Graften runs automated cloud audits, scores every client against Essential Eight, and gives each one a branded security portal — all without you lifting a finger. If a client gets breached, you'll know before they do.
No credit card required · By signing up you agree to our Terms of Service and Privacy Policy
Live product screens, shown with demo data.
Your clients trust you with their security. But without a systematic way to measure, monitor, and evidence that posture — you're flying blind. And so are they.
Essential Eight, ISO 27001, APRA CPS 234 — manually tracking controls across 20+ clients means something always falls through the cracks.
By the time a client reports an incident, the damage is done. Reactive security is not a service — it's a liability.
Without visibility into their own posture, clients don't value security. They cancel, they push back on price, and they blame you when something goes wrong.
Link AWS, Microsoft 365, or Azure with read-only credentials. Deploy the lightweight on-premises agent for Windows endpoints. Takes under 5 minutes per client.
We scan identity, MFA, patching, application control, backups, logging — every Essential Eight control — and score the result.
Every finding links to a step-by-step remediation playbook. Your AI vCISO tells you what matters most and why.
Each client gets a branded security portal. They see their score, their risks, their compliance status — your brand, not ours.
Connect AWS or Microsoft 365 and get a complete Essential Eight assessment in minutes. Schedule recurring audits and get alerted if a client's score drops.
AWS · M365 · AzureAsk "what's my biggest risk right now?" and get an answer grounded in your client's real audit data, risk register, and compliance posture — not generic AI advice.
Powered by ClaudeMap every client against 20 frameworks — Essential Eight, ISO 27001, APRA CPS 234, SOC 2, NIST CSF, GDPR. Get a prioritised remediation roadmap with AI-generated fix steps.
20 frameworksEvery finding links to a step-by-step fix guide with real commands, portal paths, and PowerShell snippets. No more Googling "how to enable MFA in Azure AD."
Built-in + AI-generatedSend clients a magic link. They see their security score, open risks, compliance status, and dark web exposure — all under your brand. You control what they see.
Your brand, not oursSet your own price per client, generate white-labelled GST invoices, and track outstanding revenue — all inside Graften. Turn security into a recurring revenue line.
AUD · GST compliantTrack every risk across your client portfolio with likelihood/impact scoring, ownership, and due dates. Import risks directly from audit findings in one click.
5×5 heatmapContinuously monitor client domains for credential exposure via HaveIBeenPwned. Breaches surface in real time — before clients find out themselves.
HIBP Core1 APISee how your client portfolio ranks against the Graften platform average. Know which clients need attention before they call you to complain.
Anonymised comparisonFor clients without cloud infrastructure — deploy our lightweight Windows agent. No PowerShell, no dependencies. Collects 30+ security data points via WMI and checks in every 15 minutes.
Windows · WMI native · No PSDefine rules that fire when a client's posture drops — critical patches unpatched, dark web hit detected, MFA disabled. Alerts route to Slack, Teams, PagerDuty, or email automatically.
21 integration targetsAll plans include a 14-day free trial. No credit card required. By starting a trial you agree to our Terms of Service and Privacy Policy. Your data is stored in AWS ap-southeast-2 (Sydney) and encrypted with AES-256-GCM.
21 native integrations across PSA, RMM, communications, monitoring, automation, and CRM. Connect your stack in minutes — Graften handles the rest.
Designed for the Australian compliance landscape
All prices in AUD and exclude GST — 10% GST is added at checkout for Australian customers. Annual billing = 2 months free. 14-day free trial on all plans — no credit card required. See the full plan comparison →
If you're an IT manager or CISO running security in-house, these plans are for you.
For AWS or Microsoft 365, the first audit typically completes in 3–5 minutes. Subsequent scheduled audits run overnight so they don't affect your clients' environments during business hours.
Read-only credentials only. For AWS, we recommend a dedicated IAM user with SecurityAudit and ViewOnlyAccess policies. For Microsoft 365, an Entra ID app registration with Directory.Read.All and SecurityEvents.Read.All. We encrypt all credentials at rest using per-subscriber keys and never store plaintext secrets.
Yes. All data is stored in AWS ap-southeast-2 (Sydney). We don't transfer audit data outside Australia.
A penetration test is a point-in-time assessment. Graften is continuous — it monitors your clients' cloud configuration in real time, alerts you when posture changes, and provides an ongoing compliance record. Penetration tests are still valuable and Graften doesn't replace them, but it keeps your clients compliant between tests.
Yes. Client-facing reports, the client portal, and invoices all use your branding — your logo, your company name, your colours. Clients never see the Graften name unless you choose to show it.
Sign up, connect your first client's cloud (AWS or M365) or deploy the on-premises agent, then run an audit. No credit card required. You get a full compliance score across Essential Eight and all supported frameworks within minutes. At the end of 14 days, choose a plan or your account pauses — we don't delete your data.
Set up your first client audit in under 5 minutes. No credit card. No lock-in.