Security checks by topic
- Identity, MFA & sign-in — 20 apps. Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
- Access control & privilege — 49 apps. Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
- Data sharing & exposure — 21 apps. External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
- Encryption, keys & secrets — 10 apps. Encryption at rest and in transit, key rotation, and the API keys, tokens and credentials that outlive the people who created them.
- Logging & audit — 10 apps. Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.
- Network security — 5 apps. IP allow-lists, TLS, DNS and edge settings that keep the application reachable only from where it should be.
- Configuration hardening — 37 apps. Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
- AI governance — 5 apps. AI assistants, agents and model access inside the tenant — what they can read, who can publish them, and how autonomously they act.
- Third-party & OAuth apps — 5 apps. OAuth grants, marketplace apps, integrations, plugins and automations with standing access to company data — the SaaS-to-SaaS supply chain.
- Lifecycle & offboarding — 7 apps. Dormant accounts, leavers with access, unowned assets and change-management gaps — the checks that catch what HR processes miss.
- Governance & compliance — 9 apps. Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.