Running a security review
A security review stands or falls on the evidence behind it. CrossTenant gives you what to put in front of the client: a scored posture for every tenant, a verdict for every control, and the record behind each one.
Prefer email? Get in touch and we run onboarding with you.
What's included
Worst-first health scores
A weighted security health score for every tenant in your book, sorted worst-first so the customer most exposed is the first one you open. When a read fails, that section is marked not assessed and excluded from the calculation: a score is never inflated by data the console could not fetch.
CIS-aligned assessment
The review grades every control in CIS Google Workspace Foundations guidance: pass, fail, or partial, each verdict paired with what was read to reach it. Where Google's APIs do not expose a setting, the control is reported as not checkable rather than quietly passed: honesty about coverage is part of the evidence.
Cyber Essentials evidence pack
An evidence pack built from Workspace data for the Cyber Essentials conversation: it covers the controls a Google Workspace tenant can evidence and declares the ones it cannot, since firewalls and on-device malware protection sit outside Workspace scope. The pack states its own boundaries.
Email authentication checks
Per-domain checks for SPF, DKIM, DMARC, MTA-STS, TLS-RPT, and BIMI, each with a verdict, the parsed record as evidence, and a one-line remediation. When a customer asks why their invoices land in spam, the answer and the fix sit on the same screen.
Policy drift detection
Capture the configuration you agreed with the customer as a baseline, then diff each tenant's live policy snapshot against it, with every deviation graded warn or critical. Drift is measured against the standard you set, not a vendor default: the review shows exactly where a tenant has moved.
Client-ready reports
The review renders as a branded PDF under your own logo: scores, verdicts, and the evidence behind them, in a document the client keeps. Reports & alerts can send the same report on a schedule, so the next meeting starts from a fresh one.
Aligned to CIS Google Workspace Foundations guidance rather than certified by it: certification needs an accredited assessor, so CrossTenant gathers and dates the evidence and leaves the judgement with you. A passing score is not a Cyber Essentials certificate. DNS results are point-in-time and stamped as such, because SPF, DKIM, and DMARC records change outside Workspace. Edition-gated checks are shown as unavailable rather than silently passed.
The review
Walk into the review with evidence
CrossTenant scores the whole book against the frameworks your customers get asked about, so the evidence exists before the meeting does. There's a free tier for your own tenant while you evaluate.