The Microsoft 365 security team you do not have.
Cipher watches your Microsoft 365 security around the clock, shows you exactly where you are exposed, and hands you the fixes. All read-only, so it never touches your emails, files, or data. Meet it free in minutes, no account needed to start.
Or take the 2-minute self-assessment.
Sample result
Four ways to see where you stand, by Spartan Tek Solutions
Every one is read-only. The first two need no account at all. Pick any starting point and act now.
Public exposure report
Grade your public email, domain, and website security from public DNS and your live site. No login, no connection, verdicts not data.
Check your exposureSelf-assessment grade
Answer about 15 questions and get a security grade before you connect anything. Two minutes, nothing shared with anyone.
Take the self-assessmentMicrosoft 365 scan
Connect read-only and meet your security team: your real Microsoft 365 score, ranked alerts, and a full findings list.
Run the free scanMonitor
Turn findings into action: step-by-step fixes, compliance mapping, audit-ready reports, and continuous re-scans that catch new drift.
Start with a free scanYou can't protect what you can't see
Open sharing links, third-party apps, and "sign in with Microsoft" connections pile up quietly until your data is reachable in ways no one chose on purpose. Cipher reads your Microsoft 365 settings, read only, and shows you whether your tenant is configured to let data leak, so you can close the gaps before someone finds them.
- Anyone-with-the-link sharing: on or off
- Which third-party and AI apps staff can connect
- Whether "private" workspaces are actually private
Watch a scan resolve in real time
This is a sample run on demo data. Press the button and see how your free results take shape: score, ranked alerts, and clear findings.
- A compliance score. A single number and letter grade summarizing your posture against HIPAA safeguards.
- Ranked risk alerts. The issues that matter most, ordered by severity, so you know what to look at first.
- A full findings list. Every check, marked pass, fail, or review, each with a clear summary.
- A downloadable problem summary. A clean PDF of your open issues you can keep on file or share internally.
The free scan shows you what to fix. The exact step-by-step remediation, compliance category mapping, and audit-ready reports come with Monitor.
Run it on your environmentIs your environment compliant?
Spartan Cipher checks your security posture against HIPAA-aligned safeguards and shows you, in clear terms, where you stand and what to fix first. Take the 2-minute self-assessment to get a security grade before you connect anything. No account needed to start, and nothing is shared with anyone.
Take the self-assessmentThe good guys aren't the only ones using AI
Are you protected against the bad ones? Attackers now use AI to write convincing phishing and to run password and account-takeover attempts faster, cheaper, and at scale. The defenses that stop those attacks are exactly the ones Spartan Cipher checks. We do not detect AI or scan for AI tools. We tell you whether the defenses that blunt AI-accelerated attacks are actually in place.
What this is not
Spartan Cipher does not watch your traffic, detect AI, or claim to spot an attacker in the act. It is a read-only configuration check. It confirms that the basic defenses, the ones that make AI-accelerated phishing and password attacks far less likely to land, are switched on.
Defenses Spartan Cipher checks
- Multi-factor authentication enforced for every user, so a stolen password is not enough.
- Legacy sign-in methods that bypass MFA blocked.
- Dormant and former-staff accounts closed before they are abused.
- Administrator access kept tight and protected.
100% read-only. Your data never moves.
We only read your cloud environment's security settings and configurations. We never access emails, files, or your data, and we never make any changes to your environment. You can revoke access instantly from your admin console.
No mailboxes, no files, no documents. Only security configuration.
The scan reads your environment. It never writes, edits, or deletes anything.
Read-only Microsoft Graph permissions, granted once by your admin.
Remove access anytime from the Entra admin center. No email or call required.
From sign-in to findings in minutes
No installs. No passwords to share. Your administrator approves read-only access once, on Microsoft's own consent screen, and Spartan Cipher can then read your Microsoft 365 security settings, never your email, files, or data. Prefer no account at all? Start with the public exposure report, which needs no sign-in.
Sign in with your email
Go to app.spartancipher.com and enter your email. We send a one-tap sign-in link, so there is no password to create or remember. You can set a password later if you prefer.
Click "Connect"
Inside the app, click Connect. This sends your administrator to Microsoft's official consent screen. You are never asked for an admin password inside our app.
Your admin approves read-only access once
Microsoft shows your admin the exact permissions, all of them read-only. Nothing here can open mail or files. Your admin approves once, and that is the only approval ever needed.
Your score and findings appear
Spartan Cipher reads your settings and shows your security score plus a clear list of what is strong and what to fix. Re-scan any time, no re-approval needed.
What makes a scan succeed
- A Microsoft 365 account for your organization.
- An administrator who can grant read-only access once on Microsoft's screen.
Nothing else to set up
That is the whole list. No software to install, nothing to download, and no standing access to anything beyond your security settings.
Prefer zero standing access? Ask about our read-only collector script: it runs the same read-only checks in your environment and uploads a result, with no standing connection at all.
On Google Workspace? Google Workspace support is launching soon. Join the launch list and we will tell you the moment it is live. No account needed today to run the public exposure report.
What we access, and what we can never touch.
Spartan Cipher checks your cloud environment's security and compliance posture. It is read-only by design: it reads your security settings, never your data. It cannot open an email or a file, because it never asks your provider for permission to. Here is exactly what that means, in clear terms.
What Spartan Cipher reads
- Whether multi-factor authentication is enforced
- Whether old, insecure sign-in methods are blocked
- Your external file-sharing settings
- How many admin accounts exist and who they are
- Inactive accounts that should be turned off
- Whether staff can approve risky third-party apps
What it can never touch
- Email content (we never request mailbox access)
- Files and documents in your cloud storage
- Your emails, files, or any of your data
- Calendars or messages
- Nothing is ever changed; we only read, never write
- No passwords are seen or stored, ever
The exact permissions we request (all read-only)
| Permission | What it lets us check | What it does not include |
|---|---|---|
| Policy.Read.All | MFA, sign-in policies, app-consent settings | No mail, no files |
| SharePointTenantSettings.Read.All | External file-sharing configuration | No document contents |
| RoleManagement.Read.Directory | Who holds admin roles | No mailbox access |
| Directory.Read.All | Admin names, account inventory | No mail or file content |
| AuditLog.Read.All | MFA registration and last sign-in dates | Metadata only, no content |
| User.Read.All | Account list for inactive-account check | No mailbox, no files |
We deliberately do not request Mail.Read, Files.Read.All, or Sites.Read.All. Those are the permissions that would let a tool read your content, and we never ask for them.
Meet your security team free. Put them to work when you are ready.
The free scan introduces you to your security team. Monitor puts them to work: watching around the clock, fixing what is exposed, and keeping the proof.
- Compliance score & letter grade
- Ranked risk alerts
- Full findings list (pass / fail / review)
- Downloadable problem summary (PDF)
- We catch it the day your security drifts, so you do not have to remember to check.
- The exact fix for every exposure, worst first, with the proof it was closed.
- Every exposure mapped to the security control or HIPAA safeguard it relates to, when relevant.
- Audit-ready, dated reports for auditors, insurers, and client security reviews.
- A full security history that proves your posture is holding over time.
Prefer not to do it yourself? Spartan Tek can fix and manage it for you.
Google Workspace support is launching
Microsoft 365 is the live product today. Google Workspace support is on the way. Join the launch list and we will tell you the moment it goes live. We will not call Google support ready until it actually works.
Prefer email? Email us to join the Google launch list. In the meantime, the public exposure report works for any domain today, no account needed.
Meet the security team your Microsoft 365 is missing.
Start free with a public exposure check, no account needed, and see exactly where you are exposed in minutes. When you are ready, put your security team on the job for $49 a month, a fraction of an IT contract or a hire.