No installation, no disruption — your IT team is in control the whole way.
Your IT team approves access in two minutes via a standard Microsoft consent. We can only look — we never change anything. Nothing is installed, and access can be revoked at any time.
We check the holes attackers most often exploit — multi-factor authentication, old login routes, forgotten admin accounts and the like. In the order that matters most.
We start at baseline — what everyone should have in place. Once you have that under control, you move on to the next level. Three levels in total: Baseline, Strengthened, Advanced.
A decision-ready report: the biggest risks in business language, the trend over time — and the technical appendix for the auditor and the IT team.
If you're sitting with your IT partner or in-house IT team and want the full picture, the details live here.
We use a multi-tenant app registration in Microsoft Entra with read-only Microsoft Graph permissions. It lets us read users, conditional access policies, app registrations, devices, sign-in logs and licenses — not change anything.
Access is activated when a Global Administrator completes admin consent once. It can be revoked in Entra under Enterprise applications at any time.
Scanner code runs on Vercel (Frankfurt). Results land in a Supabase Postgres database in AWS eu-central-1 (Frankfurt). No data leaves the EU.
Graph tokens are fetched fresh per call via client credentials flow and not stored persistently.
Across all three levels (Baseline, Strengthened, Advanced) we check the fundamentals in the identity layer — multi-factor authentication, legacy login paths, privileged roles, app registrations and password policy. Each check describes what it measures, why it matters, and what concretely needs fixing.
The Baseline level is the core today and covers the most important risks. Strengthened and Advanced are expanded continuously as the threat picture changes — it's deliberate that we don't put 300 tests on the table from day one. You can move up AND down levels as your risk picture changes.
Within 30 days of cancellation, all your data is deleted from our side. We can also delete on request — typically within 24 hours.
Our DPA and sub-processor list lives in the privacy policy.
Every Graph call is automatically logged in your own Entra ID under sign-in logs for our service principal. It's a log you own, we can't edit, and you can export to SIEM.