GuardRadiusCYBER SECURITY
HOW IT WORKS

Scope, collect, correlate, report.

Each stage finishes before the next begins, and every report carries the full check log — so the method is auditable rather than assumed.

01 SCOPE

Domains, ranges or systems confirmed with you. Written authorisation on file before any traffic.

02 COLLECT

Fixed checks execute once. Read-only throughout. Nothing installed on your machines.

03 CORRELATE

Results cross-referenced against known issues and your context to rank real exposure.

04 REPORT

Plain-English findings, a fix-first list, evidence, and the complete log of checks run.

What we check

Coverage grows with the tier. Everything below is read-only collection.

EXTERNAL
Public surface
  • DNS records and subdomain exposure
  • TLS certificates and expiry
  • Open ports and reachable services
  • Email authentication: SPF, DKIM, DMARC
  • Remote access and VPN endpoints
  • Breached-credential exposure for your domain
INTERNAL
Endpoints and identity
  • Patch level and unsupported operating systems
  • Local administrator sprawl
  • Password and lockout policy
  • SMB and RDP exposure on the LAN
  • Endpoint protection status
  • Backup presence and last successful run
FULL ENTERPRISE
Estate systems
  • Active Directory: privilege, delegation, stale objects
  • Exchange: mail flow, permissions, transport rules
  • SQL Server: authentication, roles, encryption
  • VMware: host and cluster configuration
  • Firewalls: rule base, any-any rules, logging
Templates, not improvisation

At Full Enterprise tier each system type has a collection template: a declared list of queries, the read-only permissions they need, and the data they return. You review and approve the template before the run, and the report states which template version was used.

Join the waitlist