P · Protection
Every technical control, connected and continuously validated.
All your security tools integrated into one platform, automatically monitored, assessed and mapped to SMB1001 controls. No manual exports. No stale spreadsheets. Just live evidence.
Technical integrations
Eight integrations. One platform.
Each integration connects once, then reports continuously. The platform evaluates health, validates controls and collects evidence, all without your team lifting a finger.
CrowdStrike Falcon
Endpoint protection
AI-powered EDR on every endpoint. Threat detection, automated containment and real-time response without needing an in-house SOC. Platform automatically validates SMB1001 endpoint controls once connected.
Arctic Wolf
Managed detection & response
Human-led SOC-as-a-service with 24/7 coverage. Arctic Wolf analysts investigate alerts, suppress false positives and escalate real threats. Platform ingests findings directly into your risk register.
Microsoft Entra ID
Identity & access
MFA enforcement, conditional access policies and identity governance across your Microsoft environment. Platform tracks MFA coverage percentage, flags ungated accounts and validates identity controls automatically.
Cisco Meraki
Network security
Cloud-managed firewall, traffic monitoring and network segmentation across all your sites. Platform surfaces Meraki security posture and maps network controls to your SMB1001 evidence.
NinjaOne
Endpoint management
Device inventory, patch compliance tracking and endpoint health monitoring across your entire fleet. Platform pulls NinjaOne data to track patch currency and flag devices that are overdue.
PowerDMARC
Email & domain security
DMARC, DKIM and SPF enforcement across all your domains, preventing spoofing and protecting your brand. Platform continuously monitors domain email authentication status and alerts on degradation.
Qualys VMDR
Vulnerability management
Continuous vulnerability scanning, asset discovery and risk-based prioritisation. Platform ingests Qualys findings, maps them to your risk register and tracks remediation progress against open risks.
CheckRed
Cloud security posture
Continuous cloud configuration assessment against CIS benchmarks across AWS, Azure and GCP. Platform surfaces CheckRed findings as risks and tracks remediation inside your treatment plans.
Platform-driven protection
Connect once. Validate continuously.
The protection dashboard shows every integration's live status: health score, last sync time, active alerts and which SMB1001 controls each tool automatically validates. When something changes, you know about it before it becomes a compliance gap.
Integrations
8 connected · 1 warningCrowdStrike Falcon
Last sync 4 min ago
47
Endpoints
2 low
Active alerts
4 min
Last sync
SMB1001 Controls Validated
Evidence auto-collected and attached to controls
Connect once, validate continuously
Each integration authenticates once. From that point, the platform continuously polls for health data, alert counts and control evidence, with no manual exports or spreadsheet updates.
Automatic SMB1001 control mapping
When an integration reports healthy status, the platform automatically marks the corresponding SMB1001 controls as evidenced. Your certification posture updates in real time as your security tools change.
Evidence collected, not chased
Every integration generates its own evidence trail: sync logs, health snapshots and control validations are stored automatically and attached to the relevant control in your compliance register.
Additional controls
Beyond the core integrations.
Three controls that are often overlooked, but that carry significant weight in SMB1001 assessments and real-world incident scenarios.
Password vaults
Centralised credential management for all privileged accounts and shared passwords. Platform can ingest vault compliance reports and validates credential hygiene controls. Directly satisfies SMB1001 privileged access management requirements (controls 1.2.x) across Bronze through Platinum tiers, one of the highest-impact, lowest-effort controls to implement.
Supports: 1Password, Bitwarden, Keeper, LastPass
Visitor register
Digital visitor management for physical site access, recording arrivals, departures, host sign-off and NDA acknowledgement. Platform maintains a searchable visit log for compliance evidence. Supports SMB1001 physical security controls and provides an auditable trail for any site access queries.
Works across single and multi-site organisations
Privacy monitor
Continuous dark web monitoring for exposed credentials, leaked data and breach alerts associated with your domains and email addresses. Platform surfaces findings as cases for investigation and tracks remediation. Supports breach notification obligations under the Australian Privacy Act and NZISM.
Covers domains, email addresses and executive names
Technical controls across every SMB1001 tier.
The Protection bundle scales with your certification target. Bronze starts with the highest-impact controls (password vault, basic EDR); Diamond adds 24/7 SOC coverage. Each tier builds on the last, and the platform validates each layer automatically as tools are connected.
Learn about SMB1001 certification →Common questions.
No. The right set depends on your SMB1001 certification target, your existing tools and your budget. Some controls can be satisfied by multiple integrations: for example, both CrowdStrike and Arctic Wolf address MDR requirements. We'll recommend the minimum set needed to satisfy your target tier.
Yes. If you already have a supported tool, we configure the platform connection to your existing subscription. You don't need to replace anything. The platform reads from your existing tools and validates controls against what's already there.
Each integration exposes data the platform uses to evaluate control compliance. For example, when Entra ID reports 100% MFA coverage, the platform marks the corresponding SMB1001 MFA control as validated. When CrowdStrike reports all endpoints enrolled, the EDR control is marked as evidenced. The evaluation runs on every sync cycle.
We recommend and help you configure an appropriate password vault (1Password, Bitwarden, Keeper or similar) based on your team size and environment. We don't run the vault ourselves, but we integrate it into the platform so vault compliance data contributes to your SMB1001 evidence.
It's a digital solution, accessible via tablet, kiosk or browser. Visitors sign in digitally, the host is notified and the record is stored in the platform. No paper sign-in sheets, no manual exports. Works across single and multi-site environments.
All integration findings feed into the Security Command Centre. Alerts become cases in the case management system. Vulnerability findings become risk register entries. Control validations update your compliance posture. Everything that happens in your security tools is visible in one place.
Inside Protection
What's included.
The day to day defending. Someone is watching your systems around the clock, so a problem at two in the morning gets handled at two in the morning rather than discovered on Monday.
Delivered with CrowdStrike, Arctic Wolf and other established partners.
Explore the full GRAPE platform
Ready for real protection?
Book a free consultation and we will assess your current environment, identify which integrations you already have and map the fastest path to your target certification tier.

