Website and Microsoft 365 security
Know what your website exposes, and how your Microsoft 365 is really set up.
Your website changes every time someone updates a plugin or renews a certificate, and nobody is watching what those changes expose. We test it continuously and report in plain English. We also read your Microsoft 365 and show you how it is actually configured, free on every plan. And when you need to evidence your security position to somebody else, the same platform does that too.
// Available now · included on every plan
Microsoft 365 Security Connector
Included on every plan
Your website is only half the picture. Most of your business runs inside Microsoft 365: the email, the files, the logins. Connect it and see what Microsoft already knows.
How your Microsoft 365 is set up
Your Microsoft Secure Score, and the settings behind it, tracked over time.
Who can actually get in
Which staff have multi-factor authentication, and which administrators do not. Needs Entra ID P1: Business Premium, not Business Standard.
What to fix, in order
Microsoft’s own fix for each issue, most valuable first, linked straight to where you make it.
Whether it is improving
A 90-day trend, and how you compare with businesses your size.

Vulnerability Testing as a Service
Continuous, automated testing of your websites and the internet-facing services they expose.
Your website changes every time someone updates a plugin or ships a new page, and nobody is watching what those changes expose. We test it continuously and score what we find in plain English, so you find out before somebody else does.
From$9.99per website / monthFull pricing →
No minimum: buy one website or fifty. A free account covers one, scanned monthly, no card.
01 · Discover
We map what your domain exposes: services, ports, certificates, technology.
02 · Test
Known-vulnerability templates, WordPress checks, TLS review, and a real browser.
03 · Score
Findings become one score, with the reasoning shown rather than hidden.
04 · Alert
You hear from us when a scan finishes, and when a site goes down.
05 · Report
A report you can read, share or brand as your own, and it feeds your evidence.

Essential Eight GRC
Governance, risk and compliance for the ASD Essential Eight, at Maturity Level 1: all 48 controls.
An insurer, a tender or a big client has asked you to evidence your security position, and a scan report does not answer that. We take you through every control and produce a signed report you can hand over.
The Essential Eight is an Australian framework. Outside Australia it usually matters for one reason: an Australian client, parent company or tender has asked you to evidence your position against it. If that is you, this does the job. If your obligation is Cyber Essentials, NIST or NIS2, start with the testing above and talk to us about what is coming.
From$54.99per company / monthFull pricing →
Sold on its own, no scanning plan required. Your first company licence includes a 14-day free trial.
01 · Scope
Business units, locations, domains. Anything excluded needs a reason.
02 · Assess
Work through the controls at your own pace, recording what you do and how you know.
03 · Evidence
Attach the proof. Your scan findings are already there for the controls they cover.
04 · Review
A readiness check confirms nothing is outstanding: that you finished, not that you passed.
05 · Sign off
You attest to the findings and the report becomes final, with a link you can send on.

// Better together
The scan does not just tell you. It tells your assessment.
Compliance work is mostly re-typing things you already know. These two share a spine, so the part that can be automatic already is.
Evidence that gathers itself
Scan findings attach themselves to the Essential Eight controls they evidence, dated and in plain English. Nothing is re-keyed into a spreadsheet.
One platform, one login
Testing and compliance share the same companies, team and dashboard. Add a website to a company and it is in that company’s compliance picture too.
Honest by design
Weak evidence is labelled weak, and an unsigned report says so on its face. A report that overstates your position is worth nothing to whoever you hand it to.
Australian-owned, Australian-hosted
Built and run in Australia, with hosting and storage in one jurisdiction, not spread across whichever regions a global provider is using this quarter.
Four patch-applications controls, and one covering administrative privileges.
- Scanning covers what is reachable from the internet. Most Essential Eight controls are about how your business runs internally.
- You assess the rest yourself, with your own evidence. That is the work, and no product removes it.
We would rather give you the real number than imply a larger one. Read what the Essential Eight actually asks for →
// Straight answers
Including the ones where the answer is no
- Is the Essential Eight relevant outside Australia?
- Sometimes, and we would rather say so plainly. It is the Australian Signals Directorate’s framework, and if your obligations are Cyber Essentials in the UK, NIST or CMMC in the US, or NIS2 in Europe, it is not the standard you will be measured against. Where it does matter overseas is supply chain: an Australian client, parent company or government tender asking you to evidence your position. Our website testing, on the other hand, is the same job in every market.
- Can I be certified as Essential Eight compliant?
- No, and neither can anyone else: there is no certificate and no body that issues one. It is a maturity model: you self-assess, or have someone assess you. What you can produce is a defensible, dated, signed assessment. There is no audit fee on top, because there is no audit.
- Is the Essential Eight report an independent assessment?
- No. It is a guided self-assessment, and the report says so on its face. You record your own position; we structure it, hold the evidence and produce something defensible. If you need someone other than yourself to assess you, that is a consulting engagement.
- Is this a penetration test?
- No, and we will not describe it as one. This is automated testing of what your websites expose. A penetration test is a person actively trying to break in: a different engagement at a different price. Ask us if you need one.
- Where is my data held?
- In Sydney, Australia. So yes, your data is transferred out of your own country, and we would rather say that plainly than bury it. Hosting and storage are Australian end to end and the business is Australian-owned, which means one jurisdiction and one legal regime rather than your evidence being spread across whichever regions a global provider happens to use that quarter. The transfer is covered by Standard Contractual Clauses and equivalent safeguards, and our data processing terms and full sub-processor list are published on our DPA and sub-processors pages.
- Can I try it before paying?
- Yes. Scanning has a free tier with no card required, and Essential Eight includes a 14-day free trial on your first company licence.
Start with a free test of your website.
No card required. Add Essential Eight when somebody asks you to evidence your position, not before.
