Secure. Compliant. Confident.

One connection. Every surface your Microsoft 365 estate exposes.

Sharing and permissions, security posture, email authentication, and the public web surface anyone can already see — scanned continuously, with every finding tagged to the control it proves. One tenant or five hundred, on one connection rather than four tools and an integration project.

App-only, no agent, no user disruption. Scanning reads. Anything that writes to your tenant is a separate product decision and a separate, explicit consent.

A scoped scan of your worst tenants, and a report you can act on — whether or not you buy anything afterwards.

Built and run by JeffOps, Nieuwegein, Netherlands · data stays in Azure West Europe · scanning is read-only, and writing needs its own consent · every price is on this site, with no call first.

ShareCare overview: a needs-attention bar showing three anonymous links and 35
                    privileged grants, above an exposure score of 39 out of 100.
ShareCare, on a real tenant. The first screen answers the question you were asked, before you have chosen a menu.
  1. Two links, not a report. The things that need a decision today, with the count on them, straight through to the items.
  2. One number to take to a meeting — and one you can take apart, all the way down to the file and the person it is shared with.
Straight answers

We publish what this does not do

Which planes we detect but do not fix yet, and what is not on sale yet. Where the Microsoft-first scope ends. Why readiness is not an audit opinion. It is all written down, in one place, before you ask.

Why now

Why Microsoft 365 over-sharing became urgent

Your data, your identities and your risk already live in Microsoft 365. That is exactly where these three pressures land.

Copilot made oversharing urgent

Copilot surfaces anything a user can technically reach. Permissions that sat harmless for years became a live data-leak path overnight — and the rollout stalls until somebody can show the blast radius.

Compliance went continuous

Auditors increasingly expect evidence that controls operate continuously, not a screenshot taken once a year. Manual GRC does not scale to that cadence.

Providers need leverage

Managed service providers are consolidating tooling and adding security and compliance lines they can deliver without adding headcount per client.

The products

What each product finds, proves and fixes

Four are running today. Two more are built but not released, and two are still in development. Each answers a question you are already being asked, and each is useful on its own — run one, or run several of them into the same findings store.

Sold separately. · Built as one. · Priced honestly.

SecurityPortal finds the weaknesses, CompliancePortal turns them into evidence, and PosturePortal will put the whole picture on one board. The scanning products write to the same findings store, so a scan run by one becomes evidence in another with nothing to integrate. Four are running today; ConditionalAccessPortal and CompliancePortal are close, and Dredd and PosturePortal are further out.

Available today

Data access governance

ShareCare Built

Crawls the whole Microsoft 365 sharing and permission surface app-only, scores exposure by sensitivity and blast radius, and remediates — with a grace window and undo. The Copilot-readiness answer, across every tenant.

ShareCare
Posture scanning

SecurityPortal Built

Continuous Microsoft 365 and Entra security posture — Conditional Access coverage, MFA gaps, over-privileged apps, risky sign-in patterns. Every finding carries control tags, and a tier you can only climb with evidence.

SecurityPortal
External attack surface

WebScan Built

Finds the public face of your organisation — including the hosts nobody wrote down — and grades it against the standards. Discovery, TLS, headers, cookies, DNS, exposed services and infrastructure. No tenant and no consent needed, and the scan is free; you pay to keep it.

WebScan
Email authentication

MailTrust Built

Takes every domain from DMARC monitoring to safe enforcement — inventorying real senders from aggregate reports, staging the rollout, and writing the DNS records in-product for supported providers.

MailTrust

Built, and not released yet

Priced where the price is settled, so the number is not a negotiation when they ship.

Control evidence

CompliancePortal Coming soon

Turns the scans you already run into framework-mapped, audit-ready evidence, with attestation, an evidence repository and time-boxed auditor access. It proves the technical controls on the platforms SeQontrol supports — it is not a whole-company compliance programme.

CompliancePortal

Still in development

Real work is still happening on these, so neither carries a list price — a price against something still being built is a guess with a currency symbol on it.

Drift governance

Dredd Under development

Holds your approved configuration as a versioned baseline, catches every deviation, and forces the decision: revert it or ratify it. Not "this is unwise" — "this is not what you approved."

Dredd
Single pane

PosturePortal Under development

The read-only board that aggregates findings, risk and coverage from every product into one per-tenant and fleet-wide view — top risks, trends, connector health, saved views and annotations.

PosturePortal

What actually gets crawled

Every surface below is read app-only, on a schedule, and scored into one findings store. Dashed means detected but not yet remediable app-only — the distinction is stated rather than glossed.

SharePointSites, links, permissions
OneDriveShares, revoke app-only
TeamsMembership, guest access
Entra IDApp consents, grants
ExchangeForwarding — detect only
Power PlatformDetect only
Power BISharing surface
Conditional AccessCoverage and gaps
Log AnalyticsWhere logs are exported
Public web surfaceTLS, headers, DNS
Email authSPF, DKIM, DMARC, BIMI
Google Cloud & AWSRead-only connectors
BoxLinks, revoke app-only
Slack ConnectDetect only

Google Workspace is the next plane. What is not here is not scanned — the full list of what we do not do.

What happens to what it finds

How SeQontrol works

1

Connect

An app-only Entra app per product, each asking only for what that product needs. Same onboarding flow every time.

2

See

Each scanning product reads through that connection and writes into one shared findings store.

3

Prove

Findings carry control tags, so a security finding becomes compliance evidence without a second integration.

4

Fix

Remediation is simulate-then-execute, with grace windows, approvals and undo where the plane allows it.

5

Govern

Waivers expire, approvals are recorded, and the audit trail is hash-chained. Findings are live records that change as the estate changes; what is chained is the trail of what was done and the evidence snapshots taken from it.

Where to start

One estate, or a book of them?

The product is the same. What it costs, how it is priced and what you do with it on a Monday morning are not — so the paths split here.

I run one Microsoft 365 estate

You are an admin, a security lead or the person who owns identity. The Copilot rollout is waiting on somebody proving what it can reach, and an audit is either underway or coming.

  • Start with the free exposure report on your own tenant
  • Priced on what each product counts — users, domains, sites or tenant
  • Findings become audit evidence without a second tool

I manage many client tenants

You run an MSP, an MSSP or a vCISO practice. Clients are asking whether Copilot is safe, and you need an answer that scales past doing it by hand, forty times.

  • One console across every client, from day one
  • Pooled capacity, per-tenant floor as greater-of, partner margin
  • A benchmark that ranks your book and sells the remediation work
For providers

Microsoft 365 security across every client you manage

Onboard one SeQontrol tenant and you get a fleet console across all your clients and all products from day one — the same crawl, the same evidence, the same board, priced per managed tenant.

  • Fleet views in every product — manage 5 clients or 500 from one screen, and benchmark them against each other.
  • Delegated onboarding with audited impersonation and an approval gate before you act inside a client tenant.
  • Pooled capacity across managed tenants with a per-tenant floor applied as greater-of, never additive.
  • Partner margin built into the plan, so the service is resellable rather than a cost line.
Three ways in

Find out something true about your estate, for nothing

Each of these is a real assessment with a real report at the end, whether or not you buy anything afterwards. Two of them need nothing from you but a domain name.

What Copilot can reach

A scoped crawl of your worst tenants: anonymous links, external guests, company-wide shares and the app consents nobody remembers granting — scored, with the list of what to revoke.

Needs a read-only connection to your tenant.

Get my exposure report

Who is sending as you

SPF, DKIM, DMARC, BIMI and MTA-STS across your sending and parked domains, and what an attacker could send from the ones you forgot you owned.

Needs a domain name. Nothing else.

Check my domain

What your attacker sees first

TLS, certificates, security headers, cookies, DNS hygiene and exposed content on the public face of your estate — graded against the standards that define each one.

Needs a domain name. Nothing else.

Scan my site

The principle

Security stands above compliance

Not because compliance does not matter — it is a whole product here — but because a compliance control can be waived, and an attacker does not read your waivers.

Every framework has an exception process. A control gets accepted as a risk, signed off, and the report goes green. Nothing about the estate changed. Do that a few times across a few frameworks and you have built something worse than a gap: a documented, audited, board-reported sense of safety that does not correspond to anything real.

So the order is deliberate. The security finding is the fact. Compliance is an interpretation laid over that fact, and a waiver changes the interpretation only. In SeQontrol a waived finding is still a finding — it stays visible, it stays scored, and its exception carries a mandatory expiry that invalidates itself when the underlying problem changes shape. You can accept a risk. You cannot make it disappear from the screen.

That is what the three words under the logo are ordered by: secure first, because it is the thing that is actually true; compliant second, because it is provable once the first is real; confident last, because confidence earned in that order is the only kind worth having.

A posture panel in SecurityPortal, reading: tiers read scan evidence only — resolving,
                  accepting or waiving a finding moves nothing here. Clean is not the same as complete.
The principle, enforced in the product. A tier is earned by evidence from a scan. Waiving a finding does not move it — because a waiver changes the report, not the estate.
Underneath

Why running two products costs less than running two tools

The products share one console, one findings store and one audit trail. That is not an architecture diagram — it is the reason ShareCare's exposure shows up as CompliancePortal's evidence without anyone exporting a spreadsheet.

A finding becomes evidence

ShareCare finds an external share. SecurityPortal finds a Conditional Access gap. Both land in CompliancePortal already tagged to the controls they satisfy — so the thing you fixed is the thing your auditor sees, with no export in between.

Each product asks for its own consent

Every product has its own Entra app, scoped to what that product needs — so nothing inherits permissions it has no use for, and revoking one product revokes exactly one. Adding a product is a second consent, through the same onboarding you already know.

Every product answers to the same trail

Whatever any product checked, changed or waived is in one hash-chained record you can show a client or an auditor. Waivers expire on their own; nothing quietly stays green.

Licensing

What each licence includes: see it, govern it, act on it

Most products are sold on one ladder. You buy the depth you actually want, and the step that writes to your tenant is always a deliberate, separate decision.

Tier 1

Visibility

See it
  • Full inventory and continuous scanning
  • Risk scoring and findings
  • Reporting and exports
  • Read-only. Nothing is written to your tenant
Tier 3

Automation

Act on it
  • Everything in Governance
  • Automated remediation and write-back
  • Gated twice — by the license and by the connector's own consent

Scanning is never metered. No per-scan pricing, no charging per finding, no hard cap that stops a scan for a commercial reason. You are billed on the size of the estate — a number you already know before you buy.

Before any of that

One product needs nothing from you at all

WebScan reads what any anonymous visitor reads. No tenant, no Entra app, no admin consent, no onboarding, no call. Send one URL and it goes looking for the rest — then grades everything it finds, with the standard behind each failure and the fix.

And it does not stop being free. The complete scanner is included with every SeQontrol tenant — one URL at a time, fire and forget, for as long as you keep the tenant and with no expiry date on it. The licence buys what happens after the scan: history, schedules, alerts, evidence.
Before you ask

The three reasons people do not buy this

All three are reasonable. Two of them are sometimes right, and we would rather say which.

“Microsoft already gives me this.”

For one tenant, one administrator and no reporting obligation — largely true. Secure Score, Purview and SharePoint Advanced Management ship with your licence and you should start there. A tool you already own and will actually check beats one you buy and ignore.

It stops being true when you need evidence that a control held over a period, or when you manage sixty tenants and nothing native spans them. The four specific gaps.

“We already run CIPP.”

Good, and keep running it. CIPP administers tenants and it is free; nothing here replaces that, and a provider running both is the normal case rather than an awkward one.

What it was not built to do is retain a control-tagged record that something held over time. That does not matter until an insurer, an auditor or a client's customer asks — and then it is the only thing that does. The honest split.

“I am not letting a vendor write to my tenant.”

Correct instinct, and you do not have to. Scanning is read-only. The permission that writes is a separate consent you may never grant, and every read-only product keeps working without it.

If you do grant it, each change is approved on its own, and a refusal from your directory is recorded as a refusal rather than retried quietly. What we do with the access.

Start with one tenant and one question

The usual opener is a scoped assessment: your worst few tenants, a real crawl, and a report you can act on — whether or not you buy anything afterwards.