The only zero install, zero setup, zero trust compliance tool

Compliance shouldn't cost you your data.

Get certification-ready in minutes without trusting yet another company to keep your data safe. LockList works from your browser to flag workspace security gaps and builds you a personalized, shareable report with easy remediation guidance. Nothing installed and nothing ever sent to us.

Browser based · read only · your data never leaves your browser
locklistsecurity.com/scan
54
Security score · Medium risk
7Pass
4Fail
1Review
MFA required for adminsFailHigh
Security Defaults policyFailHigh
Block legacy authenticationPass
Privileged role assignmentsFailMed
Directory audit logs accessiblePass
Named locations configuredReviewMed
Works with Microsoft 365 Google Workspace GitHub AWS Azure NinjaOne
How we compare

Compliance platforms want your data and a subscription.We want neither.

Continuous compliance platforms are powerful — once you've spent weeks wiring your stack into their cloud and signed up for the annual bill. LockList gets you the assessment and the proof without handing anything over.

Compliance platforms (Vanta, Drata, …) LockList
Your data Ingested and stored on their cloud, indefinitely Read in your browser. Never transmitted, never stored
Price Annual subscription with quoted tiers, often five figures a year $149, flat, one time
Setup Weeks of integrations, agents, and onboarding calls Sign in with the admin account you already have. Results in minutes
Your audit trail Lives inside their platform, for as long as you subscribe Yours. Every report is a file you hold
Proof for customers A trust page on their servers, built from your data A signed trust badge you share yourself. Anyone can confirm it's genuine, and we store nothing

If you need automated evidence collection all year across dozens of SaaS tools, a continuous platform earns its keep. If you need to know where you stand, fix the gaps, and prove it without your data ever leaving the building, that's LockList.

Pricing

One flat price. That's the whole pricing page.

$149
one time · no subscription
  • A full assessment of your workspace — Microsoft 365, Google Workspace, GitHub, AWS, Azure, or NinjaOne
  • Every finding mapped to SOC 2, ISO 27001, CIS, HIPAA, HITRUST CSF, or CMMC 2.0
  • The complete LockList Report — PDF, CSV, JSONL, and SOC 2 JSON exports
  • A signed, shareable trust badge
  • Guided remediation for every failed check
No tiers. No quotes. No sales calls. No lock-in.
Run your scan now
LockList Report

Sample Organization

Microsoft 365 · SOC 2 / ISO 27001 / CIS / HIPAA
Security score 54 / 100 · Medium
MFA required for adminsFailHigh
Fix: create an enabled Conditional Access policy requiring MFA for admin roles. · SOC 2 CC6.1 · ISO A.5.15
SharePoint external sharingFailMedium
Fix: restrict external sharing to existing external users. · SOC 2 CC6.7 · ISO A.5.14
Block legacy authenticationPass
The deliverable

The LockList Report

The LockList Report makes reading complex workspace settings a breeze. We'll build for you a clear security readiness packet that shows what controls passed, what failed, why it matters, and how to fix it.

Findings & severityPass/fail status and risk severity for each control.
Affected controlsSOC 2, ISO 27001, CIS, HIPAA, HITRUST CSF, and CMMC 2.0 control references for each finding.
Evidence referencesRaw configuration evidence for auditor verification.
Remediation stepsSpecific next actions for each failed check.
SOC 2 / ISO readinessMapping to SOC 2, ISO 27001, CIS, and HIPAA.
Exportable outputsPDF, CSV, JSONL, and SOC 2 JSON.

View sample report

How it works

From workspace settings to a readiness packet in minutes.

01

Connect workspace

Microsoft 365, Google Workspace, GitHub, AWS, Azure, or NinjaOne is connected through the browser based assessment flow with admin consent.

02

Choose security goal

Select the framework you're preparing for (SOC 2, ISO 27001, CIS Benchmark, or HIPAA) to shape the report output.

03

Review findings

The dashboard shows pass/fail status, risk severity, and remediation priorities mapped to your chosen framework.

04

Generate the report

Export a LockList Report for internal cleanup, SOC 2 / ISO / CIS / HIPAA prep, MSP review, or customer security conversations.

locklistsecurity.com/scan · remediation
Require MFA for all usersApply fix
Block legacy authenticationReport only createdEnforce
Restrict SharePoint external sharingApply fix
Enable Security DefaultsApplied

Guided remediation, apply safe fixes in steps. Conditional Access changes start in report only mode before they are enforced.

What we check

Concrete workspace controls.

Each finding maps to SOC 2, ISO 27001, CIS, HIPAA, HITRUST CSF, and CMMC 2.0 control references. See the SOC 2, ISO 27001, CIS, HIPAA, HITRUST CSF, and CMMC 2.0 control mappings.

Microsoft 365

  • MFA for admins and all users (Conditional Access)
  • Privileged role assignments & directory roles
  • Conditional Access policy & Security Defaults review
  • Legacy authentication detection
  • MFA registration coverage & methods
  • Sign in & directory audit log evidence
  • External sharing & mail forwarding findings

AWS

  • Root account MFA & no root access keys
  • IAM password policy & console-user MFA coverage
  • IAM access-key rotation (90 days)
  • CloudTrail multi-region logging
  • S3 account-level Block Public Access

NinjaOne

  • Device inventory & agent coverage
  • Stale / offline agent detection
  • OS patch status across endpoints
  • Antivirus coverage & health
  • Open alerts & activity log accessibility

Google Workspace

  • 2-Step Verification coverage & admin enrollment
  • Super admin count & admin role assignments
  • Login & admin audit log accessibility
  • Suspended & dormant account review
  • Domain verification posture

GitHub

  • Org wide 2FA enforcement
  • SAML SSO configuration
  • Default branch protection rules
  • Secret scanning & push protection
  • Admin / member role review & deploy keys

Azure

  • Storage secure transfer (HTTPS) & minimum TLS 1.2
  • Storage public blob access disabled
  • NSGs, SSH/RDP not open to the internet
  • Key Vault soft delete & purge protection
  • Microsoft Defender for Cloud plan coverage
  • SQL Server auditing enabled
  • Activity log export (diagnostic settings)

In every report

  • SOC 2 / ISO 27001 / CIS / HIPAA readiness mapping & remediation checklist
  • Evidence focused exports (PDF / CSV / JSONL / JSON)
Show your customers

Prove you take security seriously, without handing over your data.

When you finish an assessment, LockList signs a short summary of your results and gives you a shareable trust badge. Put it on your website or send the link to a customer. Anyone can confirm it's genuine and came from LockList, and it works without us storing anything about you.

  • Shows your grade, checks passed, framework, and a valid-through date
  • Never includes your findings or any data from your accounts
  • Signed by LockList, so anyone can check it's real and unaltered
  • You share it yourself; nothing is stored on our servers
Run a scan to get yours →
locklistsecurity.com/trust
Sample Organization
SOC 2 · Microsoft 365 · valid through Oct 2026
AGrade
✓ Signature verified — issued by locklistsecurity.com
Checks passed18
Needs attention2
FrameworkSOC 2

A shareable trust badge, verified in the visitor's browser. No data leaves your side.

Security & data handling

Built for security sensitive reviews.

The assessment is designed to be easy to approve in a security review: read only, browser based, and transparent about exactly what it reads.

Browser based

The assessment runs in your browser and reads your workspace directly from Microsoft, Google, GitHub, AWS, Azure, or NinjaOne. There is no separate server in the path reading your tenant.

Read only by default

Connection uses delegated, read only permissions with admin consent. Write access is only ever requested if you explicitly choose to apply a fix.

Your data stays with you

Tenant data is read in your browser and is not sent to or stored by LockList. No database of scans, no accounts. We are a Microsoft verified publisher and a Google verified OAuth app.

What the connection can read. Delegated read only scopes such as Directory.Read.All, Policy.Read.All, AuditLog.Read.All (Microsoft 365), and the equivalent read only permissions for Google Workspace (Admin SDK), GitHub (organization read), AWS (the SecurityAudit IAM role), Azure (the Reader role), and NinjaOne (an API client with the read only Monitoring scope). Report files are generated on demand and not retained. Read the full privacy & data handling details →
Get started

Run your scan now

Run a browser based, read only assessment of your Microsoft 365, Google Workspace, GitHub, AWS, Azure, or NinjaOne security posture. Results in minutes, your data never leaves your browser.

Run your scan now

Useful for founders, IT managers, MSPs, and compliance teams preparing for SOC 2, ISO style reviews, customer security questionnaires, or internal security cleanup.

Microsoft & Google verified
Publisher verifications
Microsoft — verified publisherWhat this means
Google — OAuth app verifiedWhat this means

You can see both for yourself: when you connect a workspace, the Microsoft consent screen shows our verified publisher badge and the Google sign-in shows no "unverified app" warning.