P · Protection
Every technical control, connected and continuously validated.
All your security tools integrated into one platform, automatically monitored, assessed and mapped to SMB1001 controls. No manual exports. No stale spreadsheets. Just live evidence.
Technical integrations
Nineteen integrations. One platform.
Every tool in your security stack, endpoint to email to backup to vendor risk, connects once and then reports continuously. The platform evaluates health, validates controls and collects evidence, all without your team lifting a finger.
Platform-driven protection
Connect once. Validate continuously.
The protection dashboard shows every integration's live status: health score, last sync time, active alerts and which SMB1001 controls each tool automatically validates. When something changes, you know about it before it becomes a compliance gap.
Integrations
19 connected · 1 warning












CrowdStrike Falcon
Last sync 4 min ago
47
Endpoints
2 low
Active alerts
4 min
Last sync
SMB1001 Controls Validated
Evidence auto-collected and attached to controls
Connect once, validate continuously
Each integration authenticates once. From that point, the platform continuously polls for health data, alert counts and control evidence, with no manual exports or spreadsheet updates.
Automatic SMB1001 control mapping
When an integration reports healthy status, the platform automatically marks the corresponding SMB1001 controls as evidenced. Your certification posture updates in real time as your security tools change.
Evidence collected, not chased
Every integration generates its own evidence trail: sync logs, health snapshots and control validations are stored automatically and attached to the relevant control in your compliance register.
Additional controls
Beyond the core integrations.
Three controls that are often overlooked, but that carry significant weight in SMB1001 assessments and real-world incident scenarios.
Password vaults
Centralised credential management for all privileged accounts and shared passwords. Platform can ingest vault compliance reports and validates credential hygiene controls. Directly satisfies SMB1001 privileged access management requirements (controls 1.2.x) across Bronze through Platinum tiers, one of the highest-impact, lowest-effort controls to implement.
Live integration: Bitwarden. Also supports 1Password, Keeper, LastPass via manual evidence.
Visitor register
Digital visitor management for physical site access, recording arrivals, departures, host sign-off and NDA acknowledgement. Platform maintains a searchable visit log for compliance evidence. Supports SMB1001 physical security controls and provides an auditable trail for any site access queries.
Works across single and multi-site organisations
Privacy monitor
Continuous dark web monitoring for exposed credentials, leaked data and breach alerts associated with your domains and email addresses. Platform surfaces findings as cases for investigation and tracks remediation. Supports breach notification obligations under the Australian Privacy Act and NZISM.
Covers domains, email addresses and executive names
Technical controls across every SMB1001 tier.
The Protection bundle scales with your certification target. Bronze starts with the highest-impact controls (password vault, basic EDR); Diamond adds 24/7 SOC coverage. Each tier builds on the last, and the platform validates each layer automatically as tools are connected.
Learn about SMB1001 certification →Common questions.
No. The right set depends on your SMB1001 certification target, your existing tools and your budget. Some controls can be satisfied by multiple integrations: for example, both CrowdStrike and Arctic Wolf address MDR requirements. We'll recommend the minimum set needed to satisfy your target tier.
Yes. If you already have a supported tool, we configure the platform connection to your existing subscription. You don't need to replace anything. The platform reads from your existing tools and validates controls against what's already there.
Each integration exposes data the platform uses to evaluate control compliance. For example, when Entra ID reports 100% MFA coverage, the platform marks the corresponding SMB1001 MFA control as validated. When CrowdStrike reports all endpoints enrolled, the EDR control is marked as evidenced. The evaluation runs on every sync cycle.
We recommend and help you configure an appropriate password vault (1Password, Bitwarden, Keeper or similar) based on your team size and environment. We don't run the vault ourselves, but we integrate it into the platform so vault compliance data contributes to your SMB1001 evidence.
It's a digital solution, accessible via tablet, kiosk or browser. Visitors sign in digitally, the host is notified and the record is stored in the platform. No paper sign-in sheets, no manual exports. Works across single and multi-site environments.
All integration findings feed into the Security Command Centre. Alerts become cases in the case management system. Vulnerability findings become risk register entries. Control validations update your compliance posture. Everything that happens in your security tools is visible in one place.
Inside Protection
What's included.
The day to day defending. Someone is watching your systems around the clock, so a problem at two in the morning gets handled at two in the morning rather than discovered on Monday.
Delivered with CrowdStrike, Arctic Wolf and other established partners.
Explore the full GRAPE platform
Ready for real protection?
Book a free consultation and we will assess your current environment, identify which integrations you already have and map the fastest path to your target certification tier.
