Back to the registry
Agent passport

AI Security Risk Assessment: Protect Cloud AI Platform and Apps You Already Run

Simplicity IT Inc. · Cybersecurity & IT

SaaSNo attestation published

Certification per Microsoft Marketplace.

protect cloud ai platform and appsdata securityshadow ai
Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 7 captures on record

User ratingNot rated0 reviews on the listing
Runs onSaaSSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

Built for the CISO who has been asked by the board what AI the company is using and has to answer honestly that nobody knows. This engagement will eliminate the blind spot around unsanctioned AI usage and reduce the exposure it is already creating.

Who this is for

Show the rest of the publisher’s description (21 more lines)

CISOs who have been asked a question they cannot answer. The trigger is almost always external: a board question, a customer security questionnaire asking about AI usage, a regulator, or an insurer adding an AI clause. The organization has an AI policy or is about to write one, and needs to know the actual position before committing to anything in writing. This assessment produces that position.

What we deliver

  • Shadow AI discovery across the estate: which generative AI applications are in use, by how many people, how often, and through what path, covering both sanctioned services and the ones nobody approved.
  • Data exposure analysis showing what categories of data are reaching each AI service, with labeled and regulated content called out specifically, and the identities and departments involved.
  • An inventory of AI agents, plugins, and connectors already deployed inside your Microsoft estate, including Copilot Studio agents, Power Platform connectors, and third-party applications holding Microsoft Graph permissions, with the permission scope each one actually has.
  • A ranked risk register with each finding scored on likelihood and impact, plus remediation options costed at three levels so the response can be matched to the organization's actual risk appetite rather than a maximalist recommendation.Outcomes our customers see

One assessment across 5,600 seats found 34 generative AI applications in active use against an expected 3, with 12 of them receiving content carrying a confidential label. An agent and permission inventory at a financial services customer surfaced 8 third-party applications holding tenant-wide Microsoft Graph read permissions granted over 500 days earlier and never reviewed. Assessments are delivered in 12 business days, and 11 of the last 12 customers proceeded to remediation within 60 days of receiving the register.

How this compares

The AI risk assessments in this market are mostly questionnaire-based, meaning they document what people say they use. This one measures what is actually happening using Defender for Cloud Apps and Purview telemetry, and the gap between the two is consistently the most useful finding in the report. The agent and Graph permission inventory is the part almost nobody else includes, and it is where the genuinely serious exposure tends to sit.

Architecture and Microsoft alignment

Discovery runs read-only through Microsoft Defender for Cloud Apps for shadow AI application usage, Microsoft Purview Data Security Posture Management for AI for data exposure, Microsoft Entra ID enterprise application and consent records for third-party permission scope, Microsoft Graph for the agent and connector inventory, and Power Platform admin analytics for Copilot Studio agents. Endpoint and network telemetry is used where available to catch usage that does not traverse a Microsoft identity path. No content is read and nothing is changed. Aligned to the Microsoft solution plays Protect Cloud AI Platform and Apps and Data Security.

Plans

Plans, prices, and full scope per plan are on the Plans tab of this listing.

Prerequisites

Global Reader and Security Reader consent, Microsoft 365 E5 or the E5 Security and Compliance add-ons for full discovery fidelity, and Power Platform administrator read access. Where Defender for Cloud Apps is not licensed, discovery fidelity drops materially and that limitation is stated in the report rather than worked around silently.

Limitations

This is a read-only assessment; nothing is blocked, revoked, or remediated, and remediation is quoted separately. AI usage on personal devices outside all managed telemetry is not discoverable and the report says so explicitly rather than implying full coverage. The assessment covers AI consumption risk; it does not review the security of AI systems your own engineering teams are building, which is a separate engagement.

How to buy

Buy through the Azure portal, using Get it in Azure portal on this listing, so the purchase is billed through your existing Microsoft agreement. Private offers on request.

Next step

Get it now in the Azure portal, or request a private offer if the scope or the price needs adjusting first.

Preview

5 images
AI Security Risk Assessment: Protect Cloud AI Platform and Apps You Already Run preview 1AI Security Risk Assessment: Protect Cloud AI Platform and Apps You Already Run preview 2AI Security Risk Assessment: Protect Cloud AI Platform and Apps You Already Run preview 3AI Security Risk Assessment: Protect Cloud AI Platform and Apps You Already Run preview 4AI Security Risk Assessment: Protect Cloud AI Platform and Apps You Already Run preview 5

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanySimplicity It Inc.Automated
HQUnited States of AmericaAutomated
IndustryTechnologyAutomated
Websitehttps://www.simplicityitinc.com/

Plans and pricing as listed

1 listed
AI Security Risk Assessment
$2,499.00/month
The plan is billed at a fixed monthly rate on a one month term, so the assessment can start without a long commitment.

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource

Publisher resources

1 link

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
1 plan listed
Delivery
SaaS
https://service.simpleintelligencegroup.com/support
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.