Security

Google Workspace security

A Workspace security audit checks the admin console against a fixed control list: authentication, external sharing, OAuth app access, mail authentication, logging retention and leaver process. Findings arrive as a ranked list with an owner and a fix date, not a score.

Most Workspace tenants fail on the same four controls: unenforced 2-step verification, unreviewed third-party OAuth grants, Drive links shared to anyone with the link, and DMARC left at p=none years after it was published.

These pages describe what we check, what we change, and what remains your decision.

Pages in this section

What this doesn't cover

  • An audit is not a penetration test and does not attempt to exploit anything.
  • We do not sign compliance certifications; we produce the evidence your assessor asks for.
  • Endpoint and network security outside Workspace is out of scope unless quoted separately.

Questions we get asked

What does a Google Workspace security audit cover?
Authentication and 2SV enforcement, admin role sprawl, external sharing defaults, OAuth and marketplace app grants, SPF, DKIM and DMARC alignment, log retention, and the leaver process end to end.
How long does an audit take?
Five working days for up to 250 users: two days of console review and log sampling, one day of interviews, two days of write-up and remediation planning.

Not sure which of these you need?

Send us the shape of your estate — seat count, current platform, and the deadline you are working to — and we will tell you which of these pages applies and what it costs.