Security Assessment & Remediation

Know exactly where your domain and tenant stand.
Before someone else does.

A read-only assessment of your Active Directory, domain controllers, Windows hosts and Microsoft 365 tenant. Evidence is encrypted on your side before it leaves the building. You get a four-page executive brief and a full technical report, not a scan log.

No domain passwords requested No agents installed Nothing changed in your domain
194

118 on-premises and 76 Microsoft 365 controls across directory, hosts, certificate services, network, Entra ID, Exchange Online, SharePoint, Teams and Defender

Read-only

signed and sealed LDAP, Kerberos WinRM, no writes during collection

AES-256-GCM

evidence encrypted on the collecting machine, keyed to a one-time authorization

4 pages

executive brief your leadership will actually read, plus the full technical report

How it works

Three steps. One afternoon.

Run the collector on any domain-joined Windows machine with your own account. Approve it in the browser. Read the report.

01

Download and pair

A single portable executable. It shows an eight-character pairing code; approve it from your workspace and the collection is bound to your domain for thirty minutes.

02

Collect, read-only

Directory, SYSVOL, the local host and up to 100 remote hosts you choose, plus your Microsoft 365 tenant through the same collector. Bounded queries, and every result sealed before upload.

03

Read the report

Eight distinct outcomes, never a missing setting counted as a pass. Every follow-up has a reason and a next action. Retained for thirty days.

What you get

Two reports. One story.

The executive brief fits in four pages and is written for the person who signs the budget. The technical report carries every observation, per host, with linked navigation and the evidence behind each verdict.

  • Cross-host matrices so you see one control across every machine
  • Passed and inapplicable evidence retained, not hidden
  • Optional remediation: unlinked GPOs and staged Microsoft 365 policies you review and enable yourself
  • A catalog that keeps growing: new on-premises and Microsoft 365 checks are added over time
Executive brief4 pages · outcomes, priorities, 30/60/90 plan
PDF
Technical assessmentContents, matrices, findings, per-host and tenant inventories · on-premises and Microsoft 365 volumes
PDF
Remediation plan50 on-premises and 34 Microsoft 365 fixes · signed, one-use · staged policies and individual settings that take effect when you apply them
ADD-ON
Sample reports

Read one before you run anything.

Both samples come from the real report engine, run against a fictional hybrid organization. No customer data appears in them.

Built for scrutiny

Your security team will ask. Here are the answers.

Everything below is verifiable in the collector you run and the file it produces.

Encrypted before upload

A fresh AES-256-GCM key per collection, wrapped with the RSA-3072 key of your workspace and bound to a one-use ticket.

Your identity, your account

The collector runs as the Windows user who launched it. No service accounts, no stored credentials, no LAPS or GPP password retrieval.

Bounded by design

Two hundred entries per inventory query, 100 remote hosts per run, fixed-port probes only, Get-* cmdlets only in Microsoft 365. Limits are reported, never silently exceeded.

Honest outcomes

Missing evidence is reported as missing. A setting we could not read is never counted as secure. Anything that did not collect stays visible until a completion run fills it in.

A catalog that keeps growing

We keep adding on-premises and Microsoft 365 checks as the Microsoft, CIS and CISA SCuBA baselines evolve. Your next assessment picks them up automatically, and every report records the catalog it was assessed against.

Remediation you stay in control of

On-premises fixes arrive as unlinked GPOs that you review and link. Microsoft 365 plans hold staged policies (report-only Conditional Access, disabled rules, test-mode policies that enforce nothing until you enable them) and individual settings that take effect when you apply them, with the previous value recorded for a best-effort rollback. Nothing is applied without your own admin sign-in and confirmation.

Pricing

Per environment. No seats to count.

An environment is an Active Directory domain or a Microsoft 365 tenant; a domain and its tenant count as one. Most teams assess once a year, so the plans follow that: a one-time assessment, an annual plan with four collections and verification rescans, and an MSP plan for service providers.

One-time assessment
$499/ environment
  • One collection and one verification rescan within 30 days
  • Executive brief and technical report
  • Reports kept 30 days
  • Remediation add-on: $299 per environment
Start an assessment Talk to sales
AnnualRecommended
$899/ environment / year
  • Four collections a year, with verification rescans
  • Executive brief and technical report
  • Reports kept 12 months, so the year-over-year change shows
  • Remediation plans: unlinked GPOs for Active Directory; for Microsoft 365, staged policies and individual settings that take effect when you apply them
Start an assessment Talk to sales
MSP
$399/ environment / year
  • Unlimited collections across all your client environments
  • Client-ready brief, no platform fee
  • Reports kept 12 months
  • Remediation plans: unlinked GPOs for Active Directory; for Microsoft 365, staged policies and individual settings that take effect when you apply them
Start an assessment Talk to sales

Annual and MSP plans run for 12 months. Before a term ends we send a renewal invoice; nothing is charged automatically, and an unpaid plan simply ends.

Read-only assessment, encrypted before upload. You authorize every collection and every change. Reports are a point-in-time review, not a guarantee.