Client-ready M365 security reports, without the enterprise price tag

Built for the solo IT consultant with 5–25 client tenants — self-serve setup, read-only by design, and a report your client will actually understand.

No credit card required. We'll email you when early access opens.

There's a gap between “run your own infrastructure” and “pay enterprise prices”

Free / self-hosted tools

CIPP and similar are powerful, but assume you're comfortable standing up and maintaining your own Azure infrastructure. That's a real burden when your job is client work, not DevOps.

Enterprise MSP tools

CoreView, ShareGate, AvePoint — priced and packaged for MSPs running dozens of tenants. $5,995+/yr minimums and sales calls for capacity a 5–15 tenant shop doesn't need.

Microsoft's own tools

The admin center and Secure Score are functional, but they don't produce a clean, brandable, client-facing artifact — and don't cross tenants the way a multi-client consultant needs day to day.

How it works

1

Connect a tenant

Your client approves a read-only Microsoft admin-consent request. No password shared, no write access ever requested.

2

Run a scan

We pull MFA coverage, conditional access gaps, legacy auth usage, privileged role hygiene, and guest exposure directly from Microsoft Graph.

3

Export a report

A branded PDF — your logo, not ours — with a transparent 0–100 score and plain-English findings you can hand straight to your client.

Solo Dana — independent consultant

Manages 5–25 SMB tenants, bills monthly for IT support or vCIO services. Technical enough to know MFA and conditional access, but doesn't want to run her own hosting or debug PowerShell modules. Currently pastes admin-center screenshots into Word docs — or sends nothing at all.

Accidental Admin Alex — in-house

Not a consultant — an ops-adjacent employee at a 20–80 person company who inherited M365 admin duties. Wants a plain-English health score and a to-do list, not a raw Graph API report.

What you get

  • Security posture score (0–100) with a transparent, evidence-backed breakdown
  • License waste report — unassigned seats, overlapping SKUs, inactive users
  • Branded, white-labelable client PDF export
  • Multi-tenant dashboard with score trend since last scan
  • Read-only by default — no write permissions, ever, in v1
  • Self-serve billing, no sales call, cancel anytime

Read-only, always

“Scoped” is the point: the minimal OAuth permission scopes we request, and the whole trust pitch. We look at your client's configuration, not their data — neverMail.Read, never Files.Read.All, never a write permission, in v1.

See pricing

Simple volume tiers, no annual contract required.

View pricing