Multi-cloud & identity posture

Know where your whole cloud and identity estate stands.

AssessTron runs 673 read-only checks across Microsoft 365, Entra, Azure, AWS, Google Cloud and Workspace, Snowflake, Alibaba, OCI, Baidu, and on-prem Active Directory and VMware. You get back a prioritized roadmap and an executive report in the frameworks your auditors ask for.

read-only · consent-based · your data stays yours

Contoso · azure rollupexample
Assessed
62
ground truth
Residual
74
+ controls
Accepted
3
carried
Posture by subscription
prod-core62
prod-data71
sandbox44
M365 & EntraAzureAWSGoogle CloudWorkspaceSnowflakeAlibabaOracle CloudBaiduActive DirectoryVMware vSphere
673
read-only checks
23
assessment modules
11
cloud & on-prem platforms
20
framework mappings
One assessment, four deliverables

The whole estate, in the formats people actually use.

Every scan produces the full package from one source of truth, so the workbook, the deck, the report, and the live dashboard never disagree.

xlsx

Technical workbook

Every finding with evidence, remediation, framework mappings, and a subscription or account column.

pptx

Executive deck

Posture, roadmap, and a posture-by-subscription slide for the board conversation.

docx / pdf

Narrative report

Methodology and scope stated plainly, with a per-subscription section your auditors can use.

web

Live dashboard

A triage worklist and trend over re-scans, segmentable by subscription or account.

Honest posture

An assessed score no client action can quietly move.

Clients suppress findings with compensating controls or accepted risk, and a Fentron operator approves each one. You keep the technical ground truth alongside the client’s residual view.

  • AAssessed. Severity-weighted posture that ignores every disposition.
  • RResidual. Compensating controls credited. A bogus one can’t inflate it, because an operator has to approve.
  • XAccepted exposure. The risk being carried, time-boxed with a review date and a defensible register.
Risk · compensating controlsexample
Assessed
62
Residual
74
Accepted
3
AZURE-008 · Key Vault soft-delete. Compensating control approved, review 2026-12-01.
AZURE-042 · SQL public access. Risk accepted, carried on the register.
A portal clients actually use

Self-service, without handing over the raw grid.

Client portalexample
74your posture · residual · trending up
What needs attention: 2 critical, 5 high, with client-readable remediation
↓ xlsx↓ pptx↓ docx↓ pdf

download shown for a premium-plan, manager-tier client

Role-based access per assessment. Clients see a curated dashboard, propose dispositions, and pull their own full report when their contract plan allows. Everything else stays operator-only.

  • Viewer → Manager tiers, stack-scoped, set per assessment.
  • Contract-gated report pull. Deliverables release only when the plan allows.
  • Curated by design. Never another client’s data, and every access change is audited.
Coverage & frameworks

Grounded in real scores, mapped to your standards.

CoverageMicrosoft 365 · Entra · Exchange & Defender · SharePoint · Teams · Purview · Power Platform · Power BI · Intune · Azure · AWS · Google Cloud · Workspace · Snowflake · Alibaba · Oracle Cloud · Baidu · on-prem Active Directory · VMware vSphere / ESXi
Mapped toNIST CSF 2.0 · NIST 800-53 · 800-171 / CMMC · HIPAA · SOC 2 · ISO 27001 · PCI DSS 4.0 · CISA SCuBA · CIS M365 / Azure / AWS / GCP / Workspace / Snowflake · MITRE ATT&CK
Grounded inMicrosoft Secure Score · Azure Defender for Cloud · per-provider posture scores. Findings describe configuration at scan time, never fabricated.