On-prem · Air-gapped · Embedded AI

Firewall Configuration Analysisbuilt for the buyers who can't trust the cloud.

Delyan turns large firewall configurations into structured data, security findings and audit-ready reports on your own machine, with nothing leaving your network.

fw-core-01.cfg · FortiOS 7.4
Analysis complete
0%
Posture
Checks
0
Issues
0
Passed
0
Warnings
0
Device
58%
Network
41%
Objects
52%
Services
33%
Policies
39%
Single installer
Analysis in minutes, not hours
Zero telemetry
Verifiable by packet capture
Deterministic
The engine decides; AI explains
Security
AnalysisComplianceTraffic FlowPath TraceMulti-Tenancy
Operation
App-DiscoveryTopology MappingConfig ComparisonVisualizations
Management
PDFs, Sheets & PNGs ReportsAI Advisor ChatAudience-grade reports
Vendor coverage
  • Fortinet FortiGate
  • Palo Alto Networks
  • Cisco
  • Check Point
  • Juniper
01 · The problem
0%+

of firewall rules in mature enterprises become redundant, shadowed or permissive, each a silent path through the perimeter.

/01
Unowned legacy rules

Decade-old policies left by departed engineers (shadowed, redundant, permissive, expired or unused) that no one dares to touch.

/02
Cloud tools unfit for the buyer

Defence, finance and critical infrastructure cannot export configurations. SaaS analysers fail procurement and sovereignty review.

/03
Audit-cycle overhead

Weeks of manual spreadsheet preparation each quarter, producing screenshot evidence auditors routinely challenge.

02 · Our approach

One engine. Four layers. Zero cloud.

A single self-contained installer: one pass from raw config to auditor-ready evidence.

01
Parsing
Every object, rule and tunnel
02
Security analysis
Shadowed, redundant, permissive
03
Compliance
Regulation Frameworks
04
Dely AI Advisor
Answers that cite the rule
03 · Trust model

Deterministic by design.

Built for environments where a wrong verdict is unacceptable. Parsing, analysis and compliance are fixed, reviewable rules: the same input always yields the same verdict. No model sits in the path of a security decision.

Dely sits on top of those verified facts. She explains, investigates and accelerates, and never invents a verdict.

INTELLIGENCE LAYER
AI never decides
Dely: explains, investigates, accelerates

Natural-language Q&A, troubleshooting, search and audience-aware narratives. Every answer is badged Grounded to evidence or Unverified.

↓ reads verified facts via deterministic tools ↑
DETERMINISTIC ENGINE
The source of truth
Hard-coded parsing, analysis & compliance logic

Encoded as fixed, reviewable rules. No probabilistic guesswork on a security decision.

04 · Capabilities

Operational from day one.

Policy analysis
Compliance Radar
Dely AI Advisor
Reporting
Air-gapped
Visual evidence
D
Dely
Configuration Advisor
offline
Which rules allow inbound RDP from any source?
Two policies permit RDP (3389) from any: policy id 47 (root) and id 112 (DMZ). Policy 112 is shadowed by 47.
GROUNDED TO EVIDENCEsource: policy id 47, 112 · service RDP/3389
Users in VLAN 100 can't reach 10.20.5.10.
Route exists. Traffic is denied by deny id 39 before any allow applies.
GROUNDED TO EVIDENCEtrace: vlan100 → route → policy 39 (deny)
Ask about your configuration…
05 · Dely AI Advisor

Meet Dely, your configuration advisor.

Cited answers
Every fact traces to a rule, object or line.
AI Lookup Tools
Dely fetches verified facts; she never invents them.
Troubleshooter
Traces interfaces, routes, policies and NAT to the blocker.
Runs fully offline
Embedded model. No cloud calls, no telemetry.
06 · Built for the region

Built for Saudi defence and banking.

Where sensitive configurations never leave the network.

NCA ECCSAMA CSFCIS BenchmarksPCI-DSSNIST 800-53NIST 800-41NIST 800-171GDPRHIPPASTIGSWIFTNIS2SOC2ISO/IEC 27001DORASOXNERC CIPECBGLBABasel-IIASD ISMMAS TRMBSI 200LGDPHKMA
Air-gapped by design

One self-contained installer. No external runtime, no updates over the wire, no telemetry. Verifiable by packet capture.

Full data sovereignty

No cloud, no phone-home. Configurations, analysis and reports stay on your own servers, inside your perimeter.

DIFFERENTIATOR
Static-config-only analysis

Works from the configuration file alone: no SPAN ports or live taps. Operates where competitors can't.

Online & offline parsingAir-gappedDely AI AdvisorConfig ComparisonTopology mappingApp-DiscoveryMulti-Tenancy
Regional alignment

NCA ECC and SAMA CSF built in, for Saudi defence and banking.

07 · Why Delyan

Differentiation by capability.

  • Deployment model
    TypicalCloud or hybrid; phones home
    Delyan: On-premises; fully air-gapped
  • Trust model
    TypicalAI generates security verdicts
    Delyan: Deterministic engine; AI explains, never decides
  • Setup time
    Typical8–12 week integration project
    Delyan: Single installer; analysis in minutes
  • Compliance evidence
    TypicalManual spreadsheets & screenshots
    Delyan: Benchmark report, audit-ready
  • Reporting
    TypicalOne template for all audiences
    Delyan: Audience-aware: board, exec, SOC, PMs
  • Visual evidence
    TypicalStatic rule lists
    Delyan: Traffic-flow, network topology, zone topology, policy graph
  • Sovereignty
    TypicalData leaves your environment
    Delyan: Nothing leaves your servers, ever
08 · Engagement

From first call to proven value.

no-cost pilot · you keep all findings
Let's talk

Ready to see it in your environment?

A 30-minute discovery call, a 45-minute technical demo, then a two-week focused pilot on your own servers.

© 2025 Delyan · delyan.net