Find and fix your Microsoft 365 & Google Workspace security gaps

Automated SOC 2 / ISO 27001 / CIS / HIPAA readiness — assess your tenant, then remediate in a click.

Sign in with Microsoft 365 or Google Workspace and get an auditor-ready assessment of your identity, admin access, MFA, logging, and data-sharing controls. Then apply guided, safe fixes — on Microsoft, Conditional Access changes start in report-only mode so nothing breaks.

100% private — the scan runs entirely in your browser. Your Microsoft / Google data is read straight from the provider and is never sent to our servers, never stored, and there are no accounts. How it stays private →
Run your free scan → See what we check
Runs 100% in your browser
Read-only — your data never leaves
No cloud storage, no accounts
Verified Microsoft publisher

Why LockList Security?

Enterprise-grade security assessment tools designed for compliance teams and auditors

Zero Token Storage

Your Microsoft 365 access tokens never leave your browser. We use delegated authentication—you sign in, we scan, you get results. No persistent access, no security risk.

Evidence-Ready Reports

Download reports in PDF, CSV, JSONL, and SOC 2 JSON. Each finding includes raw evidence from Microsoft Graph / the Google Admin SDK and its SOC 2 / ISO 27001 / CIS / HIPAA mapping — built for auditor verification and security reviews.

One-Time Scans

No ongoing monitoring, no data retention. Run assessments on-demand when you need them. Perfect for pre-audit preparation, compliance reviews, and security assessments.

Multi-Framework Mapping

Every finding maps to SOC 2, ISO 27001, CIS Microsoft 365, and the HIPAA Security Rule — so you see exactly which controls you meet and where the gaps are, in your auditor's language.

Comprehensive Coverage

Microsoft 365: 20+ checks across identity, Conditional Access, privileged access, audit logging, devices (Intune), and data sharing. Google Workspace: 2-Step Verification, admin access, audit logs, domains and more — evaluated against Microsoft, Google, and CIS baselines.

Fix, Don't Just Find

The scan is read-only. When you're ready, apply guided remediations with one click — and Conditional Access fixes start in report-only mode, so you review the impact before anything is enforced.

Open Source & Auditable

The full source code is public on GitHub. You can read every line of code that touches your data before you run it. No black boxes — exactly what you need for a security tool.

Runs in your browser

Your data never reaches our servers

The assessment runs entirely in your browser. Your tenant data is read directly from Microsoft or Google and is never sent to or stored by LockList.

Runs in your browser

The scan executes as client-side code in your browser and calls your provider's API directly. There is no LockList server in the path reading your tenant.

Token stays with you

Your Microsoft / Google access token stays in your browser, is used only to read your settings, and is never transmitted to or stored by us. It expires on its own.

Talks only to your provider

During a scan the only outbound calls are to graph.microsoft.com / admin.googleapis.com and the provider's own login — nowhere else.

Nothing stored

We keep no database of scans and no user accounts. Results live only in your browser tab for the session; closing it clears them.

Read-only by default

The assessment requests read-only permissions. Any fixes are opt-in, require your explicit approval, and Conditional Access changes start in report-only mode.

No telemetry

No analytics SDK, no tracking, no usage collection. See our Privacy Policy for the full detail.

✓ Your browser → Signs in with Microsoft / Google (MSAL / Google Identity Services) ✓ Your browser → Reads your tenant directly from the provider API (read-only) ✓ Your browser → Evaluates findings and renders results locally → On download → Results sent to our Worker only to build the file, then discarded ✗ Never → No token storage, no tenant-data retention, no telemetry ✓ Verified → Microsoft verified publisher · read our Privacy Policy

Mapped to the frameworks you're audited against

Every finding is tagged to SOC 2, ISO 27001, the CIS Microsoft 365 / Google Workspace Benchmarks, and the HIPAA Security Rule — in the app and in every report.

SOC 2

Trust Services Criteria — CC6 access, CC7 monitoring, CC8 change management.

ISO 27001:2022

Annex A controls for access, authentication, logging, and monitoring.

View ISO 27001 controls →

CIS Benchmarks

CIS Microsoft 365 & Google Workspace Foundations Benchmarks.

HIPAA Security Rule

Technical & administrative safeguards (45 CFR 164.312 / 164.308).

Private by architecture

Delegated, read-only access via Microsoft Graph and the Google Workspace Admin SDK — the scan runs in your browser, not on our servers.

Technology

Authentication
MSAL.js / Google Identity Services
APIs
Microsoft Graph / Google Admin SDK (read-only)
Hosting
Cloudflare Pages + Workers
Reports
PDF / CSV / JSONL / SOC 2 JSON

How a scan flows

1 Admin signs in with Microsoft 365 or Google Workspace 2 Browser gets a delegated, read-only token (in the browser only) 3 Browser calls the provider API directly and evaluates findings locally 4 Only on report download are results sent to our Worker to build the file x No token storage · no tenant-data retention · no telemetry · no accounts

The assessment uses delegated, read-only permissions (admin consent required). Write access is requested only if you choose to apply a fix — one fix at a time, never application-level. Read the privacy details →

Run your assessment

Sign in with Microsoft 365 or Google Workspace, get auditor-ready results in minutes — then fix what's wrong.

Scan in your browser

No download required. Sign in with Microsoft 365 or Google Workspace and the assessment runs entirely in your browser — your tenant data is read directly from Microsoft/Google and never sent to our servers.

  • ✓ Microsoft 365 & Google Workspace
  • ✓ Read-only scan; nothing stored
  • ✓ Guided one-click fixes when you're ready
Run your scan →

Or install it as an app

Prefer a desktop app? Install LockList straight from your browser — it opens in its own window with a dock/taskbar icon, like a native app. No app store, no code signing, no separate download.

  • ✓ Chrome / Edge: “Install” icon in the address bar
  • ✓ Mac Safari: Share → Add to Dock
  • ✓ Phone: Add to Home Screen
Open the app →

The assessment is free. Unlock the full multi-format report (PDF, CSV, JSONL, SOC 2 JSON) and guided auto-fix with a one-time payment.