From first call to report, in one clear procedure.
Five steps. The same every time.
We're a product, not a consultancy. The procedure is standardised so turnaround, quality, and price are predictable.
Intake call
We ask three questions: which environment, what's worrying you, who signs? No pitch, no prep.
Follow-up email with a draft SOW within one business day.
Documents
SOW, NDA, and DPA (GDPR) via DocuSign. Standard templates, editable, no surprises.
Three signed documents. You know exactly what you're getting, at what price, on what terms.
Read-only access
One technical contact grants temporary read-only access in Azure, Entra ID, and the M365 admin centres. No write rights. Not now, not later.
Access window defined in the SOW. Access expires automatically once the scan is done.
Scan
We run the same scanners and checks every time, across cost, identity, and reliability. No manual work where automation suffices.
Findings collected and prioritised against the standard rubric (high/medium/low).
Report + walkthrough
A 25 to 40 page PDF report and a 30-minute walkthrough call. Findings, evidence, annualised savings, mapped remediation packages.
Report, walkthrough, and written confirmation that all credentials have been removed.
Read-only. Time-limited. Confirmed removed.
We don't need write access for the assessment. Not for cost analysis, not for security checks, not for reliability work. Everything we find, we find via documentation and read-only APIs.
Access expires automatically once the scan is done, usually within three business days. We send written confirmation that credentials have been removed, so you can revoke immediately on your side too.
Read-only, minimal
Reader role on subscriptions, Global Reader in Entra ID, Reports Reader in M365. No Owner, Contributor, or admin rights.
Time-limited
Access window written into the SOW. Expires automatically after the scan, usually within three business days.
Everything logged
Every API call shows up in your own audit logs. Nothing happens out of sight. If in doubt, look in Azure Monitor.
Confirmed in writing
After we're done, you receive an email with a removal statement per credential. You can revoke immediately on your side.
Three documents. Standard. Editable.
Our documents are model agreements, reviewed by a Dutch lawyer and designed to be signed within one business day. Edits are possible. Most clients sign as-is.
Statement of Work
Scope, turnaround, price, no-cure-no-pay clause, and deliverables. One page.
Non-disclosure agreement
Mutual. What we see during the scan stays between us.
Data Processing Agreement
GDPR-compliant. What data we process, for how long, and when it's deleted.
Five things that don't happen.
No write access
Not needed for the assessment. Full stop.
No scope creep
Fixed price, fixed scope. Extra work gets re-quoted, never quietly billed.
No subcontractors
The scan and the report are done by REL. Nothing offshored.
No sales pitch in the report
Findings and recommendations, nothing else. Remediation packages are offered separately, without pressure.
No data sharing
Nothing flows to third parties, partners, or marketing systems. GDPR-compliant, written into the DPA.
Accepting engagements.
One intake call. 30 minutes. No prep, no pitch.