Built for Australian MSPs · Essential Eight · APRA CPS 234

Your clients' security,
finally under control

Graften runs automated cloud audits, scores every client against Essential Eight, and gives each one a branded security portal — all without you lifting a finger. If a client gets breached, you'll know before they do.

Start 14-day free trial → See how it works
20
Compliance frameworks
<5 min
First audit to score
0
Spreadsheets required
AUD
No USD conversion surprises

Live product screens, shown with demo data.

Every MSP is one breach away from losing everything

Your clients trust you with their security. But without a systematic way to measure, monitor, and evidence that posture — you're flying blind. And so are they.

📋

Compliance is a spreadsheet nightmare

Essential Eight, ISO 27001, APRA CPS 234 — manually tracking controls across 20+ clients means something always falls through the cracks.

🔍

You find out about problems after the fact

By the time a client reports an incident, the damage is done. Reactive security is not a service — it's a liability.

💬

Clients don't understand what you do

Without visibility into their own posture, clients don't value security. They cancel, they push back on price, and they blame you when something goes wrong.

30-second self-check

How would you score on Essential Eight today?

Answer honestly — most MSPs are surprised. This is a rough self-check based on your own answers, not an audit: Graften's automated scan checks 100+ real signals per control straight from your client's AWS or M365 environment, no guessing involved.

Untrusted or unapproved applications are blocked from running on workstations
Internet-facing applications are patched within 48 hours of a critical vulnerability
Office macros are blocked from the internet, or only allowed from vetted, trusted locations
Web browsers are hardened — legacy plugins and untrusted content blocked by default
Admin privileges are restricted to dedicated accounts, never used for email or browsing
Operating systems are patched within 48 hours of a critical vulnerability
Multi-factor authentication is enforced for all users, especially remote and privileged access
Backups run daily, are stored offline or immutable, and are regularly tested via restoration
Your score: 0/8 answered
Answer all 8 above to see roughly where you stand.
Get your real automated score, free →
How it works

From zero to scored in under 5 minutes

STEP 01

Connect your tools and endpoints

Link AWS, Microsoft 365, or Azure with read-only credentials. Deploy the lightweight on-premises agent for Windows endpoints. Takes under 5 minutes per client.

STEP 02

Graften audits automatically

We scan identity, MFA, patching, application control, backups, logging — every Essential Eight control — and score the result.

STEP 03

See exactly what to fix

Every finding links to a step-by-step remediation playbook. Your AI vCISO tells you what matters most and why.

STEP 04

Show your clients the proof

Each client gets a branded security portal. They see their score, their risks, their compliance status — your brand, not ours.

Platform capabilities

Everything you need.
Nothing you don't.

🔍

Automated Cloud Audits

Connect AWS or Microsoft 365 and get a complete Essential Eight assessment in minutes. Schedule recurring audits and get alerted if a client's score drops.

AWS · M365 · Azure
🤖

AI vCISO Chat

Ask "what's my biggest risk right now?" and get an answer grounded in your client's real audit data, risk register, and compliance posture — not generic AI advice.

Powered by Claude
📊

Compliance Gap Analysis

Map every client against 20 frameworks — Essential Eight, ISO 27001, APRA CPS 234, SOC 2, NIST CSF, GDPR. Get a prioritised remediation roadmap with AI-generated fix steps.

20 frameworks
📘

Remediation Playbooks

Every finding links to a step-by-step fix guide with real commands, portal paths, and PowerShell snippets. No more Googling "how to enable MFA in Azure AD."

Built-in + AI-generated
🌐

White-Label Client Portal

Send clients a magic link. They see their security score, open risks, compliance status, and dark web exposure — all under your brand. You control what they see.

Your brand, not ours
💰

Client Billing Pass-Through

Set your own price per client, generate white-labelled GST invoices, and track outstanding revenue — all inside Graften. Turn security into a recurring revenue line.

AUD · GST compliant

Risk Register

Track every risk across your client portfolio with likelihood/impact scoring, ownership, and due dates. Import risks directly from audit findings in one click.

5×5 heatmap
🔒

Dark Web Monitoring

Continuously monitor client domains for credential exposure via HaveIBeenPwned. Breaches surface in real time — before clients find out themselves.

HIBP Core1 API
📈

Portfolio Benchmarks

See how your client portfolio ranks against the Graften platform average. Know which clients need attention before they call you to complain.

Anonymised comparison
🖥️

On-Premises Agent

For clients without cloud infrastructure — deploy our lightweight Windows agent. No PowerShell, no dependencies. Collects 30+ security data points via WMI and checks in every 15 minutes.

Windows · WMI native · No PS
🔔

Real-Time Alerting

Define rules that fire when a client's posture drops — critical patches unpatched, dark web hit detected, MFA disabled. Alerts route to Slack, Teams, PagerDuty, or email automatically.

21 integration targets

All plans include a 14-day free trial. No credit card required. By starting a trial you agree to our Terms of Service and Privacy Policy. Your data is stored in AWS ap-southeast-2 (Sydney) and encrypted with AES-256-GCM.

Integrations

Works with the tools
you already use

21 native integrations across PSA, RMM, communications, monitoring, automation, and CRM. Connect your stack in minutes — Graften handles the rest.

PSA / TICKETING
HaloPSA
ConnectWise
Autotask
Freshservice
ServiceNow
Jira
Zendesk
RMM
NinjaRMM
DattoRMM
Atera
N-central
ALERTING & AUTOMATION
Slack
Microsoft Teams
PagerDuty
Datadog
Zapier
Make
CRM & REMOTE ACCESS
HubSpot
Salesforce
AnyDesk
Splashtop

Designed for the Australian compliance landscape

Essential Eight ML1–ML3 APRA CPS 234 & CPS 230 ISO 27001:2022 Australian Privacy Act (NDB) SOC 2 Type II NIST CSF 2.0
Pricing

Priced for MSPs,
not enterprise procurement teams

All prices in AUD and exclude GST — 10% GST is added at checkout for Australian customers. Annual billing = 2 months free. 14-day free trial on all plans — no credit card required. See the full plan comparison →

Month-to-month billing Cancel anytime Export everything, anytime No proprietary lock-in
Starter
$599/mo
Up to 10 clients
For MSPs getting started with security compliance. All the essentials, none of the complexity.
Start free trial
Professional
$1,999/mo
Up to 50 clients
For larger MSPs who need full monitoring capabilities and client lifecycle management.
Start free trial
Enterprise
$3,999/mo
Unlimited clients
For MSPs managing large enterprise clients who need custom pricing, priority response, and hands-on onboarding.
Talk to us
You'd start on Growthsee full plan comparison →

Manage your own security posture

If you're an IT manager or CISO running security in-house, these plans are for you.

Essential
$299/mo
1 organisation · Essential Eight + 20 frameworks · Cloud audits · Risk register · Gap analysis
Start free trial
Enterprise
$999/mo
1 organisation · Everything in Professional · Phishing simulator · Copilot governance · White-label reporting · Dedicated account manager
Talk to us
Common questions

Everything you need to know

How long does an audit take?

For AWS or Microsoft 365, the first audit typically completes in 3–5 minutes. Subsequent scheduled audits run overnight so they don't affect your clients' environments during business hours.

What credentials does Graften need?

Read-only credentials only. For AWS, we recommend a dedicated IAM user with SecurityAudit and ViewOnlyAccess policies. For Microsoft 365, an Entra ID app registration with Directory.Read.All and SecurityEvents.Read.All. We encrypt all credentials at rest using per-subscriber keys and never store plaintext secrets.

Is Graften data stored in Australia?

Yes. All data is stored in AWS ap-southeast-2 (Sydney). We don't transfer audit data outside Australia.

What's the difference between Graften and a penetration test?

A penetration test is a point-in-time assessment. Graften is continuous — it monitors your clients' cloud configuration in real time, alerts you when posture changes, and provides an ongoing compliance record. Penetration tests are still valuable and Graften doesn't replace them, but it keeps your clients compliant between tests.

Can I white-label Graften for my MSP?

Yes. Client-facing reports, the client portal, and invoices all use your branding — your logo, your company name, your colours. Clients never see the Graften name unless you choose to show it.

How does the 14-day free trial work?

Sign up, connect your first client's cloud (AWS or M365) or deploy the on-premises agent, then run an audit. No credit card required. You get a full compliance score across Essential Eight and all supported frameworks within minutes. At the end of 14 days, choose a plan or your account pauses — we don't delete your data.

Get started today

Your next breach won't wait.
Neither should you.

Set up your first client audit in under 5 minutes. No credit card. No lock-in.

Start your free trial → Talk to sales