Security Posture

Security Posture: the CIS benchmark scanner for Microsoft 365, Entra ID, Azure and AWS Every check names what it read.

Agentless, certificate-based, read-only scans of Microsoft 365, Entra ID, Azure and AWS, evaluated against the CIS benchmark pinned to its published version. Findings arrive with severity, context and the remediation steps, and a scan log that says what was read and what was not.

A check we could not read is unanswered, never passed.

Start a read-only scan How it works

One Scanner, Any Size Team

The scanner is the same for every customer, and so is the permission list. What changes is how many connections you run and who reads the reports, not what gets read.

Small Business

1-50 employees

No security team. One connection, one read-only scan, findings written in plain language with the fix beside each one.

One read-only connection
Plain-language findings with the fix
CIS benchmark checks on a schedule
Built for a team that reads the report itself.

Mid-Market

50-500 employees

An IT team stretched thin. The scan does the reading; the action matrix tells the team what to fix first and the executive report tells leadership why.

Full technical findings, 770 controls
Prioritized action matrix
Executive reports that cite the record
Built for a team that assigns the work on Monday.

Enterprise

500+ employees

A security team with many tenants and accounts. Every connection scans on its own schedule and keeps its own records, and every unanswered check is listed by name.

Many connections per organization
Per-connection schedules and records
Dedicated advisory access
Built for a team that already has a tool for everything else.

What a Scan Gives You

Security Posture Across Four Clouds

Cloud security posture management for Microsoft 365, Entra ID, Azure and AWS: scheduled, read-only detection of misconfigurations against the CIS benchmark pinned to its published version.

Findings in Context

Every finding carries the setting that produced it, the source that was read, and how it connects to neighbouring controls, so the fix goes to the cause.

Scan Log

Every source that was read, and every source that could not be, is written to the log and kept with the record. Unanswered is a verdict; it is never folded into a pass.

Scheduled Scanning

Daily, weekly or monthly, per connection, in your timezone. Daylight-saving changes are handled; the scan runs at the hour you chose.

Every Scan Kept

Each run writes its own record and its own scan log. Trend views compare records, not screenshots, so a fixed control shows the date it was fixed.

Severity and Remediation

Findings sorted by severity, grouped by workload, each with step-by-step remediation. Fixed controls resolve on the next scan; the record keeps the history.

Connect Once. Scan on a Schedule.

01

Connect

Create an App Registration in your tenant and upload the public key we give you. Access is certificate-based; there is no password to store. AWS connects with a read-only auditor role you create.

02

Read

The scanner reads configuration through the vendor APIs. No agents, no firewall rules, no mail, files or messages. Every source it reads, and every source it cannot, goes into the scan log.

03

Evaluate

Each control in the pinned CIS benchmark is evaluated from the sources it declares. A control whose sources were read gets pass or fail. A control whose sources were not read gets unanswered.

04

Remediate

Every finding carries severity, the setting that produced it, and step-by-step remediation. Fixed controls resolve on the next scan; the record keeps the history.

What the Record Looks Like

Illustrative animation, not a customer result.

Security Posture History LAST 6 MONTHS
Jul Aug Sep Oct Nov Dec Jan
87 +23% from baseline
Controls Evaluated
0
Next scan in 4h 23m
Active Findings
0
3 Critical
12 High
47 Medium

Four Clouds, One Record Base

Each platform has its own scanner and its own pinned benchmark. Coverage is declared per connection, per scan. GCP is not scanned today; it is next, not coming soon.

Microsoft 365

Mail flow, sharing, collaboration and device policy read from the tenant, evaluated against the pinned CIS Microsoft 365 benchmark.

Exchange Online mail flow and forwarding
SharePoint and OneDrive sharing
Teams policies
Purview, data governance and Intune
CIS Microsoft 365 v6.0.1, 185 controls

Microsoft Entra ID

Identity configuration read from the directory: who can sign in, from where, with what, and who holds the keys.

Conditional Access
Privileged roles and PIM
App registrations and consent
Guest access and break-glass account checks
Entra ID benchmark, 94 controls

Microsoft Azure

Subscription by subscription: identity, storage, network, logging and compute, evaluated against the pinned CIS Azure Foundations benchmark.

Identity and RBAC per subscription
Storage, Key Vault, databases
Network security groups
Defender plans, logging and compute
CIS Azure Foundations v5.0.0, 238 controls

Amazon Web Services

Every region in the organization, read with an auditor role you create, evaluated against the pinned CIS AWS Foundations benchmark.

IAM, credential report, password policy
CloudTrail and Config per region
S3 account and bucket settings
Monitoring and alarms
CIS AWS Foundations, 253 controls

Unanswered Is a Verdict

Each control declares the sources it needs. When those sources were read, the control gets pass or fail. When they were not, it is reported as unanswered, never as passed: the source is named, the count is shown, and the line is kept with the record. Your auditor and your carrier see the same line you see.

770
Controls, Four Clouds
4
Scanners, One Record Base
3
CIS Benchmarks, Version Pinned
1
Scan Log per Run
Identity Layer
Users Groups Service Principals MFA Status
Access Layer
Permissions Roles Conditional Access
Data Layer
Encryption Sharing Purview
Benchmark Layer
CIS M365 v6.0.1 CIS Azure v5.0.0 CIS AWS Entra ID

What One Record Contains

One scan, one record. The same record is read by the engineer who fixes things, the auditor who asks what was read, and the executive who wants the short version. None of them gets a different number.

Technical Report

Every finding with the setting, the source that was read, and the remediation steps

Executive Report

Kai drafts the summary for leadership and cites the record it was drafted from

Benchmark Mapping

Every finding carries its CIS control ID and the benchmark version it was evaluated against

Trend View

Records compared, not screenshots; a fixed control shows the date it was fixed

Action Matrix

Findings sorted by severity and grouped by workload, ready to assign

Unanswered List

Checks whose sources could not be read, listed by name, not folded into a total

Remediation Steps

Step-by-step fixes per finding; the next scan confirms whether they held

Scan Log

Every source read and every source that could not be, kept with the record

Executive Reports
That Cite the Record

Kai drafts the executive report from the record, not from a template. Every statement points to the control it came from, and the unanswered checks are named rather than rounded away.

Score with Its Caveat

A score per connection, with the unanswered count shown beside it

Progress Across Records

Record-to-record comparison; a fixed control shows the date it was fixed

Plain Language, Cited

Short enough for a board, and every line traces back to a control

EXECUTIVE SECURITY REPORT Illustrative
76 SCORE
Identity Security Strong
Data Protection Moderate
Access Control Strong
Unanswered 12 checks
Recommended Actions
P1 Enable MFA for all admin accounts 1 week
P2 Review external sharing policies 2 weeks
P3 Implement Conditional Access 1 month

See How One Setting
Reaches Another

A finding rarely stands alone. Security Posture shows how an exposed resource, a role and a data store connect, so the fix goes where the exposure starts. Illustrative diagram, not a customer result.

Exposed resources and the setting behind them
How roles and data stores connect
Severity by what the chain reaches
Remediation at the first link
Internet
Gateway
VPC
EC2
IAM Role
S3 Bucket
Lambda
RDS
PII Exposed

See What Every Scan Reveals

Every scan writes its findings as it reads. Passed, failed and unanswered checks arrive with the workload they came from, and the log names the source behind each one.

770
Controls, four clouds
Minutes
For most tenants
SECURITY FEED LATEST
Public S3 bucket detected with sensitive data
AWS S3 • Critical
2s ago
MFA enforcement verified for all admin accounts
Entra ID • Passed
15s ago
Legacy authentication protocols still enabled
Exchange Online • Warning
32s ago
Unified audit log source could not be read: unanswered
Microsoft 365 • Unanswered
1m ago
Global admin without PIM activation found
Entra ID • Critical
2m ago
Conditional Access policies properly configured
Entra ID • Passed
3m ago
12 stale guest accounts need review
Entra ID • Warning
4m ago
DLP policies active for all SharePoint sites
SharePoint • Passed
5m ago
Public S3 bucket detected with sensitive data
AWS S3 • Critical
2s ago
MFA enforcement verified for all admin accounts
Entra ID • Passed
15s ago
Legacy authentication protocols still enabled
Exchange Online • Warning
32s ago
Unified audit log source could not be read: unanswered
Microsoft 365 • Unanswered
1m ago
Global admin without PIM activation found
Entra ID • Critical
2m ago
Conditional Access policies properly configured
Entra ID • Passed
3m ago
12 stale guest accounts need review
Entra ID • Warning
4m ago
DLP policies active for all SharePoint sites
SharePoint • Passed
5m ago

Three Reports. Three Audiences.

Three outputs from one scan: for the people who fix things, the people who ask what was read, and the people who want the short version.

Excel

Action Matrix

A prioritized list for the people who will fix things. Sorted by severity, grouped by workload, ready to assign.

Built for Security Engineers
PDF

Technical Report

Every finding with the setting, the source that was read, and the remediation steps. Unanswered checks are listed by name, not folded into a total.

Built for Compliance & Audit
Kai

Executive Report

An AI-drafted summary for leadership. It cites the record it was drafted from, and it says which controls were unanswered rather than rounding them away.

Built for CxO & Board

The Cost of Doing This by Hand

What a yearly manual assessment cycle costs a team, against a scanner that runs on a schedule and keeps every record.

Traditional Approach

Annual cost for manual assessments
Cloud Security Engineer$130,000
Compliance Analyst$92,000
vCISO / Consultant (Retainer)$96,000
Security Tools & Licenses$45,000
Training & Certifications$12,000
Total Annual Cost $375,000

With SecValley

The scanner, on a schedule, with the records kept
770 controls across four clouds
Microsoft 365, Entra ID, Azure and AWS
Kai executive report, cited to the record
Three outputs per scan (Excel, PDF, Kai)
Scan log naming every source read
Scheduled scans, every record kept
A fraction of the cost No hiring. No training. No turnover.

Straight Answers

Is it really agentless?

Yes. Nothing is installed in your tenant or on your endpoints. The scanner authenticates with a certificate to an App Registration you created, or to an AWS role you created, and reads configuration through the vendor APIs.

What permissions does it need?

Read-only Graph and management permissions for Microsoft clouds; a read-only auditor role for AWS. No mailbox, file or message content is read. The exact permission list is shown during setup and is the same for every customer.

Do you store our data?

We store the configuration record each scan produces and the scan log that goes with it. We do not store mail, files or messages, because we never read them. Retention terms are in the DPA.

How long does a scan take?

Minutes for most tenants. Large Azure estates with many subscriptions and AWS organizations with many regions take longer; the scan log shows progress per section.

Can I revoke access at any time?

Yes. Remove the App Registration or the AWS role. The next scheduled scan will fail to read and will say so.

Start With One Connection

Connect a tenant, run one read-only scan, read the log. If it reads nothing you did not expect, keep going. Or ask for a walkthrough first.

  • Read-only, certificate-based access you can revoke
  • Your actual environment, not a sample
  • No commitment required

We respect your privacy. No spam, ever.