Security Assessment
Microsoft 365, Google Workspace, GitHub, AWS, Azure, or NinjaOne security scan, mapped to SOC 2 / ISO 27001 / CIS / HIPAA / HITRUST CSF / CMMC 2.0. Sign in with an admin account.
For a 100% complete scan, sign in with an account that has read access to your security settings
- Microsoft 365: a Global Reader (read only) or higher, and a Global Administrator must have granted this app admin consent. Lower privileged accounts return incomplete results.
- Google Workspace: a super administrator (or an admin with read access to users, roles, domains & reports).
- GitHub: an organization owner; the org must allow this OAuth app under Org settings → Third party access.
- AWS: the read only IAM role deployed from our CloudFormation template (
SecurityAudit). - Azure: the read only Reader role on the subscriptions you want assessed, granted through the same Microsoft sign-in you use for Microsoft 365.
- NinjaOne: an API client with the read-only Monitoring scope (Administration → Apps → API, client-credentials grant). Credentials are used for this scan only and never stored.
A missing permission only affects the checks that need it. Those appear as Not Detected — because the control can't be verified, it earns no credit and counts against your score. Grant the permission and re-scan for full credit.
–
Security Score
Not scanned
–
Pass
–
Fail
–
Not Detected
–
Total Checks
Multiselect platforms:
Click every platform you want in the assessment, then hit Connect. Sign-ins run one after
another, and the scan cross-checks security controls across all of them.
Security goal:
Signed inNo
Account–
StatusIdle
Downloads
PDF report
CSV results
JSONL evidence
Audit JSON
Trust badge & shareable link
(format follows selected security goal)
Findings
| Category | Check | Status | Severity | Summary |
|---|