Know exactly what's exposed in your Google Workspace.
An independent, read-only audit across eleven areas of your Workspace. Every finding is explained in plain English, ranked by real risk, and yours to act on however you choose.

What gets checked
Eleven modules covering the settings that actually cause Workspace breaches, not a generic compliance checklist.
Identity & Access
MFA enforcement, super admin count, and account hygiene across every user.
Third-Party Apps
Every OAuth-connected app, named and ranked by the level of access it holds.
Drive Sharing
Files exposed publicly, by link, or domain-wide by default.
Email Security
SPF, DKIM and DMARC configuration, auto-forwarding rules and mailbox delegation.
User Lifecycle
Dormant accounts, unclosed leavers, and licences still being paid for on inactive seats.
Groups
Groups open to external members or publicly joinable without approval.
Calendar
Organisation-wide default sharing and publicly visible calendars.
Meet
Recording defaults and external-participant permissions.
Sites
Internal Google Sites published publicly, checked across the whole domain.
Endpoint Devices
Unencrypted or compromised devices, stale ChromeOS, and screen-lock policy.
Logging & Retention
Whether your audit trail is actually kept long enough to be useful after an incident.
Every finding, costed
Each issue carries a fixed price to fix, so you can budget properly instead of guessing.
How it works
Three steps, and your report lands within 24 hours of authorisation.
Pay the flat fee
£495, paid once. Nothing recurring is attached to it and there's no contract to sign.
Authorise read-only access
Your Workspace admin authorises a scoped connection that reads configuration only. Nothing is changed, and you can revoke access at any time.
Get your report
The scan runs automatically across all eleven modules. You get a live scored dashboard and a full PDF within 24 hours.
What you receive
Everything is yours to keep and act on however you choose.
- A live scored dashboard: every module scored, every finding ranked by risk, updated the moment the scan completes.
- An executive summary: the good, the bad and the ugly, written for whoever signs the cheque rather than whoever reads the logs.
- A full PDF report: every finding with its business risk in plain terms, plus what each fix would cost.
- Named detail: the actual accounts, files, apps and groups involved, not just counts.
Exactly what you're buying
No ambiguity about scope, in either direction.
What the audit does
- Reads your Workspace configuration and admin audit logs
- Checks eleven areas against known attack paths
- Names the specific accounts, files, apps and groups involved
- Prices every fix so you can budget or brief your own team
What it deliberately doesn't do
- It is not a penetration test, nothing is attacked or exploited
- It never reads the contents of your emails, documents or files
- It cannot change a single setting. Access is strictly read-only
- It doesn't guarantee security; it is a point-in-time assessment
This is an audit, not a sales funnel.
You get the findings and the full report regardless of what you do next.
There's no pressure to engage us for remediation, if you'd rather hand the PDF straight to your own IT team, that's exactly what it's built for.
Costs are included purely so the numbers are transparent. You can budget against them, get them quoted elsewhere, or ignore them entirely. If you do want us to fix things, the price is already fixed, no day rates, no scope creep.
Pricing
One price, per domain, paid once.
The full eleven-module audit, dashboard, executive summary and costed PDF report.
- All eleven modules scanned
- Report within 24 hours
- Every finding costed to fix
- No contract, no obligation
Frequently Asked Questions
What access does a Google Workspace security audit need?
A scoped, read-only connection authorised by a Workspace super admin. The audit reads configuration and audit-log data only. It cannot change a single setting, and you can revoke access from your Google account at any time.
Will a Workspace audit disrupt my team or change any settings?
No. Nothing is installed, no settings change, and your users won't notice anything. The scan reads your Admin Console configuration in the background.
How long does a Google Workspace security audit take?
The scan itself takes a few minutes. Your report is with you within 24 hours of authorisation.
What data does a Workspace audit read, and what does it never access?
The audit reads configuration (settings, sharing states, account status), not the contents of your emails, files or documents. Results are stored securely so you can compare against future scans, and are deleted on request.
Do I have to buy remediation after a Workspace audit?
No. The report is yours regardless. Remediation pricing is included for transparency, not as a commitment.
What happens if a Workspace audit finds no problems?
Then you have documented evidence that your Workspace is in good shape, which is useful for insurers, clients and boards. In practice, every environment we've scanned has surfaced something worth knowing about.
Ready to uncover your Workspace risks?
£495 flat. Report within 24 hours. No obligation to buy anything after.

