HOW IT WORKS

From first call to report, in one clear procedure.

TURNAROUND< 1 week end-to-endFORMATRemote · read-onlyTRUSTNDA · DPA · NCNP
01 · PROCEDURE

Five steps. The same every time.

We're a product, not a consultancy. The procedure is standardised so turnaround, quality, and price are predictable.

01

Intake call

30 MIN · FREE
WHAT WE DO

We ask three questions: which environment, what's worrying you, who signs? No pitch, no prep.

WHAT YOU GET

Follow-up email with a draft SOW within one business day.

02

Documents

2–3 DAYS
WHAT WE DO

SOW, NDA, and DPA (GDPR) via DocuSign. Standard templates, editable, no surprises.

WHAT YOU GET

Three signed documents. You know exactly what you're getting, at what price, on what terms.

03

Read-only access

1 DAY
WHAT WE DO

One technical contact grants temporary read-only access in Azure, Entra ID, and the M365 admin centres. No write rights. Not now, not later.

WHAT YOU GET

Access window defined in the SOW. Access expires automatically once the scan is done.

04

Scan

< 3 BUSINESS DAYS
WHAT WE DO

We run the same scanners and checks every time, across cost, identity, and reliability. No manual work where automation suffices.

WHAT YOU GET

Findings collected and prioritised against the standard rubric (high/medium/low).

05

Report + walkthrough

30 MIN
WHAT WE DO

A 25 to 40 page PDF report and a 30-minute walkthrough call. Findings, evidence, annualised savings, mapped remediation packages.

WHAT YOU GET

Report, walkthrough, and written confirmation that all credentials have been removed.

02 · ACCESS

Read-only. Time-limited. Confirmed removed.

We don't need write access for the assessment. Not for cost analysis, not for security checks, not for reliability work. Everything we find, we find via documentation and read-only APIs.

Access expires automatically once the scan is done, usually within three business days. We send written confirmation that credentials have been removed, so you can revoke immediately on your side too.

PERMISSIONS

Read-only, minimal

Reader role on subscriptions, Global Reader in Entra ID, Reports Reader in M365. No Owner, Contributor, or admin rights.

DURATION

Time-limited

Access window written into the SOW. Expires automatically after the scan, usually within three business days.

AUDIT

Everything logged

Every API call shows up in your own audit logs. Nothing happens out of sight. If in doubt, look in Azure Monitor.

REMOVAL

Confirmed in writing

After we're done, you receive an email with a removal statement per credential. You can revoke immediately on your side.

03 · DOCUMENTS

Three documents. Standard. Editable.

Our documents are model agreements, reviewed by a Dutch lawyer and designed to be signed within one business day. Edits are possible. Most clients sign as-is.

SOW

Statement of Work

Scope, turnaround, price, no-cure-no-pay clause, and deliverables. One page.

NDA

Non-disclosure agreement

Mutual. What we see during the scan stays between us.

DPA

Data Processing Agreement

GDPR-compliant. What data we process, for how long, and when it's deleted.

04 · WHAT WE NEVER DO

Five things that don't happen.

01

No write access

Not needed for the assessment. Full stop.

02

No scope creep

Fixed price, fixed scope. Extra work gets re-quoted, never quietly billed.

03

No subcontractors

The scan and the report are done by REL. Nothing offshored.

04

No sales pitch in the report

Findings and recommendations, nothing else. Remediation packages are offered separately, without pressure.

05

No data sharing

Nothing flows to third parties, partners, or marketing systems. GDPR-compliant, written into the DPA.

07 · ACCEPTING ENGAGEMENTS

Accepting engagements.

One intake call. 30 minutes. No prep, no pitch.

Book an intake call30 minutes · free · no prep required