CrossTenant
Home / Use cases / Running a security review

Running a security review

A security review stands or falls on the evidence behind it. CrossTenant gives you what to put in front of the client: a scored posture for every tenant, a verdict for every control, and the record behind each one.

Prefer email? Get in touch and we run onboarding with you.

What's included

Worst-first health scores

A weighted security health score for every tenant in your book, sorted worst-first so the customer most exposed is the first one you open. When a read fails, that section is marked not assessed and excluded from the calculation: a score is never inflated by data the console could not fetch.

worst-first not assessed per tenant

CIS-aligned assessment

The review grades every control in CIS Google Workspace Foundations guidance: pass, fail, or partial, each verdict paired with what was read to reach it. Where Google's APIs do not expose a setting, the control is reported as not checkable rather than quietly passed: honesty about coverage is part of the evidence.

per-control verdicts evidence not checkable

Cyber Essentials evidence pack

An evidence pack built from Workspace data for the Cyber Essentials conversation: it covers the controls a Google Workspace tenant can evidence and declares the ones it cannot, since firewalls and on-device malware protection sit outside Workspace scope. The pack states its own boundaries.

workspace-scoped out-of-scope declared

Email authentication checks

Per-domain checks for SPF, DKIM, DMARC, MTA-STS, TLS-RPT, and BIMI, each with a verdict, the parsed record as evidence, and a one-line remediation. When a customer asks why their invoices land in spam, the answer and the fix sit on the same screen.

spf / dkim / dmarc mta-sts / tls-rpt parsed records

Policy drift detection

Capture the configuration you agreed with the customer as a baseline, then diff each tenant's live policy snapshot against it, with every deviation graded warn or critical. Drift is measured against the standard you set, not a vendor default: the review shows exactly where a tenant has moved.

your baseline warn / crit live diff

Client-ready reports

The review renders as a branded PDF under your own logo: scores, verdicts, and the evidence behind them, in a document the client keeps. Reports & alerts can send the same report on a schedule, so the next meeting starts from a fresh one.

branded pdf scheduled

Aligned to CIS Google Workspace Foundations guidance rather than certified by it: certification needs an accredited assessor, so CrossTenant gathers and dates the evidence and leaves the judgement with you. A passing score is not a Cyber Essentials certificate. DNS results are point-in-time and stamped as such, because SPF, DKIM, and DMARC records change outside Workspace. Edition-gated checks are shown as unavailable rather than silently passed.

The review

Walk into the review with evidence

CrossTenant scores the whole book against the frameworks your customers get asked about, so the evidence exists before the meeting does. There's a free tier for your own tenant while you evaluate.