Product

Checkpoint — the compliance console that lives in your tenant

Most third-party GRC platforms ask you to copy your riskiest data — your risk register, your audit findings, your control gaps — into someone else's SaaS. Checkpoint doesn't. Every record is a SharePoint list in your own Microsoft 365 tenant; posture checks read your live Entra, Intune and Defender signals via Microsoft Graph and never leave your browser.

Checkpoint is included in every engagement — it's how we deliver, not a separate product you buy. It's provisioned in your tenant on day one, and it stays there: if you ever stop working with us, your registers, evidence and audit trail don't get walled off in our database, because there is no our database. They're already yours.

Try the live demo — no sign-up Book a walkthrough

Unlike Vanta or Drata, nothing here is gated behind a sales call — the demo below is the actual console. Prefer the mechanics first? See how it works, end to end →

Before you dive in

This is the real console — with sample data

Vanta and Drata gate their product behind a discovery call. We don't think that's necessary — what opens below is the actual application, not a sales deck, running against a fictional demo tenant.

  • Sample data. A fictional tenant — nothing you touch is real, nothing you see is yours.
  • No sign-up. No account, no email, no password to invent.
  • Nothing installed. Runs entirely in this browser tab — close it and it's gone, no trace left behind.
Continue to the demo →

Your data never moves. That's the whole point.

Checkpoint has no backend and no database. It's a static web app that signs you in with your own Microsoft account, reads your tenant's security posture read-only, and stores every register as SharePoint lists you already own, govern and back up.

In-tenant by design

Risks, actions, controls, evidence, audit trails — all SharePoint lists in your tenant, inheriting your permissions, retention and versioning. Off-boarding us costs you nothing: the data was always yours.

Read-only posture scanning

Sign-in requests read-only Microsoft Graph access. MFA coverage, Conditional Access, PIM usage, guest accounts, device compliance, risky OAuth grants and Secure Score — measured live, never guessed from a spreadsheet.

Evidence that collects itself

Every scan exports the raw Graph data behind each check as timestamped, SHA-256-hashed JSON into your document library, auto-linked to the controls it satisfies. When the auditor asks "prove it", it's already filed.

Guided tour

One cycle, six phases — the same one every engagement runs on.

Not a product roadmap slide — this is the actual sequence a Checkpoint-run engagement moves through, from first scan to standing in front of the board. Want the mechanical version — sign in, deploy, scan, report, remediate, certify, with the data-flow at each step? Follow the full flow →

Step 01 of 07

See the whole surface before you touch a single control.

Every control, across every framework you're pursuing, laid out as one map — colour-coded by status, cross-referenced wherever frameworks share a control. Overlap is visible on day one, not discovered in week six.

  • Deterministic layout — the same control always lands in the same place, no guesswork
  • Cross-framework edges show exactly which controls do double duty
  • Filter by framework or drill into any single node

Control Constellation

Step 02 of 07

A projected certification date, computed — not promised.

The projected audit-ready date is a straight line drawn from your last eight weeks of real velocity — controls actually implemented, not controls promised on a kickoff call. Under three weeks of history, it says so honestly instead of inventing a number.

  • Milestone timeline from kickoff through to certification
  • The projection recalculates automatically as work lands
  • Insufficient history shows as 'insufficient history' — never a fabricated date

Certification Journey

Step 03 of 07

One glance answers 'how ready are we, really?'

Each ring is a control theme; the arc is how much of it is actually implemented; the colour band moves from grey to gold to green as evidence lands behind it. The centre number is the one figure a CFO or an auditor actually wants.

  • Live readiness rings, grouped automatically by control theme
  • Colour bands: grey (not started), gold (in progress), green (implemented)
  • An outer evidence ring — because 'implemented' and 'evidenced' are different claims

Compliance Fingerprint

Step 04 of 07

Proof it didn't stop the week after kickoff.

A 26-week activity strip — scans, evidence captured, attestations, reviews, audits — rendered as a four-step gold intensity ramp. A quiet strip is exactly as informative as a busy one, and it never lies.

  • Every scan, upload, attestation, review and audit logged automatically
  • Click any week to filter the activity feed to it
  • The gap an auditor looks for first — and the one this makes impossible to hide

Assurance Pulse

Step 05 of 07

Certification is a rhythm, not a finish line.

Checkpoint keeps the governance cadence running quietly in the background between audits, so the week before a surveillance visit looks like every other week.

  • Compliance calendar — review dates, renewal dates, nothing missed
  • Internal audit programme and management review, satisfying ISO 27001 clauses 9.2/9.3 continuously
  • Scheduled posture re-scans flag drift before an auditor finds it
  • Append-only audit log — every material action, timestamped

Running quietly, every week

Step 06 of 07

Press one button. Present live, not from screenshots.

When it's time to prove it — to the board, to procurement, to the auditor — Checkpoint switches to a full-screen, auto-cycling six-slide deck built from the same live data you've been working in all along.

  • One button, full-screen, presentation-ready
  • Six slides, auto-cycling: fingerprint, posture trend, journey, top risks, action throughput, milestones
  • Also exports: a Trust Center page and a time-boxed Auditor Pack your certifier can open without a licence

Boardroom Mode

Step 07 of 07

AI, on your terms

Proposes. Never writes.

Checkpoint's AI drafts policy language, evidence descriptions, risk treatment notes and questionnaire answers — grounded in your own registers, never invented. It has no tool or function calling, so it cannot take an action; every response comes back as text and one line that never changes:

"AI-assisted draft — review before use."

And it runs on your own Azure OpenAI resource — provisioned in your tenant, reached with your own Entra ID token. No API key, ever sent to us. No Compliance365-hosted endpoint in the loop at all.

The governance rails

  • Your Azure OpenAI, not oursChat completions only, against the resource you provisioned. No API key baked into the app — access is Entra RBAC on your own subscription.
  • No tool or function callingThe model literally cannot take an action. It returns text and a disclaimer — never a write, never an API call, never a side effect.
  • Grounded, or it says nothingA fixed system prompt refuses to invent control references, risk IDs, dates or figures that aren't already in your own data.
  • Never claims an outcomeIt will not state or imply a certification or audit has been passed — that determination belongs to your accredited auditor, always.
  • Audited and rate-limitedEvery request is logged and client-side rate-limited — the same one seam every AI feature is wrapped in, so nothing can skip the rails.
AI assistant
Compliance Copilot
Questionnaire assistant
Mock auditor

Also inside

Vendor risk register with data classification
Trust Center page, shareable with procurement
Time-boxed Auditor Pack, no licence required
Partner Console for firms running multiple clients

Built like the security tool it is

Least-privilege consent

Sign-in requests read-only scopes. Write access to your SharePoint is requested separately, the first time it's needed — and an admin consents to each step explicitly.

No third-party code at runtime

Strict Content-Security-Policy, no CDN dependencies, content-hashed assets with subresource integrity, and a tamper-evident append-only audit log.

Auditable end to end

Every register change is versioned by your own SharePoint, every material action is written to the audit log, and every scan's raw evidence is hashed and filed.

Full security & architecture page — every Graph permission, the tenant-boundary diagram, disclosure policy →

See it with your own data

Try the demo in two clicks, or book a 30-minute walkthrough and we'll run a read-only posture scan against your real tenant — you'll leave with your actual gaps, not a sales deck.

Try the live demo Book a walkthrough
Microsoft Teams