Service
Security Controls Assessment
Your cloud controls graded from live configuration, attested by the engineer who did the work, with a costed roadmap for what to fix first.
What it covers
Read-only assessment of the cloud environments you run — Microsoft 365, Azure, AWS, Google Cloud — plus your internet-facing domain, mail authentication and TLS posture.
Every control is scored from configuration we can see, with the evidence attached. Where a control cannot be evidenced from an API, it is attested by the engineer or reported as unassessed. Nothing is scored from a conversation.
Graded against the frameworks your obligations actually name — the Essential Eight, CIS, ISO 27001, PCI-DSS, NIST, SOC 2, HIPAA, MITRE ATT&CK and others. We confirm which apply to you at scoping rather than listing everything and letting you guess.
What you're paying for
The scanning is not the product. Open-source tooling does that, and any competent provider can run it. Four things are the product:
- A strict maturity rating. Graded at your weakest control, with unevidenced controls never counted as passes.
- Engineer attestation. Named, against evidence, for the controls no API exposes.
- A live findings and remediation readout. A working session where you can argue with the findings.
- A prioritised, costed roadmap. What to fix, in what order, and what it will take.
How we get access
Access is read-only in every environment, without exception, provisioned as a time-bound application registration rather than a user account. You create it, you can see exactly what it holds, and you can revoke it yourself at any moment without contacting us.
The scanning engines run on an RG Labs operator workstation in Australia, not on our hosted platform. Your credentials never reach it. The platform receives assessment results only — it has no ability to authenticate to your environment, connect to it, or act against it, even if the platform itself were compromised.
At the end of the engagement the credential is revoked with you, and local scanner output is destroyed. Revocation is confirmed in writing as part of handover. Full detail is on our trust page.
What it is not
- Not a penetration test. We read configuration; we do not exploit anything.
- Not a certification. No assessment we run makes you compliant with anything, and we do not issue certificates.
- Not a licence sale. We do not resell Microsoft, or anyone else. The report has nothing to sell you, which is the entire point of having us write it.
Scope and price
From $9,500 ex GST. Two to three weeks. Priced by the number of cloud environments and tenants in scope, quoted in writing before anything starts — there are no variable rates and no hourly billing.
Half of what you pay for it (after any Snapshot credit), capped at $5,000, credits against engineering work paid for within 90 days of paying for the assessment. If you want to see the shape of your findings first, a Snapshot credits in full against this assessment within 90 days of paying for the Snapshot.