Read-Only · Fully Remote · Zero Risk

Infrastructure Audit & Assessment

A comprehensive read-only audit of your entire IT environment. We inventory everything, assess your security posture, and map your compliance position — without installing agents or making changes.

Request a Scoping Call

What We Inventory

We connect with read-only credentials and map your entire environment. No software installed, no agents deployed, no changes made.

🏦

Microsoft 365

Complete tenant inventory and configuration review.

  • Entra ID users, groups, and roles
  • Licenses and subscription review
  • Conditional access policies
  • Intune device compliance
  • Defender security posture
  • Exchange mail flow analysis
🖥

On-Premise Systems

All servers, endpoints, and infrastructure devices.

  • OS versions and patch levels
  • Installed software inventory
  • Running services and ports
  • Active Directory structure
  • Group Policy objects
  • Storage and backup configuration
📡

Network Infrastructure

Full network topology and device inventory.

  • Firewalls and routing rules
  • Switches and VLANs
  • DNS and DHCP configuration
  • Wireless infrastructure
  • VPN and remote access
  • Network segmentation analysis
🛡

Security Posture

Comprehensive security assessment.

  • Endpoint protection coverage
  • SIEM/XDR configuration
  • Vulnerability scan results
  • Access control review
  • Audit logging verification
  • Incident response readiness
📋

Compliance Position

Gap analysis against major frameworks.

  • NIST 800-171 alignment
  • CMMC 2.0 readiness
  • HIPAA Security Rule
  • SOC 2 Trust Services Criteria
  • ISO 42001 AI management
  • Framework-specific remediation

Custom Services

Application and service dependency mapping.

  • Web servers and APIs
  • Database servers
  • Custom applications
  • Cloud dependencies identified
  • Data flow mapping
  • Single points of failure

Read-Only. Zero Risk. Fully Remote.

We connect with read-only credentials, inventory your environment, and disconnect. No software is installed on your systems. No agents are deployed. No changes are made. All collected data is stored on our own infrastructure — never in the cloud.

What You Receive

A complete documentation package delivered in your preferred format (PDF, Word, or HTML).

Infrastructure Inventory

Complete hardware, software, user, and network inventory document with asset details and configuration data.

Security Assessment

Vulnerabilities, misconfigurations, and security gaps identified with severity ratings and impact analysis.

Compliance Gap Analysis

Your current posture mapped against NIST 800-171, CMMC 2.0, HIPAA, and SOC 2. Shows what's met, partial, and missing.

Architecture Diagram

Network topology, data flow, system dependencies, and cloud integration points visualized.

Risk Register

All identified risks with severity scoring, likelihood assessment, and business impact ratings.

Remediation Roadmap

Prioritized action plan — what to fix first, what can wait, and what needs immediate attention.

M365 Configuration Review

Detailed review of policies, licenses, security defaults, and recommendations for optimization.

Executive Summary

Business-language overview for leadership. Translates technical findings into business risk and action items.

Pricing

Per-project pricing based on environment size. No recurring fees, no subscriptions. One audit, one deliverable package, one invoice.

Tier Environment Size Timeline Price
Small 1-25 users, 1-5 servers 1-2 weeks $3,500
Medium 26-100 users, 6-20 servers 2-3 weeks $7,500
Large 101-500 users, 21-50 servers 3-4 weeks $15,000
Enterprise 500+ users, 50+ servers 4-6 weeks Custom Quote

Pricing is per project and subject to change. A scoping call determines your tier based on actual environment size. Enterprise engagements require a scoping call before quoting.

How It Works

Access Requirements

Our Process

Data Handling

From Audit to Action

The audit identifies gaps. The remediation roadmap shows you how to close them. For defense contractors and regulated industries, that often means sovereign AI infrastructure.

1

Audit Your Environment

We inventory everything and deliver a complete assessment package with compliance gap analysis.

2

Review the Findings

The remediation roadmap prioritizes what needs fixing. You see exactly where you stand against NIST 800-171, CMMC, HIPAA, and SOC 2.

3

Close the Gaps

For cloud dependency and data sovereignty gaps, the Sovereign AI IT Platform provides on-premise AI infrastructure that eliminates external data transmission.

4

Reassess and Certify

After remediation, a follow-up assessment confirms gaps are closed. We stand with you during your certification process.

Ready to See What You Have?

Most organizations don't know what's on their network until someone maps it. Get a professional, read-only assessment with actionable remediation guidance.

Request a Scoping Call

30-minute consultation · No obligation · Fully remote