Not currently — see the pricing page for planned tiers. During early access, joining the waitlist requires no credit card, and we expect to offer a limited free single-tenant scan as a top-of-funnel option post-launch.
Read-only, always: User.Read.All, Reports.Read.All, Policy.Read.All, Directory.Read.All, and AuditLog.Read.All. We never request write/modify permissions, Mail.Read, or Files.Read.All — the product's entire pitch is that we look at configuration, not content.
Under 10 minutes from signup to your first connected tenant: create an account, send your client a standard Microsoft admin-consent link, and run your first scan once they approve it.
Yes — the exported PDF carries your logo and branding, not ours. That's a core feature, not an add-on.
ScopedIQ is deliberately scoped for 5–25 tenant consultants and MSPs. Beyond that, you're likely better served by an enterprise tool built for larger fleets — talk to us and we'll tell you honestly if that's the case.
No. Every signal we pull is configuration and metadata (MFA registration status, policy settings, sign-in logs, role assignments, guest account presence) — never message content, file content, or anything requiring a content-read permission.
Every tenant, scan, and finding is enforced at the database row-security layer, not just application-level filtering — one consultant's client data is never visible to another consultant's account, even accidentally.
Yes. Monthly, self-serve, cancel anytime — no annual contract is ever required to use ScopedIQ.
At launch, scans are manual-trigger only. Scheduled recurring scans (weekly/monthly) are a planned Pro-tier feature.