Platform features

Everything in the SBCMSP platform

1,692 checks across four surfaces, ten compliance frameworks, AI remediation, monitoring and white-label reporting — explore every capability.

Get started Platform overview
Scan surfaces

Everything attackers and auditors can reach — external, internal, cloud and identity.

External Security Scanning

Continuously scan every client’s internet-facing attack surface: TLS, DNS, email authentication, exposed services, su…

Learn more

Attack Surface Management

Subdomain discovery, shadow-IT detection, third-party exposure mapping and a live port inventory — the full external …

Learn more

Deep Scan (EASM)

Over 4,000 CVE and template checks fire against every live host — KEV/EPSS-ranked, graded A–F and routed into the same findings queue…

Learn more

Windows Internal Agent

A lightweight Windows agent runs 324 internal checks across 18 core + 16 advanced modules: BitLocker, patching, local admin, AD attack p…

Learn more

SBCMSP Agent

Deploy once and the SBCMSP Agent reports continuously — per-host scoring, public-IP exposure scanning and identity fi…

Learn more

AWS Security Posture

168 checks across IAM, S3, EC2, CloudTrail, KMS and VPC — public exposure, weak IAM and misconfiguration flagged conti…

Learn more

Azure Security Posture

116 checks across Identity, Storage, Network, Key Vault, VMs, SQL and Defender — misconfiguration and public exposure …

Learn more

Microsoft 365 / Entra Assessment

126 checks on MFA coverage, conditional access, legacy auth, risky sign-ins, external sharing and tenant hardening, s…

Learn more

Google Workspace Security Posture

18 checks across 2-step verification, super-admin hygiene, risky OAuth apps, Alert Center and mobile posture — read-o…

Learn more

Google Cloud Security Posture

16 checks across IAM, public buckets, open firewalls, Cloud SQL, DNSSEC and log export — misconfiguration flagged per…

Learn more

Container & IaC Scanning New

32 Terraform and CloudFormation misconfiguration rules plus container SBOM CVE scanning, KEV/EPSS-ranked and on-deman…

Learn more

Public-Repo Secret Scanning New

Finds a client's leaked API keys, tokens and cloud credentials across public repos, gists and history — masked sample…

Learn more
Intelligence & remediation

Rank by real-world risk and guide the fix.

KEV / EPSS Intelligence

Every finding is enriched with CISA KEV listing status and EPSS exploit probability, so your techs fix what attackers…

Learn more

Threat Intelligence Feeds New

Public indicator-of-compromise feeds matched against every discovered asset — malicious IPs, domains and file hashes…

Learn more

Attack Path Correlation New

Correlate findings across external, deep-scan, endpoint and cloud into named attacker escalation routes — not a flat li…

Learn more

AI vCISO

A continuous virtual-CISO program that reasons over each client’s real multi-surface posture every night — briefings, …

Learn more

Score Projection

A color-coded score trend plus a projection that says “fix these 5 findings and this score goes from 83 to 97” — the …

Learn more

AI Remediation Guidance

Each finding pairs with AI-written, step-by-step remediation guidance — implementation steps, verification commands a…

Learn more

SLA Tracking & Escalations

Severity-driven SLAs (critical 24h, high 72h, medium 14d, low 30d) start the clock the moment a finding lands. Overdu…

Learn more

Active Defense

Turn a finding into a scoped, operator-approved action — disable a compromised Microsoft 365 account — behind a guardrail spine that keeps every step reversible and…

Learn more

AI Trust & Data Governance

Every client identifier is tokenized before any AI prompt and re-hydrated locally; evidence review stays text-only, with per-feature toggles and an activity…

Learn more

Approve-First AI Actions New

The in-app assistant proposes fixes as preview cards with a before/after diff — rescan a domain, set a finding's status, open a PSA ticket. Nothing runs until you click Apply…

Learn more

Remediation Campaigns New

Fix one recurring finding across every affected client, or patch one vulnerable package or CVE across the whole fleet, as a single approve-first campaign that proposes the fix per target…

Learn more

Security & Compliance Autopilots New

Control-drift detection that proposes a fix, an evidence-staleness review queue, a living security roadmap and one-click board packs — every change approve-first…

Learn more

Run your first scan free

See a client’s real posture in minutes — then unlock all 1,692 checks.