A brand-new tenant, straight out of the box, does not pass. The Free AI Readiness Assessment runs 112 checks against CIS Benchmarks and the NIST AI Risk Management Framework and scores your tenant 0–100 — every finding opening to the evidence behind it and the fix. Under fifteen minutes, free.
If you connected an AI agent, MCP server or app today, it could reach and move sensitive data right now. A brand-new tenant, straight out of the box, does not pass.
Illustrative scan of a default-configuration Microsoft 365 tenant. 98/112 checks returned a result. 0% of the score is self-attested.
Sabiki Security makes AIRM — the platform that gets Microsoft 365 organisations ready for AI, and keeps them that way. Two offerings, one journey:
Find out if you're ready to switch AI on.
If you connected an AI agent, MCP server or app today, it could reach and move sensitive data right now. A brand-new tenant, straight out of the box, does not pass.
Illustrative scan of a default-configuration Microsoft 365 tenant. 98/112 checks returned a result. 0% of the score is self-attested.
Stay ready, every day after.
Security lead? AIRM has its own free front door — the Sabiki NHI Risk Score™: every non-human identity in the tenant, scored 0–100, in about five minutes. Get your free score →
Copilot — and every agent like it — operates with the permissions, sharing settings and data controls that already exist in your tenant. A file that is overshared today becomes a file the assistant can surface on request tomorrow. An open consent setting today becomes a path for an agent to enter the tenant tomorrow. Deployment doesn't create these conditions. It makes them reachable at speed and at scale.
And AI works at machine speed — it doesn't wait or sleep, and it registers its own identities that act with standing permissions around the clock: a new actor in your tenant with no human in the loop. It can reach and move data through channels you never had to police — a stale "anyone" SharePoint link, an over-permissioned agent, mailbox auto-forwarding, a quietly-consented third-party app. A misconfiguration that was low-risk yesterday is now reachable by AI at scale, instantly.
That's why the assessment is a readiness gate, not an inventory tool — and why a default Microsoft 365 tenant, measured against CIS Benchmarks and the NIST AI Risk Management Framework, does not pass.
Create your free account and connect one Microsoft 365 tenant. Agentless — nothing installed. Every permission is listed on the consent screen before anything connects.
112 checks against CIS Benchmarks and the NIST AI Risk Management Framework — assessed from what your tenant actually shows, not a questionnaire. Nothing is self-attested; nothing changes without a person approving it.
A 0–100 score and band in your Readiness dashboard, plus the full report: every finding scored by severity and weight, each opening to the evidence and the fix. Yours to keep — whether or not you ever pay us anything.
You have three free scans per tenant: your baseline, your progress, your proof. Watch the Score move as you remediate — and when you want it watched continuously, Explore AIRM is one click from your dashboard.
Sample: Northwind Trading, a fictional demo tenant. The product, the checks and the numbers are real. The company and the identity names are not.
A score is a moment in time. The tenant changes the day after: new AI agents appear, consents sprawl, owners leave. That is why your Readiness dashboard carries one more button — Explore AIRM. One click starts your trial of the platform that watches the tenant continuously, so the Score you earned stays earned.
The assessment names them once.
The assessment counts them once.
The assessment scores you once.
“We paid for an assessment last year and I thought we were covered. The free Sabiki report found things that engagement never looked at… There was a list of applications reading mail that I had never seen and could not account for. I got more out of this than I got out of the work we paid for.”
Michael Barbara · Owner, Perfecto Foods
Yes — sign-up, three scans per tenant, and the scored report are free, and the report is yours whether or not you ever pay us. The business model is simple and stated: fixing the gaps is where money changes hands — through your MSP's remediation work, or through AIRM, our subscription platform, which you can trial from your Readiness dashboard. Both are offered, never required.
Because one number proves nothing. Scan one is your baseline. Fix what the plan tells you, scan again — that's your progress. Scan three is your proof, the before-and-after your board actually believes. When you want the Score watched continuously instead of on demand, that's AIRM.
Nothing without a person approving it. The assessment reads identity and permission metadata — not your emails, files or documents — through delegated Microsoft Graph permissions, listed in full on the consent screen. Access is revocable in the Microsoft Entra admin centre at any time.
Two products, two questions. The AI Readiness Assessment answers "are we ready to switch AI on?" — 112 checks, scored 0–100. The Sabiki NHI Risk Score™ answers "what's already running that nobody owns?" — every non-human identity, scored 0–100. Run either first; they meet at AIRM.
Secure Score remains a useful control — it grades configuration against a checklist, for a world where the identities signing in are people. It doesn't ask whether the tenant is ready for AI: it carries no line item for a non-human identity, or for whether your sharing posture is safe to expose to an assistant. A good Secure Score and an unsafe AI deployment are not mutually exclusive — we see the combination regularly.
The platform runs on Microsoft Azure, Southeast Asia (Singapore), with findings stored in MongoDB Atlas in the same region. Customer tenant data stays in Singapore, is never used to train models, and is never shared with any third-party AI provider.
Every week you wait, more agents appear in the tenant with nobody watching them. Get the number, get the plan, decide from evidence.
No credit card · Three free scans per tenant · Nothing installed · Nothing changes without your approval