Automated Security Assessments, Packs & Intelligence Reports
The naked truth
about your security posture.
31 automated products — compliance assessments, deep-dive security packs, board-ready intelligence reports, and a new Copilot Assessments tier covering agent inventory, interaction compliance, and meeting insights. Essential Eight, NIST CSF, CMMC, NIS2, Cyber Essentials, MAS TRM, and more. Results in minutes, not weeks. No consultant. No agent installs.
Trusted by organisations across
Compliance Assessments
Choose your assessment
Framework-aligned automated assessments — Essential Eight, MCSB, CIS, NIST CSF, CMMC, NIS2, CPS 234, MAS TRM, Cyber Essentials. Each report maps to the framework auditors and regulators expect.
Essential Eight ML1, ML2 & ML3 Assessment
AUCloud Security Benchmark v2 Assessment
GlobalCIS Microsoft 365 Benchmark Assessment
GlobalMicrosoft Copilot Readiness Assessment
GlobalCPS 234 Information Security Assessment
AURansomware Resilience Score
GlobalPower Platform Security Assessment
GlobalNIST Cybersecurity Framework Assessment
USCMMC Level 1 & 2 Readiness Assessment
USNIS2 Directive Compliance Assessment
EUUK Cyber Essentials Readiness Assessment
UKSecurity & Industry Packs
Deep-dive security packs
Deep-dive packs by attack surface (identity, email, data, endpoint) or by industry vertical (finance, legal, healthcare). One score, one report, focused on the topic your team is being asked about.
Entra ID / Identity Hardening Pack
GlobalEmail Security Pack
GlobalSharePoint & Data Oversharing Pack
GlobalFinance / Fintech Security Pack
GlobalLegal & Professional Services Pack
GlobalEndpoint / Intune Compliance Pack
GlobalHealthcare Security Pack
GlobalAICD Governance Assessment
AUAssess your board's cyber security governance against the AICD Cyber Security Governance Principles (Version 2, November 2024). Combines automated M365 tenant analysis with a governance questionnaire completed by a nominated governance contact — with full privacy separation from the IT consent process.
Intelligence Reports
Board-ready security intelligence
Business-language reports for non-IT audiences — cyber insurance readiness, board cyber risk briefings, and investor-grade security due diligence.
Cyber Insurance Readiness Report
GlobalBoard Cyber Risk Report
GlobalProductivity Analytics
Prove the value of your M365 investment
M365 usage, licence waste, adoption heatmaps, and Copilot ROI — see exactly where your investment is paying off and where it isn't.
Licence Optimisation Report
GlobalAdoption & Usage Report
GlobalCopilot ROI Report
GlobalCopilot Assessments
Six audits for Microsoft 365 Copilot
Microsoft published a unified Copilot APIs surface — Package Management, Interaction Export, Chat, Retrieval, Meeting AI Insights. We turned each into a focused governance audit you can run on a customer tenant in under 15 minutes.
Copilot Readiness Audit
EXTENDEDCopilot ROI Report
Copilot Agent Inventory & Governance Audit
NEWCopilot Interaction Compliance Audit
NEWCopilot Synthetic Red-Team Probe
NEWProcess
Four steps. Under ten minutes.
Pay securely
Select your assessment and pay via Stripe. Takes two minutes. You'll receive a setup email immediately.
Grant read-only access
Click the link in your email. Sign in as Global Admin and click Accept on the Microsoft permission screen. That's it.
We do the work
Our platform runs the full assessment against your tenant automatically. No agents, no scripts to run, no consultant on-site.
Inbox delivery
Your scored HTML report arrives within 10 minutes. Per-pillar scores, all findings, and a prioritised remediation roadmap.
Security & Trust
We see your posture.
Nothing else.
baref00t requests the minimum permissions required to assess your configuration. We cannot modify, delete, or access your data.
Read-Only Permissions
We request only Directory.Read, Policy.Read, and DeviceManagement.Read scopes. We cannot write to your tenant in any way. Review the full permission list before consenting.
Revocable Instantly
Remove our access anytime from Entra ID → Enterprise Applications. Takes 30 seconds. No call required, no notice period.
Regional Data Processing
Assessments run in the Azure region closest to you — Australia East, US East, West Europe, or Southeast Asia. Your data never leaves the region it's processed in.
No Data Retention
We don't store your tenant configuration data. Only the report output is retained — accessible only via the secure link sent to you.
Transparency
Exactly what we request. Nothing more.
// Microsoft Graph — Application permissions
// Type: Read-only. Cannot write or delete.
Directory.Read.All // users, groups, roles
Policy.Read.All // Conditional Access
Organization.Read.All // tenant info
AuditLog.Read.All // sign-in logs
RoleManagement.Read.All // PIM, role assigns
DeviceManagement
.Configuration.Read.All // Intune policies
UserAuthenticationMethod
.Read.All // MFA methods
IdentityRiskEvent.Read.All // risky sign-ins
Reports.Read.All // usage reports
SecurityEvents.Read.All // security alerts
Sites.Read.All // SharePoint sites
SharePointTenantSettings
.Read.All // SP tenant config
GroupMember.Read.All // group membership
Application.Read.All // app registrations
InformationProtection
.Read.All // sensitivity labels
// Azure RBAC (optional — for Defender checks)
Security Reader // read-only
Reader // read-only- READCannot write, modify, or deleteAll permissions are Application-type read-only scopes. There is no mechanism in our app registration to perform write operations.
- READAdmin consent required onceA Global Administrator must click Accept on the Microsoft consent screen. This is standard practice for any third-party M365 integration.
- READToken stored encrypted in Key VaultYour tenant access credential is stored in Azure Key Vault with HSM-backed encryption. It's never logged or transmitted outside Azure.
- READRevoke from Entra ID at any timeEntra ID → Enterprise Applications → baref00t → Delete. Instant revocation. No support ticket required.
FAQ
Common questions
How is this different from Microsoft Secure Score?
Which frameworks and regions do you cover?
What is a Copilot "probe account" and when do I need one?
What happens if a check fails?
Can I bundle multiple assessments?
Do you support multi-tenant or MSP use?
How do I revoke access after the assessment?
Where is my data processed?
What currencies do you accept?
Do I need CMMC Level 1 or Level 2?
Is the E8 assessment suitable for PSPF compliance?
What does the NIS2 assessment cover?
How does the Ransomware Resilience score work?
Ready to see the naked truth?
Get your security assessment report in under 10 minutes.
No consultant. No agent installs. No surprises.
Contact
Get in Touch
Have questions about our assessments? We’d love to hear from you.