Coming soon · Compliance that holds its course

Small corrections.
Whole fleet on course.

Trimtab keeps a lookout on every Windows device and Microsoft 365 tenant, checks them against CMMC Level 2 and HIPAA, explains each gap in plain English, and tells you the moment anything drifts off course.

37 device checks  ·  19 Microsoft 365 checks  ·  Charted to CMMC Level 2 and HIPAA

Read-only Lookout agent CMMC Level 2 · NIST SP 800-171 r2 HIPAA Security Rule Microsoft 365 and Exchange Online Drift detection Built for MSPs
How it works

From cast-off to clear answers in one afternoon.

No consultants, no spreadsheets, no guessing which setting maps to which control. Just a clear chart of where you stand.

Post a Lookout

Install Lookout, our agent, with one command and a client enrollment key. It scans daily and after every restart, and never changes a setting. Connect Microsoft 365 with a single admin approval.

Chart every check

Checks cover encryption, malware protection, accounts, hardening, audit logging, patching, identity, email, and sharing. Each result is charted to the exact CMMC and HIPAA requirements it proves.

Hold your heading

The Bridge shows your whole fleet at a glance and flags anything that drifted from Pass to Fail since the last scan, with step-by-step corrections.

Features

Everything you need to stay shipshape, nothing you have to babysit.

A read-only Lookout

Lookout observes and reports. It never changes a configuration, so it's safe to run on production machines.

Mapped to the standard

Every check rolls up to CMMC Level 2 and HIPAA controls, so you see compliance by requirement, not just a list of settings.

Plain-English explanations

Each requirement shows what it means in everyday language, the official wording, and a link to the source document.

Drift detection

Every scan is compared to the last. Anything that drifted off course, and everything brought back on course, is called out on the Bridge.

Course corrections

Every finding comes with the evidence behind it and step-by-step instructions to fix it. Reports print cleanly for auditors and clients.

One Bridge, every client

Separate clients, per-client enrollment keys, and per-device credentials you can revoke at any time. Filter the fleet by client in one click.

Keeps watch offline

Laptops at sea keep scanning. Results are logged locally and report in automatically the next time the device reaches port.

Fleet view by check

See which checks fail most across all devices, and jump straight to the machines that need attention.

Your heading, your rules

Password length, patch age, log size, and other limits are configurable, so the checks match your policy rather than ours.

Plain English

Compliance your clients can actually read.

Frameworks are written for assessors. Trimtab translates every requirement into a sentence anyone can act on, without losing the official text.

  • What the requirement means, in everyday words
  • The official requirement wording, word for word
  • A direct link to NIST, DoD, or the HIPAA regulation
  • Why each failed check matters, right on the finding
FailAC.L2-3.1.10

Use session lock with pattern-hiding displays

In plain terms If someone walks away from their computer, the screen should lock automatically and hide what was on it. Official requirement Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity. Source NIST SP 800-171 r2 · 3.1.10
Frameworks

Charted against the standards your clients are held to.

Available

CMMC Level 2

The DoD requirement for contractors handling Controlled Unclassified Information, aligned to NIST SP 800-171 r2.

26controls checked
7families
Available

HIPAA Security Rule

Administrative and technical safeguards for electronic protected health information under 45 CFR 164.

10safeguards checked
2sections
Available

Microsoft 365

MFA, legacy sign-in, admin roles, guest access, SharePoint sharing, and Exchange Online mail flow and auditing, charted to the same controls.

19tenant checks
Readonly access

What Trimtab proves, and what it doesn't. On the horizon: CIS Windows Benchmarks and NIST CSF 2.0. Device checks prove technical settings. Policies, training, physical security, and other process controls still need their own evidence. Trimtab tells you exactly which requirements it covered, so nothing is assumed.

Who it's for

One tool for the people doing the work and the people answering for it.

Managed service providers

Run a tighter ship for every client.

  • Every client on one Bridge, separated by enrollment key
  • Spot drift before your client's assessor does
  • Hand clients reports they understand
  • Deploy in minutes with any software deployment tool
Defense contractors and healthcare

Know your position, every day.

  • A daily score instead of a once-a-year surprise
  • Gaps explained in language leadership can follow
  • Evidence collected automatically, device by device
  • A clear line between what's proven and what's still on you
Security

A compliance tool shouldn't be the leak in your hull.

Read-only Lookout

No check modifies the system. The only side effect is a temporary policy export that is deleted immediately.

Per-device credentials

Each device gets its own token, encrypted at rest with Windows DPAPI and stored where only administrators can read it.

Encrypted in transit

Lookout talks to Trimtab over HTTPS only, using outbound connections. No inbound ports are opened on your devices.

MFA on every login

The Bridge requires a password and an authenticator code, and sign-in attempts are rate-limited after repeated failures.

FAQ

Questions from the crew.

Does Trimtab change anything on my devices?

No. Every check is read-only. Trimtab reports what it finds and recommends a fix, and your team decides what to change.

What operating systems are supported?

Windows 10, Windows 11, and Windows Server, using the built-in Windows PowerShell. No extra runtime is required.

Does Trimtab make me CMMC certified or HIPAA compliant?

No tool can. Certification comes from an assessment, and compliance includes policies and processes as well as technology. Trimtab gives you continuous, evidence-backed visibility into the technical requirements, and clearly marks what it does not cover.

How often are devices scanned?

Once a day and shortly after every restart, by default. Scans take under a minute and run in the background.

What if a laptop is offline?

Lookout keeps scanning. Results are queued on the device and uploaded automatically the next time it can reach Trimtab.

What data does Lookout collect?

Security configuration only: device name, model, serial number, operating system, and the result and evidence for each check. It does not read documents, email, or browsing activity. See our privacy page for the full list.

When can I get Trimtab?

Trimtab is coming soon and isn't available for purchase yet. Sign up for updates and we'll let you know when it launches.

Is Microsoft 365 supported?

Yes. A Global Administrator approves read-only access once, and Trimtab checks identity, sharing, and Exchange Online settings daily, charted to the same controls as device checks.

Coming soon

Trimtab is almost ready to set sail.

We're putting the finishing touches on Trimtab. Sign up and we'll signal you the moment it leaves the harbor.