Copilot made oversharing urgent
Copilot surfaces anything a user can technically reach. Permissions that sat harmless for years became a live data-leak path overnight — and the rollout stalls until somebody can show the blast radius.
Sharing and permissions, security posture, email authentication, and the public web surface anyone can already see — scanned continuously, with every finding tagged to the control it proves. One tenant or five hundred, on one connection rather than four tools and an integration project.
A scoped scan of your worst tenants, and a report you can act on — whether or not you buy anything afterwards.
Built and run by JeffOps, Nieuwegein, Netherlands · data stays in Azure West Europe · scanning is read-only, and writing needs its own consent · every price is on this site, with no call first.

Which planes we detect but do not fix yet, and what is not on sale yet. Where the Microsoft-first scope ends. Why readiness is not an audit opinion. It is all written down, in one place, before you ask.
Your data, your identities and your risk already live in Microsoft 365. That is exactly where these three pressures land.
Copilot surfaces anything a user can technically reach. Permissions that sat harmless for years became a live data-leak path overnight — and the rollout stalls until somebody can show the blast radius.
Auditors increasingly expect evidence that controls operate continuously, not a screenshot taken once a year. Manual GRC does not scale to that cadence.
Managed service providers are consolidating tooling and adding security and compliance lines they can deliver without adding headcount per client.
Four are running today. Two more are built but not released, and two are still in development. Each answers a question you are already being asked, and each is useful on its own — run one, or run several of them into the same findings store.
SecurityPortal finds the weaknesses, CompliancePortal turns them into evidence, and PosturePortal will put the whole picture on one board. The scanning products write to the same findings store, so a scan run by one becomes evidence in another with nothing to integrate. Four are running today; ConditionalAccessPortal and CompliancePortal are close, and Dredd and PosturePortal are further out.
Crawls the whole Microsoft 365 sharing and permission surface app-only, scores exposure by sensitivity and blast radius, and remediates — with a grace window and undo. The Copilot-readiness answer, across every tenant.
ShareCareContinuous Microsoft 365 and Entra security posture — Conditional Access coverage, MFA gaps, over-privileged apps, risky sign-in patterns. Every finding carries control tags, and a tier you can only climb with evidence.
SecurityPortalFinds the public face of your organisation — including the hosts nobody wrote down — and grades it against the standards. Discovery, TLS, headers, cookies, DNS, exposed services and infrastructure. No tenant and no consent needed, and the scan is free; you pay to keep it.
WebScanTakes every domain from DMARC monitoring to safe enforcement — inventorying real senders from aggregate reports, staging the rollout, and writing the DNS records in-product for supported providers.
MailTrustPriced where the price is settled, so the number is not a negotiation when they ship.
Conditional Access policy inventory, baseline coverage gaps and approval-gated policy write-back for the Entra estate.
ConditionalAccessPortalTurns the scans you already run into framework-mapped, audit-ready evidence, with attestation, an evidence repository and time-boxed auditor access. It proves the technical controls on the platforms SeQontrol supports — it is not a whole-company compliance programme.
CompliancePortalReal work is still happening on these, so neither carries a list price — a price against something still being built is a guess with a currency symbol on it.
Holds your approved configuration as a versioned baseline, catches every deviation, and forces the decision: revert it or ratify it. Not "this is unwise" — "this is not what you approved."
DreddThe read-only board that aggregates findings, risk and coverage from every product into one per-tenant and fleet-wide view — top risks, trends, connector health, saved views and annotations.
PosturePortalEvery surface below is read app-only, on a schedule, and scored into one findings store. Dashed means detected but not yet remediable app-only — the distinction is stated rather than glossed.
Google Workspace is the next plane. What is not here is not scanned — the full list of what we do not do.
An app-only Entra app per product, each asking only for what that product needs. Same onboarding flow every time.
Each scanning product reads through that connection and writes into one shared findings store.
Findings carry control tags, so a security finding becomes compliance evidence without a second integration.
Remediation is simulate-then-execute, with grace windows, approvals and undo where the plane allows it.
Waivers expire, approvals are recorded, and the audit trail is hash-chained. Findings are live records that change as the estate changes; what is chained is the trail of what was done and the evidence snapshots taken from it.
The product is the same. What it costs, how it is priced and what you do with it on a Monday morning are not — so the paths split here.
You are an admin, a security lead or the person who owns identity. The Copilot rollout is waiting on somebody proving what it can reach, and an audit is either underway or coming.
You run an MSP, an MSSP or a vCISO practice. Clients are asking whether Copilot is safe, and you need an answer that scales past doing it by hand, forty times.
Onboard one SeQontrol tenant and you get a fleet console across all your clients and all products from day one — the same crawl, the same evidence, the same board, priced per managed tenant.
Each of these is a real assessment with a real report at the end, whether or not you buy anything afterwards. Two of them need nothing from you but a domain name.
A scoped crawl of your worst tenants: anonymous links, external guests, company-wide shares and the app consents nobody remembers granting — scored, with the list of what to revoke.
Needs a read-only connection to your tenant.
SPF, DKIM, DMARC, BIMI and MTA-STS across your sending and parked domains, and what an attacker could send from the ones you forgot you owned.
Needs a domain name. Nothing else.
TLS, certificates, security headers, cookies, DNS hygiene and exposed content on the public face of your estate — graded against the standards that define each one.
Needs a domain name. Nothing else.
Not because compliance does not matter — it is a whole product here — but because a compliance control can be waived, and an attacker does not read your waivers.
Every framework has an exception process. A control gets accepted as a risk, signed off, and the report goes green. Nothing about the estate changed. Do that a few times across a few frameworks and you have built something worse than a gap: a documented, audited, board-reported sense of safety that does not correspond to anything real.
So the order is deliberate. The security finding is the fact. Compliance is an interpretation laid over that fact, and a waiver changes the interpretation only. In SeQontrol a waived finding is still a finding — it stays visible, it stays scored, and its exception carries a mandatory expiry that invalidates itself when the underlying problem changes shape. You can accept a risk. You cannot make it disappear from the screen.
That is what the three words under the logo are ordered by: secure first, because it is the thing that is actually true; compliant second, because it is provable once the first is real; confident last, because confidence earned in that order is the only kind worth having.

The products share one console, one findings store and one audit trail. That is not an architecture diagram — it is the reason ShareCare's exposure shows up as CompliancePortal's evidence without anyone exporting a spreadsheet.
ShareCare finds an external share. SecurityPortal finds a Conditional Access gap. Both land in CompliancePortal already tagged to the controls they satisfy — so the thing you fixed is the thing your auditor sees, with no export in between.
Every product has its own Entra app, scoped to what that product needs — so nothing inherits permissions it has no use for, and revoking one product revokes exactly one. Adding a product is a second consent, through the same onboarding you already know.
Whatever any product checked, changed or waived is in one hash-chained record you can show a client or an auditor. Waivers expire on their own; nothing quietly stays green.
Most products are sold on one ladder. You buy the depth you actually want, and the step that writes to your tenant is always a deliberate, separate decision.
Scanning is never metered. No per-scan pricing, no charging per finding, no hard cap that stops a scan for a commercial reason. You are billed on the size of the estate — a number you already know before you buy.
WebScan reads what any anonymous visitor reads. No tenant, no Entra app, no admin consent, no onboarding, no call. Send one URL and it goes looking for the rest — then grades everything it finds, with the standard behind each failure and the fix.
All three are reasonable. Two of them are sometimes right, and we would rather say which.
For one tenant, one administrator and no reporting obligation — largely true. Secure Score, Purview and SharePoint Advanced Management ship with your licence and you should start there. A tool you already own and will actually check beats one you buy and ignore.
It stops being true when you need evidence that a control held over a period, or when you manage sixty tenants and nothing native spans them. The four specific gaps.
Good, and keep running it. CIPP administers tenants and it is free; nothing here replaces that, and a provider running both is the normal case rather than an awkward one.
What it was not built to do is retain a control-tagged record that something held over time. That does not matter until an insurer, an auditor or a client's customer asks — and then it is the only thing that does. The honest split.
Correct instinct, and you do not have to. Scanning is read-only. The permission that writes is a separate consent you may never grant, and every read-only product keeps working without it.
If you do grant it, each change is approved on its own, and a refusal from your directory is recorded as a refusal rather than retried quietly. What we do with the access.
The usual opener is a scoped assessment: your worst few tenants, a real crawl, and a report you can act on — whether or not you buy anything afterwards.