Products

All products stand alone, and share one platform

One console, one findings store, one audit trail, one onboarding flow. Consent is the part that is not shared: each product that reads your tenant has its own Entra application and asks for its own grant, scoped to what that product needs. So adding a product is a second consent — but it is never a second integration project, and no product carries permissions it has no use for. Two products need no grant at all: WebScan works entirely from outside, and PosturePortal reads what the others already wrote.

At a glance

Which product answers which question

ProductThe question it answersWrites to your tenant?
ShareCare What is over-shared, and what can Copilot reach? Yes — on the Automation tier, where the plane allows it
SecurityPortal Is the tenant configured safely? No — assessment and evidence only
WebScan What does our public surface look like to an attacker? No — it never writes anywhere
CompliancePortal Coming soon Can we prove the technical controls held, continuously? No — it maps, scores, evidences and attests
PosturePortal Under development So what? What do I show the client or the board? No — read-only by design
MailTrust Can someone spoof us, and how do we stop it safely? Yes — DNS write-back on the Automation tier
Dredd Under development What changed since we approved this, and who ratified it? Yes — approval-gated restore of the approved state
ConditionalAccessPortal Coming soon Do our Conditional Access policies actually cover what we think? Yes — approval-gated policy write-back

“Built” means the capability exists and runs today, and four of the eight are: ShareCare, SecurityPortal, WebScan and MailTrust. “Coming soon” means built and running but not on sale. “Under development” means not yet available. Where a plane is detected but not yet remediable, the product’s own page says so — and the limits page collects every one of these in one place, because we would rather label it plainly than let you find out in month two.

Three products, one loop

SecurityPortal finds the weaknesses. CompliancePortal turns them into evidence. PosturePortal puts the whole picture on one board. Two of the three are not released yet — the badges below say which is which, and the loop is not closed until they ship. Each is sold on its own; together they close the loop from "what is wrong" to "here is the proof" without a single manual hand-off.

Posture scanning

SecurityPortal Built

Continuous Microsoft 365 and Entra posture — Conditional Access coverage, MFA enforcement gaps, over-permissioned apps, risky sign-in patterns. Findings carry control tags so they land in CompliancePortal as evidence.

SecurityPortal
Control evidence

CompliancePortal Coming soon

Maps the findings you already produce onto the frameworks you care about, with attestation for the controls that cannot be automated, an evidence repository and time-boxed auditor access. Technical control evidence — not a whole-company compliance programme.

CompliancePortal
Single pane

PosturePortal Under development

Read-only by design. Aggregates findings, risk scores, trends, connector health and coverage from every product into one per-tenant and fleet-wide board, with saved views and annotations for client and board reporting.

PosturePortal

And the rest of the portfolio

Each of these is a complete answer to a question you are probably already being asked — and the scanning ones feed the same shared findings store.

Data access governance

ShareCare Built

What is shared outside, what is over-shared inside so Copilot can reach it, and who can fix it. Crawls seven planes app-only, scores by sensitivity and blast radius, and remediates with a grace window and undo.

ShareCare
External attack surface

WebScan Built

Finds and grades the public face of your organisation — subdomain discovery, certificate transparency, TLS, headers, cookies, DNS, exposed services and infrastructure. Needs no tenant and no consent, and the scan itself is free on every tenant; you pay to keep the results.

WebScan
Email authentication

MailTrust Built

SPF, DKIM, DMARC, BIMI and MTA-STS posture, real sender inventory from aggregate reports, a staged path to enforcement, and DNS records written in-product for supported providers.

MailTrust
Drift governance

Dredd Under development

Your approved configuration as a versioned baseline. Every deviation becomes a finding with two answers: revert it, or ratify it into the baseline. Both are recorded, attributed and versioned.

Dredd
Policy governance

ConditionalAccessPortal Coming soon

Conditional Access policy inventory and metering, baseline coverage gaps, and approval-gated policy write-back — on the Visibility / Governance / Automation ladder. Its Entra app asks for read scope only until write-back is consented separately. Not released yet.

Start with the one that hurts most

Most people start with one — usually ShareCare for Copilot risk, or MailTrust for spoofing — and add the others once the connection is already in place.