Compliance the manual way is slow, consultant-heavy, and stale by the next quarterly ISM update. Netra changes that.
curl -sL https://netra.run/install.sh | bash -s -- --region australiaeast
Netra makes it easy to get your Azure tenancy ISM PROTECTED compliant — and secures it pragmatically with the standards you're assessed against, kept continuously compliant.
ISM PROTECTED posture mapped to ASD's own controls — not a months-long consultant spreadsheet marathon.
Hardened against real standards: CIS, NIST 800-53, MCSB and the ACSC Blueprint — free from our own checks.
Re-scan any time. Posture stays current as your tenant changes and the ISM updates each quarter.
One read-only pass over your tenant, mapped to the controls your assessor actually asks for — and everything it can't prove, it says so, plainly.
Deploys as a single Container App into your own subscription. Your configuration never leaves it.
The Reader role only. Resource Graph has no mutation API — the read-only claim is checkable in source.
When a check needs Graph, Netra asks — a one-click portal link or an az grant, each spelling out why.
The console shows exactly which managed identity reads your tenant, and that it holds Reader and nothing else.
One command in Azure Cloud Shell (Bash), in the subscription you want assessed — no local tooling:
curl -sL https://netra.run/install.sh | bash -s -- --region australiaeast
Owner on the target subscription — or Contributor plus Role Based Access Control Administrator. The installer creates the resources and grants Netra's identity read-only Reader.
Permission to register an application — Application Developer, or a tenant that allows app registration — for the Entra sign-in app.
To assess MFA & Conditional Access, a Global Administrator or Privileged Role Administrator runs one read-only Policy.Read.All grant — the exact command is shown in the app.
Only Reader — and, if you consent, read-only Policy.Read.All. No write path, no standing secret. Teardown is one command.
One scan, every framework a finding touches — pinned to real benchmark versions.
Built by Abhijit Ghosh — nearly a decade in the Australian federal government, including several years at the Australian Cyber Security Centre (ACSC) and the Australian Signals Directorate (ASD).
Netra is the tool that assessment work kept calling for: the ISM turned into something you can run, read, and hand to an assessor — with the honest gaps shown, not a spreadsheet re-filled by hand every quarter. It reads only, holds nothing but Reader, and keeps your data in your own tenant.
Netra is built to be approvable in an afternoon. The install templates are public, and the full source is available to security teams on request — read the code, verify there's no write path, watch it hold nothing but Reader. Reach us at security@netra.run.