199 checks. 4 frameworks. Actionable remediation for every finding.
Comprehensive coverage across industry-leading benchmarks and best-practice guides.
v1.3.0 — Industry-standard security configuration benchmark with Level 1 and Level 2 profiles for graduated hardening.
Based on official ScubaGoggles baselines. Federal-grade security controls for Google Workspace environments.
Google's own Security Checklist and vendor-recommended best practices for Medium & Large Businesses.
Curated checks from hands-on practitioner experience and industry best practices beyond the major frameworks.
Every service area audited with framework-mapped checks and remediation guidance.
User accounts, super admins, MFA enforcement, org units
DMARC, SPF, DKIM, spam, phishing, DLP, forwarding
Sharing, external access, DLP, desktop sync
External sharing, interop, appointments
History, external access, DLP, reporting
Join controls, recording, host management
External access, creation, visibility
MFA, SSO, session management, recovery, app access
Membership, API access, roster import
Unlicensed access, alpha features
App restrictions, allowlisting
Site creation, external sharing
Audit logging, alert rules
From authentication to actionable report in minutes, not weeks.
Service account or OAuth 2.0. Connect to your GWS tenant in minutes.
Automated data collection from 11 Google APIs and DNS records.
Run 199 checks across 4 frameworks with intelligent pass/fail logic.
HTML dashboard, JSON, CSV exports. AI-powered analysis.
Powerful features to streamline your Google Workspace security auditing workflow.
Chat with your findings. Get remediation guidance in natural language. Supports OpenAI, Anthropic, and AWS Bedrock.
Plotly Dash dashboard with compliance views, drill-down, filtering. Real-time exploration of audit results.
HTML report with executive summary, JSON for automation, CSV for spreadsheets. All generated in one run.
Run as a Docker container, in GitHub Actions, or as a cron job. Built for automation pipelines.
Audit specific OUs or the entire organization. Scoped checks for complex GWS deployments.
Cache API data for re-analysis. Run checks against cached data without re-authenticating.
Start with the open-source edition or get a full-featured trial. Either way, your first audit is minutes away.