DeliverablesHow it worksSecurityPricingLog in
How it works

From first look to a picture leadership can act on.

No installation, no disruption — your IT team is in control the whole way.

1

We get to look

Your IT team approves access in two minutes via a standard Microsoft consent. We can only look — we never change anything. Nothing is installed, and access can be revoked at any time.

2

We review your setup

We check the holes attackers most often exploit — multi-factor authentication, old login routes, forgotten admin accounts and the like. In the order that matters most.

3

You build up level by level

We start at baseline — what everyone should have in place. Once you have that under control, you move on to the next level. Three levels in total: Baseline, Strengthened, Advanced.

4

Leadership gets one clear picture

A decision-ready report: the biggest risks in business language, the trend over time — and the technical appendix for the auditor and the IT team.

Bonus
We go further than Microsoft Secure Score
Microsoft gives you a score — we give you exactly what you face, what it means for the business, and what to do about it.
See the comparison
For your IT team

The technical depth — for those who want to know exactly what happens.

If you're sitting with your IT partner or in-house IT team and want the full picture, the details live here.

What access do you actually get?

We use a multi-tenant app registration in Microsoft Entra with read-only Microsoft Graph permissions. It lets us read users, conditional access policies, app registrations, devices, sign-in logs and licenses — not change anything.

Access is activated when a Global Administrator completes admin consent once. It can be revoked in Entra under Enterprise applications at any time.

Where does the review run?

Scanner code runs on Vercel (Frankfurt). Results land in a Supabase Postgres database in AWS eu-central-1 (Frankfurt). No data leaves the EU.

Graph tokens are fetched fresh per call via client credentials flow and not stored persistently.

What gets reviewed?

Across all three levels (Baseline, Strengthened, Advanced) we check the fundamentals in the identity layer — multi-factor authentication, legacy login paths, privileged roles, app registrations and password policy. Each check describes what it measures, why it matters, and what concretely needs fixing.

The Baseline level is the core today and covers the most important risks. Strengthened and Advanced are expanded continuously as the threat picture changes — it's deliberate that we don't put 300 tests on the table from day one. You can move up AND down levels as your risk picture changes.

What happens to data if we stop?

Within 30 days of cancellation, all your data is deleted from our side. We can also delete on request — typically within 24 hours.

Our DPA and sub-processor list lives in the privacy policy.

How do you know what we've looked at?

Every Graph call is automatically logged in your own Entra ID under sign-in logs for our service principal. It's a log you own, we can't edit, and you can export to SIEM.