Product
Most third-party GRC platforms ask you to copy your riskiest data — your risk register, your audit findings, your control gaps — into someone else's SaaS. Checkpoint doesn't. Every record is a SharePoint list in your own Microsoft 365 tenant; posture checks read your live Entra, Intune and Defender signals via Microsoft Graph and never leave your browser.
Checkpoint is included in every engagement — it's how we deliver, not a separate product you buy. It's provisioned in your tenant on day one, and it stays there: if you ever stop working with us, your registers, evidence and audit trail don't get walled off in our database, because there is no our database. They're already yours.
Unlike Vanta or Drata, nothing here is gated behind a sales call — the demo below is the actual console. Prefer the mechanics first? See how it works, end to end →
Before you dive in
Vanta and Drata gate their product behind a discovery call. We don't think that's necessary — what opens below is the actual application, not a sales deck, running against a fictional demo tenant.
Checkpoint has no backend and no database. It's a static web app that signs you in with your own Microsoft account, reads your tenant's security posture read-only, and stores every register as SharePoint lists you already own, govern and back up.
Risks, actions, controls, evidence, audit trails — all SharePoint lists in your tenant, inheriting your permissions, retention and versioning. Off-boarding us costs you nothing: the data was always yours.
Sign-in requests read-only Microsoft Graph access. MFA coverage, Conditional Access, PIM usage, guest accounts, device compliance, risky OAuth grants and Secure Score — measured live, never guessed from a spreadsheet.
Every scan exports the raw Graph data behind each check as timestamped, SHA-256-hashed JSON into your document library, auto-linked to the controls it satisfies. When the auditor asks "prove it", it's already filed.
Guided tour
Not a product roadmap slide — this is the actual sequence a Checkpoint-run engagement moves through, from first scan to standing in front of the board. Want the mechanical version — sign in, deploy, scan, report, remediate, certify, with the data-flow at each step? Follow the full flow →
Step 01 of 07
Every control, across every framework you're pursuing, laid out as one map — colour-coded by status, cross-referenced wherever frameworks share a control. Overlap is visible on day one, not discovered in week six.
Control Constellation
Step 02 of 07
The projected audit-ready date is a straight line drawn from your last eight weeks of real velocity — controls actually implemented, not controls promised on a kickoff call. Under three weeks of history, it says so honestly instead of inventing a number.
Certification Journey
Step 03 of 07
Each ring is a control theme; the arc is how much of it is actually implemented; the colour band moves from grey to gold to green as evidence lands behind it. The centre number is the one figure a CFO or an auditor actually wants.
Compliance Fingerprint
Step 04 of 07
A 26-week activity strip — scans, evidence captured, attestations, reviews, audits — rendered as a four-step gold intensity ramp. A quiet strip is exactly as informative as a busy one, and it never lies.
Assurance Pulse
Step 05 of 07
Checkpoint keeps the governance cadence running quietly in the background between audits, so the week before a surveillance visit looks like every other week.
Running quietly, every week
Step 06 of 07
When it's time to prove it — to the board, to procurement, to the auditor — Checkpoint switches to a full-screen, auto-cycling six-slide deck built from the same live data you've been working in all along.
Boardroom Mode
Step 07 of 07
AI, on your terms
Checkpoint's AI drafts policy language, evidence descriptions, risk treatment notes and questionnaire answers — grounded in your own registers, never invented. It has no tool or function calling, so it cannot take an action; every response comes back as text and one line that never changes:
"AI-assisted draft — review before use."
And it runs on your own Azure OpenAI resource — provisioned in your tenant, reached with your own Entra ID token. No API key, ever sent to us. No Compliance365-hosted endpoint in the loop at all.
The governance rails
Also inside
Sign-in requests read-only scopes. Write access to your SharePoint is requested separately, the first time it's needed — and an admin consents to each step explicitly.
Strict Content-Security-Policy, no CDN dependencies, content-hashed assets with subresource integrity, and a tamper-evident append-only audit log.
Every register change is versioned by your own SharePoint, every material action is written to the audit log, and every scan's raw evidence is hashed and filed.
Try the demo in two clicks, or book a 30-minute walkthrough and we'll run a read-only posture scan against your real tenant — you'll leave with your actual gaps, not a sales deck.
Hi! I’m the Compliance365 AI. I can help you work out which security or privacy framework you need, explain what’s involved, and answer questions about ISO 27001, SOC 2, Essential Eight, and more.
What can I help you with today?
Messages are sent to our AI assistant (Claude, by Anthropic) to generate a reply — not stored as part of your account and not used to train AI models.