What SeQontrol does not do
Every limit worth knowing, in one place — including the ones a sales call would normally leave until month two.
Security software is bought on trust, and trust does not survive a discovered exaggeration. So here is the unflattering version, in one place, rather than scattered through the pages that are trying to persuade you.
Every product asks for its own consent
There is no single grant that switches the platform on. Each product that reads your tenant has its own Entra application and its own admin consent, scoped to that product's permissions — so adding a product means going back to an administrator, not flipping a switch. The upside is real: nothing inherits permissions it has no use for. But if you were told this was a one-consent platform, it is not, and you would have found out during onboarding.
Two products sit outside that shape. WebScan asks for nothing at all — no tenant, no consent, no agent — because it works from outside. PosturePortal connects to nothing of its own; it reads what the other products already wrote.
Revoking a product's admin consent revokes exactly one product's Graph access. It does not touch the grants sitting beside it: the Exchange management role, the Azure reader assignment, the Power Platform service principal registration and each DNS provider's OAuth authorisation are separate authorities and have to be removed separately. Write-back is a separate opt-in again, and Exchange admin, Power Platform, Azure and DNS each need their own one-time setup — and for DNS, in-product write-back is live for Azure DNS and DNSimple only, with every other provider getting guided manual steps. The platform page lists every step.
Some planes detect but do not (yet?) fix
Where one of our products remediates a plane app-only, it does. Exchange forwarding, SharePoint site roles, Power Platform and delegated-admin relationships are detected and reported rather than written back.
That is our gap, not Microsoft's, and this page used to say otherwise. Each of those planes has a documented application-only write path — certificate-based Exchange Online PowerShell, Sites.FullControl.All on the SharePoint admin APIs, a Power Platform service principal, DelegatedAdminRelationship.ReadWrite.All on Graph. In some cases we have not built the connector; in others we are unwilling to ask you for permission that broad in order to ship it. Either way the limit is ours to lift. When a product cannot safely act, it gives the precise reason rather than guessing or quietly failing.
Half the catalogue is not on sale yet
Four of the eight products run today: ShareCare, SecurityPortal, WebScan and MailTrust. ConditionalAccessPortal and CompliancePortal are built and running but not released. PosturePortal and Dredd are still being written.
Two of them have no price. Dredd is quoted rather than listed, because its licence unit is still being set; PosturePortal carries no number at all. And nothing unreleased has a date — ask, and you get an honest read on where it stands rather than a quarter.
Subdomain discovery is not a complete estate
WebScan finds hostnames two ways, and only one of them is immediate. The names carried on the certificate your site serves at scan time are read straight away — though a wildcard certificate names a shape rather than hosts and yields nothing to enumerate, and a shared CDN or load-balancer certificate can carry names that are not yours.
The rest come from public certificate transparency logs. We tail those logs from the day we add them rather than replaying their history, so we hold nothing logged before we started watching. That is our design and not a property of CT — the logs are append-only and can be read from their first entry — and it is a limit we could lift.
Certificates reach the logs within hours of issuance, so the delay is not the log's, it is ours. A name we never saw reaches us at its next renewal: about ninety days on a Let's Encrypt default, and potentially the better part of a year on a longer-lived commercial certificate.
We also do not follow every log that exists, and the set we do follow changes as the public logs themselves do — they are retired and replaced on a schedule the whole industry runs on. More to the point: a log starts counting for us on the day we add it. Adding one widens what we will see from that day forward; we do not go back and replay what it recorded before.
Which means an empty or short list is a statement about our coverage, not about your estate, and nothing in the product will present it as one. Read it as “what we have seen so far” and it is useful. Read it as “what exists” and it is wrong.
WebScan is not a penetration test
It grades configuration against published standards, from outside, as any visitor would. It attempts no exploitation, runs no fuzzing, and sees nothing behind a login. Active testing and authenticated scanning are on the roadmap; until they ship, a clean grade says the outside is configured well, not that the application is safe.
We are Microsoft-first
Microsoft 365 and Entra are the deep estate. Box sharing ships today with app-only revoke; Slack Connect is detect-only until the admin APIs exist to act on. Google Cloud and AWS are read-only connectors in CompliancePortal, which is built and running but not released yet. Everything else is roadmap, and we will not pretend otherwise on a sales call.
Readiness is not an audit opinion
CompliancePortal — built and running, not released yet — turns the continuous evidence the scanning products already produce into readiness for the technical controls on the platforms we support. The evidence underneath is continuous; the assessments themselves run when you raise one, not on a schedule. Your auditor still signs the opinion, and the controls that live in people and process are still yours to run.
We have not written down our own assurance yet
Product data lives in Microsoft Azure, West Europe, and that much is published. What is not: a subprocessor list, retention defaults per data class, and whatever certifications we do or do not hold. If your procurement needs those before you can buy, ask early — the honest answer today is that they are not written down, and we would rather say so here than have you discover it in a security questionnaire.
Why this page exists
Most vendors bury this and let you find out in month two. We would rather you knew before the first call, because every one of these limits is something you would eventually hit — and finding out late costs you more than it costs us.
If one of them is a dealbreaker, tell us and we will say so plainly rather than sell around it. Ask the awkward question.