calibrant.ai — continuous Microsoft 365 posture measurement
Calibrateyour
Microsoft 365
Run full-scope tenant healthchecks and living security assessments from a relay you control. Calibrant includes an independently authored M365 baseline and a November 19, 2024 CISA SCuBA snapshot in one platform.
The Calibrant Product Suite
One platform. Every calibration.
Tenant Healthcheck
Available Now116 health rules across the same 8 M365 categories on every scan, with license-aware severity-weighted scoring.
Learn moreSecurity Baseline
Available NowIndependent M365 security baseline plus a November 19, 2024 CISA SCuBA snapshot, with automatic and manual evidence.
Learn moreProtocol
How it works
Three steps to a secure, compliant M365 environment.
Deploy
Deploy the relay in your Azure subscription. The optional Microsoft connection labels and cross-checks the tenant; it is not required for scanning.
Measure
Evaluate 116 health rules and automatically collect evidence for 191 security controls across your M365 tenant.
Improve
Fix misconfigurations, document eligible control-specific safeguards you handle elsewhere, and watch the score move scan over scan.
Differentiators
Why Calibrant
Living assessments, not annual audits.
Security attestations persist for their review window, and Healthcheck context is saved for safe reuse. Every completed scan keeps its own evidence and answers, so your audit history cannot be rewritten later — and every assessment and scan exports an audit-ready PDF, on every plan.
Auto-detect what M365 exposes. Attest the rest.
67% of baseline controls and 51% of the bundled CISA SCuBA snapshot are auto-checked from your tenant, and the ACSC Essential Eight is tracked to its ML1–ML3 maturity levels with the Microsoft slice of each requirement verified by scan. The rest require documented validation because they are organizational, a narrower reader surface is unavailable, or you declined an optional integration. A third-party safeguard can receive compensated credit only where the exact control explicitly permits it, with evidence and a review expiry.
Configuration evidence, plus the context it cannot prove.
Calibrant reads Microsoft first. When a setting cannot prove business intent, complete scope, justified exclusions, policy quality, or an allowed outside safeguard, the scan asks a focused follow-up. Saved answers carry forward while the relevant Microsoft evidence and Calibrant evaluation rules remain unchanged; only affected items are asked again. Each control receives one verdict, unlicensed products are excluded, and required context is completed before any score is published.
Your tenant's credentials never leave your tenant.
The relay runs in your own Azure subscription and authenticates with a Managed Identity you control. Calibrant stores no Microsoft tokens, and the relay executes only operations from its own compiled catalogue — the portal cannot tell it what code to run. Every Graph role and the one directory role it holds are read-only; the optional Power Platform registration is not, and we document exactly what it permits.
Ready to calibrate?
Most tenants get audited once — after an incident. Calibrant treats your M365 environment like an instrument that needs continuous measurement: scored scans, living assessments, and score trends retained for the life of your account.
Start 14-Day Free TrialEarly access — from $8/mo, flat per tenant, no per-user fees