Skip links

Built for Google Workspace

Is your
Google Workspace
actually secure?

Stop guessing. Our automated, read-only scanner instantly identifies misconfigurations and guides you step by step to harden your environment.

Let’s Get Started

The platform

One platform for a hardened Google Workspace

Workspace Audit replaces hours of manual clicking through the Admin Console with
a clear, prioritised plan to lock down your environment — and keep it that way.

See your full posture in one place.

A single dashboard scores your environment across every Google service, so you finally know where you stand — without digging through hundreds of admin pages.

100+ automated checks.

Compliance score by service

Filter by OU, Group or domain

Fix what matters first

Every finding is severity-rated and mapped to industry frameworks, with a direct fix-link straight into the Admin Console — so your team can act in minutes, not days.

Critical → Low severity ratings

CIS, SCuBA & Cyber Essentials mapping

One-click jump to the exact setting

Stay secure as you grow

Schedule recurring scans, get alerted when posture drifts, and prove progress over time with a full historical timeline and audit-ready reports.

Daily, weekly or monthly scans

Email alerts on drift

Exportable PDF & CSV reports

How it works

From sign-in to a secureWorkspace in three steps

No agents to install, no config files to maintain.
Just connect and scan.

Connect

Sign in with a Google Workspace super-admin account using read-only OAuth 2.0. No agents, no installs, no config files.

Scan

We run 100+ checks across Gmail, Drive, Calendar, Meet, Chat, Admin and more — usually finished in just a few minutes.

Fix

Work through severity-rated findings with one-click links straight into the Admin Console. Re-scan to prove it’s fixed.

Features

Everything you need to
secure your Workspace

From a single, automated scan to continuous posture monitoring.

Comprehensive Dashboard

High-level compliance score, severity breakdowns, and posture across every Google service.

Automated Monitoring

Schedule daily, weekly or monthly scans with email alerts when posture drifts.

Multi-Domain Support

Organisation View for MATs, MSPs, school districts, and holding companies — all domains in one dashboard.

Detailed, Actionable Reports

Filter by OU or Group, see the exact misconfiguration, and jump to the fix in the Admin Console.

Historical Timeline

Track every change to your security posture over time with full historical reports.

Read-Only & Secure

Strict OAuth 2.0, read-only access. We can never change settings or read your data.

Risk Center

Go beyond config. See real-world risk.

Posture scanning finds misconfigurations. Risk Center finds risky usage — shadow IT,
over-shared Drives, privileged accounts, weak DNS and at-risk users.

Third-Party Apps & Shadow IT

Stop unsanctioned AI tools and shadow SaaS quietly siphoning your Drive and Gmail data.

Shared Drives Risk Audit

Stop sensitive files leaking through Shared Drives still open to ex-staff and outside contractors.

Groups & Mailing Lists

Close the back door where one Group membership silently grants access to half your Drive.

Admin Roles & Privileged Access

Revoke the forgotten super-admin accounts an attacker would use to own your entire tenant.

DNS & Email Authentication

Stop attackers spoofing your domain to phish staff, customers and finance teams.

User Security Posture

Find the unprotected accounts attackers will compromise first — before they do.

Dashboard

A clear view of your entire security posture.

Compliance score at a glance, broken down by service. Drill into any finding, see the exact misconfiguration, and click straight through to fix it.

100+ security checks across every Google service

Severity-rated findings — Critical, High, Medium, Low

Filter by OU, Group, or domain

Export audit-ready PDF and CSV reports.

Security & Trust

Built for IT and security teams — and reviewed by them

Read-only by architecture. GDPR and FERPA aligned. We access only the security metadata needed to audit your Workspace — never the contents of your emails, files, calendars or chats — and we publish exactly which scopes we use and why.

  • Read-only OAuth scopes
  • GDPR & FERPA aligned
  • 180-day retention
  • Encrypted in transit & at rest

Read-only by architecture

We never read the content of emails, Drive files, calendar events, or chat messages — only the security metadata needed to audit your posture.

Standard OAuth 2.0 scopes

Sign in with Google using narrowly-scoped read-only permissions. Pro scans require explicit Domain-Wide Delegation you control and can revoke at any time.

Data minimisation

We store only the security metadata needed for reports and history — never email contents, files, chats or passwords.

Encrypted in transit & at rest

HTTPS everywhere, encryption at rest, and strict access controls limiting production data to authorised engineers for support only.

GDPR & FERPA aligned

Full GDPR data subject rights and a FERPA “School Official” posture for education customers. Reports auto-purged after 180 days.

No AI training on your data

Aggregated, non-identifiable data sent to Google’s enterprise Gemini API is never used to train public foundation models.

Ready to Transform Your Business?

Let us help you unlock your full potential today.

    We respect your privacy and do not tolerate spam and will never sell, rent, lease or give away your information