrular.A score the platform gives itself is not, on its own, evidence for a board or an auditor. An independent third eye verifies the same facts from outside.
Ekran görüntüsü denetim kanıtı değildir. Tarihli, çerçeve-eşlemeli, tekrarlanabilir bir değerlendirme raporu gerekir — teknik ekip dışındakilerin de okuyabileceği dilde.A screenshot is not audit evidence. You need a dated, framework-mapped, repeatable assessment report — in language people outside the engineering team can read.
Öneri listeleri "olması gerekeni" söyler. Sizin onayladığınız yapılandırmayı bilen ve ondan sapmayı izleyen bir mekanizma ise Azure'da yoktur. TrueState tam bunu yapar.Recommendation lists describe an ideal. A mechanism that knows the configuration you approved and watches for drift from it does not exist in Azure. That is exactly what TrueState does.
Tek istediğimiz izin, Azure'un yerleşik Reader rolü. Yazma izni, data-plane erişimi ya da dizin izni hiçbir akışta istenmez. Ne gördüğümüz kadar ne göremediğimiz de tasarımın parçası:The only permission we ask for is Azure's built-in Reader role. No flow ever requests write access, data-plane access or directory permissions. What we cannot see is as much a part of the design as what we can:
Kimlik ve ayrıcalıklı erişimden ağ güvenliğine, veri korumadan loglamaya — her kontrol ya tam otomatik doğrulanır ya da dürüstçe "incelenmeli" olarak işaretlenir. Ölçemediğimiz hiçbir ayarı "izleniyor" göstermeyiz.From identity and privileged access to network security, data protection and logging — every check is either fully automated or honestly marked "review". We never present a setting we cannot measure as "monitored".
Owner yoğunluğu, wildcard custom roller, PIM kullanımı, blast-radius haritasıOwner density, wildcard custom roles, PIM usage, blast-radius map
İnternete açık yönetim ve veritabanı portları, NSG kapsaması, DDoS, BastionInternet-exposed management and database ports, NSG coverage, DDoS, Bastion
TLS asgari sürümleri, şifreleme, public erişim, soft delete ve purge protectionMinimum TLS versions, encryption, public access, soft delete and purge protection
Activity Log export, tanılama ayarları, flow log ve retention kapsamasıActivity Log export, diagnostic settings, flow log and retention coverage
VM/VMSS/AKS/ACR sertleştirmesi, emekli kaynak tipleri, boot diagnosticsVM/VMSS/AKS/ACR hardening, retired resource types, boot diagnostics
App Service, SQL, Cosmos, Redis, APIM, Service Bus, AI servisleri yapılandırmasıApp Service, SQL, Cosmos, Redis, APIM, Service Bus, AI services configuration
Backup kapsaması, vault güvenliği, tek-region riskiBackup coverage, vault security, single-region risk
Policy atamaları ve muafiyetleri, resource lock, MG hiyerarşisi, tag disipliniPolicy assignments and exemptions, resource locks, MG hierarchy, tag discipline
Her teknik bulgu ilgili çerçeve maddelerine eşlenir. Rapor "uyumlusunuz" demez — hangi teknik kontrolün hangi maddeye kanıt ürettiğini gösterir. Sertifikasyon iddiası değil, denetim kanıtı üretiriz.Every technical finding maps to the relevant framework clauses. The report never says "you are compliant" — it shows which technical control produces evidence for which clause. We produce audit evidence, not certification claims.
Defender for Cloud güçlü bir üründür ve açıksa bulgularını okuyup raporumuzda tek listede birleştiririz (çift kayıtları ayıklayarak). Controlio'nun eklediği katman farklı:Defender for Cloud is a strong product; when enabled, we read its findings and merge them into one deduplicated list in our report. The layer Controlio adds is different:
| Defender for Cloud | Controlio | |
|---|---|---|
| DeğerlendirenAssessed by | Platformun kendisiThe platform itself | Bağımsız üçüncü tarafIndependent third party |
| Çerçeve görünümü (ISO, NIST, DORA/NIS2)Framework view (ISO, NIST, DORA/NIS2) | Ücretli plan gerektirirRequires a paid plan | DahilIncluded |
| Onaylı yapılandırma baseline'ı + sapma izlemeApproved configuration baseline + drift monitoring | YokNot available | TrueState yol haritasıroadmap |
| Denetime hazır, paylaşılabilir raporAudit-ready, shareable report | Portal ekranları / workbook kurulumuPortal views / self-built workbooks | Tek tık PDF, yönetici özeti dahilOne-click PDF, executive summary included |
| Tehdit koruması, attack path, ajan tabanlı analizThreat protection, attack paths, agent-based analysis | Defender'ın alanıDefender's domain — öneririzwe recommend it | Bu alana girmeyizWe stay out of this space |
Microsoft hesabınızla giriş yapın veya Controlio uygulamasına management group / subscription kapsamında Reader rolü atayın. Ajan yok, script yok, yazma izni yok.Sign in with your Microsoft account, or assign the Reader role to the Controlio app at management-group or subscription scope. No agents, no scripts, no write permissions.
Azure Resource Graph üzerinden envanter çıkarılır, 120+ kontrol değerlendirilir, Defender bulguları (varsa) birleştirilir. Tipik ortamda tarama bir kahve molasından kısa sürer.Inventory is built via Azure Resource Graph, 120+ checks are evaluated and Defender findings (if any) are merged. In a typical environment the scan takes less than a coffee break.
Skor, kritik bulgular, çerçeve eşlemesi ve düzeltme rehberiyle denetime hazır rapor — yönetici özeti C-level diliyle, teknik ek mühendis diliyle.An audit-ready report with the score, critical findings, framework mapping and remediation guidance — the executive summary in C-level language, the technical annex in engineering language.
Tek seferlik salt-okunur değerlendirme: skor, bulgular, çerçeve eşlemesi, düzeltme rehberi, PDF rapor.A one-time read-only assessment: score, findings, framework mapping, remediation guidance, PDF report.
Onayladığınız yapılandırma dondurulur; sapmalar saatlik izlenir, kritik değişiklikler e-posta/Teams ile bildirilir. Onay disiplini çift kontrollüdür.The configuration you approve is frozen; drift is monitored hourly and critical changes are notified by email/Teams. Approval follows a dual-control discipline.
Azure Lighthouse ile çok-müşterili görünüm, müşteri karşılaştırması ve white-label raporlama.Multi-customer view via Azure Lighthouse, customer comparison and white-label reporting.
Defender'ı kapatmanızı asla önermeyiz; tam tersine bulgularını okur ve raporumuza katarız. Controlio'nun kattığı şey bağımsızlık ve kanıt: platformun kendi kendine verdiği notu dışarıdan doğrulayan, ücretli plan istemeden çerçeve eşlemesi sunan ve denetçiye verebileceğiniz tarihli rapor üreten bir katman.We would never suggest turning Defender off; on the contrary, we read its findings and include them in our report. What Controlio adds is independence and evidence: a layer that verifies the platform's self-assessment from outside, provides framework mapping without a paid plan, and produces a dated report you can hand to an auditor.
Yok. Tek istediğimiz rol Azure'un yerleşik Reader rolüdür ve bu rol yapısal olarak hiçbir değişiklik yapamaz, hiçbir secret değeri okuyamaz. İsteğe bağlı Key Vault son-kullanma kontrolü için ayrı ve açık onayla Key Vault Reader (yalnız metadata) eklenebilir — o da değer okuyamaz.None. The only role we request is Azure's built-in Reader, which structurally cannot make any change or read any secret value. For the optional Key Vault expiry check, Key Vault Reader (metadata only) can be added with separate, explicit consent — it cannot read values either.
Hayır ve hiçbir araç bunu diyemez. Uyum, süreçleri de kapsayan bir denetim sonucudur. Biz teknik kontrollerin hangi çerçeve maddelerine kanıt ürettiğini gösteririz; raporun kapağında bunun bir sertifikasyon denetimi olmadığı açıkça yazar.No — and no tool can say that. Compliance is the outcome of an audit that also covers processes. We show which framework clauses your technical controls produce evidence for; the report cover states explicitly that it is not a certification audit.
Yalnız güvenlik-anlamlı yapılandırma alanları ve bulgular saklanır; kaynak içerikleri, secret değerleri ve kişisel veriler hiçbir zaman toplanmaz. Veri minimizasyonu ürünün tasarım ilkesidir.Only security-relevant configuration fields and findings are stored; resource contents, secret values and personal data are never collected. Data minimisation is a design principle of the product.
Reader rol atamasını silerek — tek taraflı ve anında. Sonraki tarama erişimin kesildiğini dürüstçe raporlar ve durur; arka kapı ya da kalıcı bağımlılık yoktur.By deleting the Reader role assignment — unilaterally and instantly. The next scan honestly reports that access was cut and stops; there is no back door and no lasting dependency.
Erken erişim döneminde fiyatlandırmayı pilot kullanıcılarla birlikte şekillendiriyoruz. Erken erişime katılanlar lansman koşullarından öncelikli yararlanır.During early access we are shaping pricing together with pilot users. Early-access participants get priority on launch terms.
İlk değerlendirmenizi dakikalar içinde alın; yazma izni vermeden.Get your first assessment in minutes — without granting write access.