100% read-only · verdicts, not your data

The Microsoft 365 security team you do not have.

Cipher watches your Microsoft 365 security around the clock, shows you exactly where you are exposed, and hands you the fixes. All read-only, so it never touches your emails, files, or data. Meet it free in minutes, no account needed to start.

No account to start No credit card Results in seconds
Live sample
scan · acme-dental.com
M365 · read-only
MFA enforcedPass
Legacy auth blockedPass
Admin roles scopedPass
App consent restrictedReview
External sharing limitedPass
87/100
Compliance score
B+

Sample result

What you can do right now

Four ways to see where you stand, by Spartan Tek Solutions

Every one is read-only. The first two need no account at all. Pick any starting point and act now.

Free · no account

Public exposure report

Grade your public email, domain, and website security from public DNS and your live site. No login, no connection, verdicts not data.

Check your exposure
Free · no account

Self-assessment grade

Answer about 15 questions and get a security grade before you connect anything. Two minutes, nothing shared with anyone.

Take the self-assessment
Free

Microsoft 365 scan

Connect read-only and meet your security team: your real Microsoft 365 score, ranked alerts, and a full findings list.

Run the free scan
Paid

Monitor

Turn findings into action: step-by-step fixes, compliance mapping, audit-ready reports, and continuous re-scans that catch new drift.

Start with a free scan
Who and what can reach your data

You can't protect what you can't see

Open sharing links, third-party apps, and "sign in with Microsoft" connections pile up quietly until your data is reachable in ways no one chose on purpose. Cipher reads your Microsoft 365 settings, read only, and shows you whether your tenant is configured to let data leak, so you can close the gaps before someone finds them.

  • Anyone-with-the-link sharing: on or off
  • Which third-party and AI apps staff can connect
  • Whether "private" workspaces are actually private
Check your public exposure
Reachabilityacme-dental.com
Anyone-with-the-link sharing Off
Third-party and AI app access Review
"Private" workspace privacy Review
What you'll see

Watch a scan resolve in real time

This is a sample run on demo data. Press the button and see how your free results take shape: score, ranked alerts, and clear findings.

--/100
Compliance score
Ready to scan
MFA enforced for all usersFail
Admin accounts protected by MFAPass
User app consent restrictedReview
Stale accounts disabledFail
Legacy authentication blockedPass
Step-by-step fix + compliance mapping + verification available with Monitor

  • A compliance score. A single number and letter grade summarizing your posture against HIPAA safeguards.
  • Ranked risk alerts. The issues that matter most, ordered by severity, so you know what to look at first.
  • A full findings list. Every check, marked pass, fail, or review, each with a clear summary.
  • A downloadable problem summary. A clean PDF of your open issues you can keep on file or share internally.

The free scan shows you what to fix. The exact step-by-step remediation, compliance category mapping, and audit-ready reports come with Monitor.

Run it on your environment
Compliance

Is your environment compliant?

Spartan Cipher checks your security posture against HIPAA-aligned safeguards and shows you, in clear terms, where you stand and what to fix first. Take the 2-minute self-assessment to get a security grade before you connect anything. No account needed to start, and nothing is shared with anyone.

Take the self-assessment
2 minutes No account to start Free security grade
B+
Sample HIPAA-aligned grade
FDCBA
The AI-era threat

The good guys aren't the only ones using AI

Are you protected against the bad ones? Attackers now use AI to write convincing phishing and to run password and account-takeover attempts faster, cheaper, and at scale. The defenses that stop those attacks are exactly the ones Spartan Cipher checks. We do not detect AI or scan for AI tools. We tell you whether the defenses that blunt AI-accelerated attacks are actually in place.

What this is not

Spartan Cipher does not watch your traffic, detect AI, or claim to spot an attacker in the act. It is a read-only configuration check. It confirms that the basic defenses, the ones that make AI-accelerated phishing and password attacks far less likely to land, are switched on.

Defenses Spartan Cipher checks

  • Multi-factor authentication enforced for every user, so a stolen password is not enough.
  • Legacy sign-in methods that bypass MFA blocked.
  • Dormant and former-staff accounts closed before they are abused.
  • Administrator access kept tight and protected.
Read-only by design

100% read-only. Your data never moves.

We only read your cloud environment's security settings and configurations. We never access emails, files, or your data, and we never make any changes to your environment. You can revoke access instantly from your admin console.

No content access.

No mailboxes, no files, no documents. Only security configuration.

No changes, ever.

The scan reads your environment. It never writes, edits, or deletes anything.

Least-privilege consent.

Read-only Microsoft Graph permissions, granted once by your admin.

Revoke in one click.

Remove access anytime from the Entra admin center. No email or call required.

How a scan works

From sign-in to findings in minutes

No installs. No passwords to share. Your administrator approves read-only access once, on Microsoft's own consent screen, and Spartan Cipher can then read your Microsoft 365 security settings, never your email, files, or data. Prefer no account at all? Start with the public exposure report, which needs no sign-in.

1

Sign in with your email

Go to app.spartancipher.com and enter your email. We send a one-tap sign-in link, so there is no password to create or remember. You can set a password later if you prefer.

2

Click "Connect"

Inside the app, click Connect. This sends your administrator to Microsoft's official consent screen. You are never asked for an admin password inside our app.

3

Your admin approves read-only access once

Microsoft shows your admin the exact permissions, all of them read-only. Nothing here can open mail or files. Your admin approves once, and that is the only approval ever needed.

4

Your score and findings appear

Spartan Cipher reads your settings and shows your security score plus a clear list of what is strong and what to fix. Re-scan any time, no re-approval needed.

Connecting takes about two minutes, one time.

What makes a scan succeed

  • A Microsoft 365 account for your organization.
  • An administrator who can grant read-only access once on Microsoft's screen.

Nothing else to set up

That is the whole list. No software to install, nothing to download, and no standing access to anything beyond your security settings.

Prefer zero standing access? Ask about our read-only collector script: it runs the same read-only checks in your environment and uploads a result, with no standing connection at all.

On Google Workspace? Google Workspace support is launching soon. Join the launch list and we will tell you the moment it is live. No account needed today to run the public exposure report.

Security overview

What we access, and what we can never touch.

Spartan Cipher checks your cloud environment's security and compliance posture. It is read-only by design: it reads your security settings, never your data. It cannot open an email or a file, because it never asks your provider for permission to. Here is exactly what that means, in clear terms.

What Spartan Cipher reads

  • Whether multi-factor authentication is enforced
  • Whether old, insecure sign-in methods are blocked
  • Your external file-sharing settings
  • How many admin accounts exist and who they are
  • Inactive accounts that should be turned off
  • Whether staff can approve risky third-party apps

What it can never touch

  • Email content (we never request mailbox access)
  • Files and documents in your cloud storage
  • Your emails, files, or any of your data
  • Calendars or messages
  • Nothing is ever changed; we only read, never write
  • No passwords are seen or stored, ever
Why this matters: because Spartan Cipher never accesses your email, files, or data, none of your content ever flows through it. There is nothing sensitive for us to lose. You get the security findings without handing over a single record. The same read-only design is what makes it a clean fit for regulated workloads, including HIPAA and FTC Safeguards.
Measured against the standards auditors trust: Spartan Cipher's checks are aligned with CISA's Secure Configuration Baselines (SCuBA) for Microsoft 365, the same baselines U.S. federal agencies are directed to follow, and map to NIST SP 800-53 and the MITRE ATT&CK framework. You are not graded against our opinion, you are graded against the references your insurer, auditor, and clients already recognize.

The exact permissions we request (all read-only)

PermissionWhat it lets us checkWhat it does not include
Policy.Read.AllMFA, sign-in policies, app-consent settingsNo mail, no files
SharePointTenantSettings.Read.AllExternal file-sharing configurationNo document contents
RoleManagement.Read.DirectoryWho holds admin rolesNo mailbox access
Directory.Read.AllAdmin names, account inventoryNo mail or file content
AuditLog.Read.AllMFA registration and last sign-in datesMetadata only, no content
User.Read.AllAccount list for inactive-account checkNo mailbox, no files

We deliberately do not request Mail.Read, Files.Read.All, or Sites.Read.All. Those are the permissions that would let a tool read your content, and we never ask for them.

Free vs Monitor

Meet your security team free. Put them to work when you are ready.

The free scan introduces you to your security team. Monitor puts them to work: watching around the clock, fixing what is exposed, and keeping the proof.

Free scan
How you meet your security team. No card.
  • Compliance score & letter grade
  • Ranked risk alerts
  • Full findings list (pass / fail / review)
  • Downloadable problem summary (PDF)
Run Free Scan
Recommended
Monitor
Your security team, on the job.
$49/month
An IT firm to manage this runs $750+ a month. A person on staff is a salary. Cipher is $49.
  • We catch it the day your security drifts, so you do not have to remember to check.
  • The exact fix for every exposure, worst first, with the proof it was closed.
  • Every exposure mapped to the security control or HIPAA safeguard it relates to, when relevant.
  • Audit-ready, dated reports for auditors, insurers, and client security reviews.
  • A full security history that proves your posture is holding over time.
Start with a free scan

Prefer not to do it yourself? Spartan Tek can fix and manage it for you.

Google Workspace

Google Workspace support is launching

Microsoft 365 is the live product today. Google Workspace support is on the way. Join the launch list and we will tell you the moment it goes live. We will not call Google support ready until it actually works.

Prefer email? Email us to join the Google launch list. In the meantime, the public exposure report works for any domain today, no account needed.

Meet the security team your Microsoft 365 is missing.

Start free with a public exposure check, no account needed, and see exactly where you are exposed in minutes. When you are ready, put your security team on the job for $49 a month, a fraction of an IT contract or a hire.

No account to start No credit card Read-only