Get certification-ready in minutes without trusting yet another company to keep your data safe. LockList works from your browser to flag workspace security gaps and builds you a personalized, shareable report with easy remediation guidance. Nothing installed and nothing ever sent to us.
Continuous compliance platforms are powerful — once you've spent weeks wiring your stack into their cloud and signed up for the annual bill. LockList gets you the assessment and the proof without handing anything over.
| Compliance platforms (Vanta, Drata, …) | LockList | |
|---|---|---|
| Your data | Ingested and stored on their cloud, indefinitely | ✓Read in your browser. Never transmitted, never stored |
| Price | Annual subscription with quoted tiers, often five figures a year | ✓$149, flat, one time |
| Setup | Weeks of integrations, agents, and onboarding calls | ✓Sign in with the admin account you already have. Results in minutes |
| Your audit trail | Lives inside their platform, for as long as you subscribe | ✓Yours. Every report is a file you hold |
| Proof for customers | A trust page on their servers, built from your data | ✓A signed trust badge you share yourself. Anyone can confirm it's genuine, and we store nothing |
If you need automated evidence collection all year across dozens of SaaS tools, a continuous platform earns its keep. If you need to know where you stand, fix the gaps, and prove it without your data ever leaving the building, that's LockList.
The LockList Report makes reading complex workspace settings a breeze. We'll build for you a clear security readiness packet that shows what controls passed, what failed, why it matters, and how to fix it.
Microsoft 365, Google Workspace, GitHub, AWS, Azure, or NinjaOne is connected through the browser based assessment flow with admin consent.
Select the framework you're preparing for (SOC 2, ISO 27001, CIS Benchmark, or HIPAA) to shape the report output.
The dashboard shows pass/fail status, risk severity, and remediation priorities mapped to your chosen framework.
Export a LockList Report for internal cleanup, SOC 2 / ISO / CIS / HIPAA prep, MSP review, or customer security conversations.
Guided remediation, apply safe fixes in steps. Conditional Access changes start in report only mode before they are enforced.
Each finding maps to SOC 2, ISO 27001, CIS, HIPAA, HITRUST CSF, and CMMC 2.0 control references. See the SOC 2, ISO 27001, CIS, HIPAA, HITRUST CSF, and CMMC 2.0 control mappings.
When you finish an assessment, LockList signs a short summary of your results and gives you a shareable trust badge. Put it on your website or send the link to a customer. Anyone can confirm it's genuine and came from LockList, and it works without us storing anything about you.
A shareable trust badge, verified in the visitor's browser. No data leaves your side.
The assessment is designed to be easy to approve in a security review: read only, browser based, and transparent about exactly what it reads.
The assessment runs in your browser and reads your workspace directly from Microsoft, Google, GitHub, AWS, Azure, or NinjaOne. There is no separate server in the path reading your tenant.
Connection uses delegated, read only permissions with admin consent. Write access is only ever requested if you explicitly choose to apply a fix.
Tenant data is read in your browser and is not sent to or stored by LockList. No database of scans, no accounts. We are a Microsoft verified publisher and a Google verified OAuth app.
Directory.Read.All, Policy.Read.All, AuditLog.Read.All (Microsoft 365), and the
equivalent read only permissions for Google Workspace (Admin SDK), GitHub (organization read), AWS (the SecurityAudit IAM role), Azure (the Reader role), and NinjaOne (an API client with the read only Monitoring scope). Report files are generated on demand and not retained.
Read the full privacy & data handling details →
Run a browser based, read only assessment of your Microsoft 365, Google Workspace, GitHub, AWS, Azure, or NinjaOne security posture. Results in minutes, your data never leaves your browser.
Run your scan nowUseful for founders, IT managers, MSPs, and compliance teams preparing for SOC 2, ISO style reviews, customer security questionnaires, or internal security cleanup.
You can see both for yourself: when you connect a workspace, the Microsoft consent screen shows our verified publisher badge and the Google sign-in shows no "unverified app" warning.