Coming soon · Compliance that holds its course

Small corrections.
Whole fleet on course.

Trimtab keeps a lookout on every Windows device and Microsoft 365 tenant, checks them against the standards your clients answer to, from CMMC and HIPAA to the FTC Safeguards Rule, explains each gap in plain English, and tells you the moment anything drifts off course.

41 device checks  ·  20 Microsoft 365 checks  ·  5 standards

Read-only Lookout agent CMMC Level 1 and 2 HIPAA Security Rule FTC Safeguards Rule CIS Controls IG1 Microsoft 365 and Exchange Online Drift detection Built for MSPs
How it works

From cast-off to clear answers in one afternoon.

No consultants, no spreadsheets, no guessing which setting maps to which control. Just a clear chart of where you stand.

Post a Lookout

Install Lookout, our agent, with one command and a client enrollment key. It scans daily and after every restart, and never changes a setting. Connect Microsoft 365 with a single admin approval.

Chart every check

Checks cover encryption, malware protection, accounts, hardening, audit logging, patching, identity, email, and sharing. Each result is charted to the exact requirements it proves, in every standard you select.

Hold your heading

The Bridge shows your whole fleet at a glance and flags anything that drifted from Pass to Fail since the last scan, with step-by-step corrections.

Features

Everything you need to stay shipshape, nothing you have to babysit.

A read-only Lookout

Lookout observes and reports. It never changes a configuration, so it's safe to run on production machines.

Mapped to the standard

Every check rolls up to the controls of each standard you choose for a client, so you see compliance by requirement, not just a list of settings.

Plain-English explanations

Each requirement shows what it means in everyday language, the official wording, and a link to the source document.

Drift detection

Every scan is compared to the last. Anything that drifted off course, and everything brought back on course, is called out on the Bridge.

Course corrections

Every finding comes with the evidence behind it and step-by-step instructions to fix it. Reports print cleanly for auditors and clients.

One Bridge, every client

Separate clients, per-client enrollment keys, and per-device credentials you can revoke at any time. Filter the fleet by client in one click.

Keeps watch offline

Laptops at sea keep scanning. Results are logged locally and report in automatically the next time the device reaches port.

Fleet view by check

See which checks fail most across all devices, and jump straight to the machines that need attention.

Your heading, your rules

Password length, patch age, log size, and other limits are configurable, so the checks match your policy rather than ours.

Plain English

Compliance your clients can actually read.

Frameworks are written for assessors. Trimtab translates every requirement into a sentence anyone can act on, without losing the official text.

  • What the requirement means, in everyday words
  • The official requirement wording, word for word
  • A direct link to the official source: NIST, DoD, the eCFR, or CIS
  • Why each failed check matters, right on the finding
FailAC.L2-3.1.10

Use session lock with pattern-hiding displays

In plain terms If someone walks away from their computer, the screen should lock automatically and hide what was on it. Official requirement Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity. Source NIST SP 800-171 r2 · 3.1.10
Frameworks

Charted against the standards your clients are held to.

Available

CMMC Level 1

The baseline for every defense contractor handling Federal Contract Information: the 15 safeguarding requirements of FAR 52.204-21.

11of 15 requirements checked
4families
Available

CMMC Level 2

The DoD requirement for contractors handling Controlled Unclassified Information, aligned to NIST SP 800-171 r2.

34controls checked
7families
Available

HIPAA Security Rule

Administrative and technical safeguards for electronic protected health information under 45 CFR 164.

11safeguards checked
2sections
Available

FTC Safeguards Rule

Encryption, MFA, and activity logging for tax preparers, CPA firms, mortgage brokers, auto dealers, and insurance agencies under GLBA.

7requirements checked
314.416 CFR
Available

CIS Controls IG1

Essential cyber hygiene from the Center for Internet Security. A recognized baseline for clients who aren't regulated, and a foundation for those who are.

20safeguards checked
9controls
Available

Microsoft 365

MFA, legacy sign-in, admin roles, guest access, SharePoint sharing, and Exchange Online mail flow, malware filtering, and auditing, charted to the same controls.

20tenant checks
Readonly access

What Trimtab proves, and what it doesn't. On the horizon: cyber insurance readiness and NIST CSF 2.0. Device checks prove technical settings. Policies, training, physical security, and other process controls still need their own evidence. Trimtab tells you exactly which requirements it covered, so nothing is assumed.

Who it's for

One tool for the people doing the work and the people answering for it.

Managed service providers

Run a tighter ship for every client.

  • Every client on one Bridge, separated by enrollment key
  • Spot drift before your client's assessor does
  • Hand clients reports they understand
  • Deploy in minutes with any software deployment tool
Defense contractors and healthcare

Know your position, every day.

  • A daily score instead of a once-a-year surprise
  • Gaps explained in language leadership can follow
  • Evidence collected automatically, device by device
  • A clear line between what's proven and what's still on you
Security

A compliance tool shouldn't be the leak in your hull.

Read-only Lookout

No check modifies the system. The only side effect is a temporary policy export that is deleted immediately.

Per-device credentials

Each device gets its own token, encrypted at rest with Windows DPAPI and stored where only administrators can read it.

Encrypted in transit

Lookout talks to Trimtab over HTTPS only, using outbound connections. No inbound ports are opened on your devices.

MFA on every login

The Bridge requires a password and an authenticator code, and sign-in attempts are rate-limited after repeated failures.

FAQ

Questions from the crew.

Does Trimtab change anything on my devices?

No. Every check is read-only. Trimtab reports what it finds and recommends a fix, and your team decides what to change.

What operating systems are supported?

Windows 10, Windows 11, and Windows Server, using the built-in Windows PowerShell. No extra runtime is required.

Does Trimtab make me CMMC certified or HIPAA compliant?

No tool can. Certification comes from an assessment, and compliance includes policies and processes as well as technology. Trimtab gives you continuous, evidence-backed visibility into the technical requirements, and clearly marks what it does not cover.

How often are devices scanned?

Once a day and shortly after every restart, by default. Scans take under a minute and run in the background.

What if a laptop is offline?

Lookout keeps scanning. Results are queued on the device and uploaded automatically the next time it can reach Trimtab.

What data does Lookout collect?

Security configuration only: device name, model, serial number, operating system, and the result and evidence for each check. It does not read documents, email, or browsing activity. See our privacy page for the full list.

When can I get Trimtab?

Trimtab is coming soon and isn't available for purchase yet. Sign up for updates and we'll let you know when it launches.

Is Microsoft 365 supported?

Yes. A Global Administrator approves read-only access once, and Trimtab checks identity, sharing, and Exchange Online settings daily, charted to the same controls as device checks.

Coming soon

Trimtab is almost ready to set sail.

We're putting the finishing touches on Trimtab. Sign up and we'll signal you the moment it leaves the harbor.