TATER SecurityAll docs

TATER Security - Compliance & Security

The compliance and security application at the center of the TATER platform. Continuous M365 and endpoint compliance, automated remediation, the full GRC suite, federal ATO, and an agentic AI analyst. Last updated 2026-08-01

What is TATER Security?

TATER Security is the platform's compliance and security core. It continuously assesses your Microsoft 365 tenants and your endpoint fleet against 4,800+ controls across 30+ frameworks (CIS, NIST 800-53, ISO 27001, SOC 2, PCI-DSS, HIPAA, CISA SCuBA, DISA STIGs, CMMC, FedRAMP, and more), shows you exactly where you stand, and helps you close the gaps with 1,385+ one-click remediation scripts, a complete GRC module suite, a federal ATO pipeline, and a built-in AI analyst.

It lives at app.tatersecurity.com and uses Microsoft Entra sign-in (or local password auth). This is the app most teams open first.

Where it fits in the platform

TATER is one connected platform of six apps that share a single identity, a single data model, and a single AI/MCP layer. TATER Security is the compliance and security hub; the other five apps each own a distinct job and link back to it:

See the platform overview for the full picture.

Navigation is a two-part rail, matching the sister apps: an icon strip of modules down the far left, and a panel listing the open module's pages. Clicking a rail icon lands on that module's dashboard - KPIs, a tile per page, and recent activity. The rail leads with three utility icons - Favorites (your starred items), Dashboard (the suite overview), and Tasks (tasks assigned to you - opens TATER Ops) - followed by the modules, in rail order:

Three more modules appear only for the roles that use them: TATER Audit (the auditor-firm engagement workbench, shown to audit-firm organizations), MSP (cross-client management, for service providers), and Administration (tenant administration, SuperAdmin only).

Above the rail sits the app switcher - a row of small buttons for the six sister apps - and below it a Search menu box that filters the nav across every module. Press Ctrl+K anywhere for the universal search overlay (recent pages, quick actions, and cross-record search).

Core capabilities

Compliance scanning & frameworks

Run M365 cloud audits, Windows / Server OS CIS benchmark scans, and endpoint vulnerability scans. Map every control to the frameworks you report against, with cross-framework overlap detection and per-org compliance narratives.

Dashboard & reporting

At-a-glance compliance posture, trend charts, risk scoring, and drift alerts. Generate executive, auditor, and technical reports in PDF and CSV. For deep, filterable, exportable reporting across the whole platform, use TATER Insights.

Endpoints & fleet

Track your device fleet with compliance scoring and MDE integration, manage endpoints (live shell, patching, software deployment, BitLocker escrow, USB/app/JIT/DNS policies), and dial in hardening per device group.

Remediation & hardening

Close findings with one-click automated remediation (Azure Automation), admin-defined self-service fixes the agent exposes to end users, and curated step-by-step implementation guides with verification and rollback.

Evidence & audit

Collect compliance evidence automatically, keep a tamper-evident audit trail, and give external auditors time-limited read-only access.

GRC modules

A full governance, risk, and compliance suite sits inside TATER Security: Risk Register, Exceptions, Audit Management, BCP/DR, Data Classification, Training, Control Testing, Change Control, Vendor Risk, Questionnaires, Regulatory Change, Access Reviews, AI Governance, Governance Meetings, and SOC 2 readiness.

Federal / DoD ATO

The authorization pipeline for federal and DoD work: POA&M, the RMF 6-step tracker, and an OSCAL-capable SSP generator.

AI analyst & MCP

A built-in conversational AI analyst works your scan data, and the MCP server lets Claude or Microsoft 365 Copilot act on your compliance posture - always audit-tracked.

Getting started

  1. Sign in at app.tatersecurity.com with Microsoft Entra ID.
  2. Run the Setup Wizard or follow Getting Started to connect your tenant and configure scanning.
  3. Run your first scan, review posture on the dashboard, then assign controls, accept risks, or trigger remediation.