Agentless, certificate-based, read-only scans of Microsoft 365, Entra ID, Azure and AWS, evaluated against the CIS benchmark pinned to its published version. Findings arrive with severity, context and the remediation steps, and a scan log that says what was read and what was not.
A check we could not read is unanswered, never passed.
Built For You
The scanner is the same for every customer, and so is the permission list. What changes is how many connections you run and who reads the reports, not what gets read.
No security team. One connection, one read-only scan, findings written in plain language with the fix beside each one.
An IT team stretched thin. The scan does the reading; the action matrix tells the team what to fix first and the executive report tells leadership why.
A security team with many tenants and accounts. Every connection scans on its own schedule and keeps its own records, and every unanswered check is listed by name.
Capabilities
Cloud security posture management for Microsoft 365, Entra ID, Azure and AWS: scheduled, read-only detection of misconfigurations against the CIS benchmark pinned to its published version.
Every finding carries the setting that produced it, the source that was read, and how it connects to neighbouring controls, so the fix goes to the cause.
Every source that was read, and every source that could not be, is written to the log and kept with the record. Unanswered is a verdict; it is never folded into a pass.
Daily, weekly or monthly, per connection, in your timezone. Daylight-saving changes are handled; the scan runs at the hour you chose.
Each run writes its own record and its own scan log. Trend views compare records, not screenshots, so a fixed control shows the date it was fixed.
Findings sorted by severity, grouped by workload, each with step-by-step remediation. Fixed controls resolve on the next scan; the record keeps the history.
Process
Create an App Registration in your tenant and upload the public key we give you. Access is certificate-based; there is no password to store. AWS connects with a read-only auditor role you create.
The scanner reads configuration through the vendor APIs. No agents, no firewall rules, no mail, files or messages. Every source it reads, and every source it cannot, goes into the scan log.
Each control in the pinned CIS benchmark is evaluated from the sources it declares. A control whose sources were read gets pass or fail. A control whose sources were not read gets unanswered.
Every finding carries severity, the setting that produced it, and step-by-step remediation. Fixed controls resolve on the next scan; the record keeps the history.
Dashboard
Illustrative animation, not a customer result.
Platform Coverage
Each platform has its own scanner and its own pinned benchmark. Coverage is declared per connection, per scan. GCP is not scanned today; it is next, not coming soon.
Mail flow, sharing, collaboration and device policy read from the tenant, evaluated against the pinned CIS Microsoft 365 benchmark.
Identity configuration read from the directory: who can sign in, from where, with what, and who holds the keys.
Subscription by subscription: identity, storage, network, logging and compute, evaluated against the pinned CIS Azure Foundations benchmark.
Every region in the organization, read with an auditor role you create, evaluated against the pinned CIS AWS Foundations benchmark.
Each control declares the sources it needs. When those sources were read, the control gets pass or fail. When they were not, it is reported as unanswered, never as passed: the source is named, the count is shown, and the line is kept with the record. Your auditor and your carrier see the same line you see.
Reporting
One scan, one record. The same record is read by the engineer who fixes things, the auditor who asks what was read, and the executive who wants the short version. None of them gets a different number.
Every finding with the setting, the source that was read, and the remediation steps
Kai drafts the summary for leadership and cites the record it was drafted from
Every finding carries its CIS control ID and the benchmark version it was evaluated against
Records compared, not screenshots; a fixed control shows the date it was fixed
Findings sorted by severity and grouped by workload, ready to assign
Checks whose sources could not be read, listed by name, not folded into a total
Step-by-step fixes per finding; the next scan confirms whether they held
Every source read and every source that could not be, kept with the record
Kai drafts the executive report from the record, not from a template. Every statement points to the control it came from, and the unanswered checks are named rather than rounded away.
A score per connection, with the unanswered count shown beside it
Record-to-record comparison; a fixed control shows the date it was fixed
Short enough for a board, and every line traces back to a control
A finding rarely stands alone. Security Posture shows how an exposed resource, a role and a data store connect, so the fix goes where the exposure starts. Illustrative diagram, not a customer result.
Every scan writes its findings as it reads. Passed, failed and unanswered checks arrive with the workload they came from, and the log names the source behind each one.
From Scan to Boardroom
Three outputs from one scan: for the people who fix things, the people who ask what was read, and the people who want the short version.
A prioritized list for the people who will fix things. Sorted by severity, grouped by workload, ready to assign.
Every finding with the setting, the source that was read, and the remediation steps. Unanswered checks are listed by name, not folded into a total.
An AI-drafted summary for leadership. It cites the record it was drafted from, and it says which controls were unanswered rather than rounding them away.
Why It Makes Sense
What a yearly manual assessment cycle costs a team, against a scanner that runs on a schedule and keeps every record.
Questions
Yes. Nothing is installed in your tenant or on your endpoints. The scanner authenticates with a certificate to an App Registration you created, or to an AWS role you created, and reads configuration through the vendor APIs.
Read-only Graph and management permissions for Microsoft clouds; a read-only auditor role for AWS. No mailbox, file or message content is read. The exact permission list is shown during setup and is the same for every customer.
We store the configuration record each scan produces and the scan log that goes with it. We do not store mail, files or messages, because we never read them. Retention terms are in the DPA.
Minutes for most tenants. Large Azure estates with many subscriptions and AWS organizations with many regions take longer; the scan log shows progress per section.
Yes. Remove the App Registration or the AWS role. The next scheduled scan will fail to read and will say so.
Connect a tenant, run one read-only scan, read the log. If it reads nothing you did not expect, keep going. Or ask for a walkthrough first.
We'll reach out within one business day to schedule a time that works for you.