Download and pair
A single portable executable. It shows an eight-character pairing code; approve it from your workspace and the collection is bound to your domain for thirty minutes.
A read-only assessment of your Active Directory, domain controllers, Windows hosts and Microsoft 365 tenant. Evidence is encrypted on your side before it leaves the building. You get a four-page executive brief and a full technical report, not a scan log.
118 on-premises and 76 Microsoft 365 controls across directory, hosts, certificate services, network, Entra ID, Exchange Online, SharePoint, Teams and Defender
signed and sealed LDAP, Kerberos WinRM, no writes during collection
evidence encrypted on the collecting machine, keyed to a one-time authorization
executive brief your leadership will actually read, plus the full technical report
Run the collector on any domain-joined Windows machine with your own account. Approve it in the browser. Read the report.
A single portable executable. It shows an eight-character pairing code; approve it from your workspace and the collection is bound to your domain for thirty minutes.
Directory, SYSVOL, the local host and up to 100 remote hosts you choose, plus your Microsoft 365 tenant through the same collector. Bounded queries, and every result sealed before upload.
Eight distinct outcomes, never a missing setting counted as a pass. Every follow-up has a reason and a next action. Retained for thirty days.
The executive brief fits in four pages and is written for the person who signs the budget. The technical report carries every observation, per host, with linked navigation and the evidence behind each verdict.
Both samples come from the real report engine, run against a fictional hybrid organization. No customer data appears in them.
Everything below is verifiable in the collector you run and the file it produces.
A fresh AES-256-GCM key per collection, wrapped with the RSA-3072 key of your workspace and bound to a one-use ticket.
The collector runs as the Windows user who launched it. No service accounts, no stored credentials, no LAPS or GPP password retrieval.
Two hundred entries per inventory query, 100 remote hosts per run, fixed-port probes only, Get-* cmdlets only in Microsoft 365. Limits are reported, never silently exceeded.
Missing evidence is reported as missing. A setting we could not read is never counted as secure. Anything that did not collect stays visible until a completion run fills it in.
We keep adding on-premises and Microsoft 365 checks as the Microsoft, CIS and CISA SCuBA baselines evolve. Your next assessment picks them up automatically, and every report records the catalog it was assessed against.
On-premises fixes arrive as unlinked GPOs that you review and link. Microsoft 365 plans hold staged policies (report-only Conditional Access, disabled rules, test-mode policies that enforce nothing until you enable them) and individual settings that take effect when you apply them, with the previous value recorded for a best-effort rollback. Nothing is applied without your own admin sign-in and confirmation.
An environment is an Active Directory domain or a Microsoft 365 tenant; a domain and its tenant count as one. Most teams assess once a year, so the plans follow that: a one-time assessment, an annual plan with four collections and verification rescans, and an MSP plan for service providers.
Annual and MSP plans run for 12 months. Before a term ends we send a renewal invoice; nothing is charged automatically, and an unpaid plan simply ends.
Read-only assessment, encrypted before upload. You authorize every collection and every change. Reports are a point-in-time review, not a guarantee.