Security posture & architecture
The question every MSP gets asked — "how secure is each of my customers, right now?" — answered across the whole book, in the framing auditors and cyber-insurers use. And answered about CrossTenant itself: the console is built to stand up to its own security review.
What's included
Benchmark-based scoring
Each customer is assessed against the CIS Google Workspace Foundations Benchmark and Cyber Essentials-style controls, with a per-control verdict and the evidence behind it. Every tenant gets a score, so "how secure is this customer?" has a defensible answer.
Email authentication, per customer domain
SPF, DKIM, DMARC, MTA-STS, TLS-RPT, and BIMI are checked for every customer domain. A failing check comes with concrete remediation — the record to publish and a deep link to the right Admin console page, not just a red icon.
Policy drift & golden baselines
Capture a known-good policy state as a baseline, then watch every tenant for drift against it. When a setting quietly changes, you see what diverged, and where.
Breach & alert signals
Google Alert Center alerts, suspicious sign-ins, and risky third-party OAuth grants surface across the whole book — with bulk revoke for OAuth apps you don't want anywhere near customer data.
2-Step Verification coverage
Enrolment coverage per customer, and the users who would fail an audit question listed individually — with a jump to the Admin console page where enforcement lives.
No customer data at rest
Every screen is a live read from Google's APIs — CrossTenant keeps no copy of your customers' data. Each customer's credentials are held in isolation, and access scopes are requested per operation at the least privilege the task needs, not as one broad standing grant.
Confirmed writes, tamper-evident audit
Every write requires an explicit confirmation — read-only customers are enforced server-side, not by hiding buttons — and lands in a hash-chained, per-tenant audit log where tampering is detectable. Team access is role-based: per engineer, per customer, per area of the product.
Honest remediation
Where Google exposes no write API for a setting, CrossTenant says so — and links you to the exact Admin console page that fixes it, rather than pretending to a write it cannot make.
Scores and verdicts are evidence for your own assessments — CrossTenant is not a certification body, and a passing score is not a Cyber Essentials certificate. Checks that depend on a customer's Workspace edition are shown as unavailable rather than silently passed.
Bring your security team
CrossTenant is built to be reviewed: live reads, least-privilege scopes, server-side enforcement, and a tamper-evident audit trail. Put it in front of your reviewers — we'll answer the hard questions.