Resources
See it before you scan it.
Field guides on how OAuth grants work, what every scope actually permits, and how an inventory becomes audit evidence. Start with the interactive demo — a real scan of a sample environment, no signup.
Watch a shadow-AI scan run
A live scan of a sample healthcare tenant surfaces every AI & SaaS app with access, scores each one’s data exposure, and explains why — in about a minute. No account, no install.
Open the demo →Field guides
The shadow-AI field guide
How third-party AI tools get OAuth access to your cloud, why nothing you run can see it, and what a grant actually lets them read.
9 min read →
02OAuth scopes in plain English
Every common Google Workspace and Microsoft 365 permission an app can ask for, translated into what it lets the app do.
7 min read →
03From app inventory to audit evidence
How an inventory becomes evidence under HIPAA, SOC 2, PCI DSS, ISO 27001 and the AI frameworks — and why the word is “may support,” not “satisfies.”
8 min read →