>_ NETRA

The read-only eye on your Azure ISM PROTECTED posture.

Compliance the manual way is slow, consultant-heavy, and stale by the next quarterly ISM update. Netra changes that.

AZURE CLOUD SHELL curl -sL https://netra.run/install.sh | bash -s -- --region australiaeast
Cloud Shell opens in a new tab — copy the command above and paste it in (Bash). It can't auto-run for you.
N E S W
CONTINUOUS SCAN_

Netra makes it easy to get your Azure tenancy ISM PROTECTED compliant — and secures it pragmatically with the standards you're assessed against, kept continuously compliant.

Compliant, fast

ISM PROTECTED posture mapped to ASD's own controls — not a months-long consultant spreadsheet marathon.

Secured pragmatically

Hardened against real standards: CIS, NIST 800-53, MCSB and the ACSC Blueprint — free from our own checks.

Continuous compliance

Re-scan any time. Posture stays current as your tenant changes and the ISM updates each quarter.

What Netra sees

One read-only pass over your tenant, mapped to the controls your assessor actually asks for — and everything it can't prove, it says so, plainly.

How it runs

In your tenant

Deploys as a single Container App into your own subscription. Your configuration never leaves it.

Read-only by construction

The Reader role only. Resource Graph has no mutation API — the read-only claim is checkable in source.

Consent, explained

When a check needs Graph, Netra asks — a one-click portal link or an az grant, each spelling out why.

Obvious identity

The console shows exactly which managed identity reads your tenant, and that it holds Reader and nothing else.

What you need to install

One command in Azure Cloud Shell (Bash), in the subscription you want assessed — no local tooling:

AZURE CLOUD SHELL curl -sL https://netra.run/install.sh | bash -s -- --region australiaeast

Azure role

Owner on the target subscription — or Contributor plus Role Based Access Control Administrator. The installer creates the resources and grants Netra's identity read-only Reader.

Entra (Azure AD)

Permission to register an application — Application Developer, or a tenant that allows app registration — for the Entra sign-in app.

Identity plane (optional)

To assess MFA & Conditional Access, a Global Administrator or Privileged Role Administrator runs one read-only Policy.Read.All grant — the exact command is shown in the app.

What Netra ends up holding

Only Reader — and, if you consent, read-only Policy.Read.All. No write path, no standing secret. Teardown is one command.

Mapped to what you're assessed against

One scan, every framework a finding touches — pinned to real benchmark versions.

ISM PROTECTED (ASD OSCAL) CIS Azure Foundations v2.0.0 CIS M365 v4.0.0 NIST SP 800-53 Rev. 5 MCSB v1 ACSC Blueprint for Secure Cloud

Pricing

$100 AUD / month
per install — one Netra deployment in your tenant
Subscribe
Everything included. No feature gates, no per-seat charge, no control limits. Every install gets the full 986-control ISM PROTECTED assessment, all five evidence planes, the attestation and decision workspace, and the PDF, SSP and Annex artefacts.
Unlimited subscriptions and users. One install scans every Azure subscription its identity can read, and everyone in your tenant who can sign in can use it.
Updates included. ASD revises the ISM; released updates carry the new catalog, and upgrading is one command that keeps your attestations and decisions.
Cancel any time. Monthly, no lock-in. Uninstall is one command and leaves nothing behind.
Plus your own Azure costs. Netra runs in your tenant, so you pay Microsoft directly for the infrastructure it uses — a single Container App, Log Analytics, and a Burstable Postgres, typically ~$55–65 AUD/month at current list prices. Nothing is billed through us, and you can tear it down whenever you like. Costs vary by region and usage; check the Azure pricing calculator for your own estimate.

Who's behind it

Built by Abhijit Ghosh — nearly a decade in the Australian federal government, including several years at the Australian Cyber Security Centre (ACSC) and the Australian Signals Directorate (ASD).

Netra is the tool that assessment work kept calling for: the ISM turned into something you can run, read, and hand to an assessor — with the honest gaps shown, not a spreadsheet re-filled by hand every quarter. It reads only, holds nothing but Reader, and keeps your data in your own tenant.

Independent and unaffiliated. Netra is an independent product. It is not endorsed by, affiliated with, sponsored by, or produced on behalf of the Australian Signals Directorate, the Australian Cyber Security Centre, or the Australian Government, and the author's prior public service does not imply any such endorsement. Netra is built entirely from publicly available information — the published ISM and the public benchmarks it maps to — and contains no material derived from any position of employment. "ISM", "ACSC", "ASD", "Essential Eight" and "IRAP" are used nominatively to describe the frameworks assessed.

Security audits welcome

Netra is built to be approvable in an afternoon. The install templates are public, and the full source is available to security teams on request — read the code, verify there's no write path, watch it hold nothing but Reader. Reach us at security@netra.run.

No warranty; no liability. Netra is provided "as is", without warranty of any kind, express or implied. To the maximum extent permitted by law, the authors and copyright holder accept no liability for any claim, loss or damage arising from its use. It is an assessment aid, not a guarantee of security or compliance; you remain responsible for your own compliance decisions and their verification.

Independence. Netra is an independent assessment aid. It is not endorsed by, affiliated with, or accredited by the Australian Signals Directorate, the ACSC, or the Australian Government. It reports observed posture against the ISM and public benchmarks; it does not grant accreditation or IRAP assessment. "ISM", "Essential Eight", "ACSC" and "IRAP" are used nominatively to describe the frameworks assessed. Framework control identifiers are curated references pinned to the versions shown and should be verified against the source benchmark.