TATER Security - Compliance & Security
The compliance and security application at the center of the TATER platform. Continuous M365 and endpoint compliance, automated remediation, the full GRC suite, federal ATO, and an agentic AI analyst. Last updated 2026-08-01
What is TATER Security?
TATER Security is the platform's compliance and security core. It continuously assesses your Microsoft 365 tenants and your endpoint fleet against 4,800+ controls across 30+ frameworks (CIS, NIST 800-53, ISO 27001, SOC 2, PCI-DSS, HIPAA, CISA SCuBA, DISA STIGs, CMMC, FedRAMP, and more), shows you exactly where you stand, and helps you close the gaps with 1,385+ one-click remediation scripts, a complete GRC module suite, a federal ATO pipeline, and a built-in AI analyst.
It lives at app.tatersecurity.com and uses Microsoft Entra sign-in (or local password auth). This is the app most teams open first.
Where it fits in the platform
TATER is one connected platform of six apps that share a single identity, a single data model, and a single AI/MCP layer. TATER Security is the compliance and security hub; the other five apps each own a distinct job and link back to it:
- TATER Security (this app) - compliance, scanning, endpoints, remediation, GRC, ATO.
- TATER Ops - IT service management: tickets, change/incident/release, service catalog.
- TATER Manage - tenant administration, endpoint fleet, MSP and licensing.
- My TATER - the personal dashboard every user lands on.
- TATER Insights - centralized, filterable, exportable reporting.
- TATER Vault - zero-knowledge password and secrets manager.
See the platform overview for the full picture.
Navigation - the modules
Navigation is a two-part rail, matching the sister apps: an icon strip of modules down the far left, and a panel listing the open module's pages. Clicking a rail icon lands on that module's dashboard - KPIs, a tile per page, and recent activity. The rail leads with three utility icons - Favorites (your starred items), Dashboard (the suite overview), and Tasks (tasks assigned to you - opens TATER Ops) - followed by the modules, in rail order:
- Compliance - scans, unified controls, risk acceptances, and the compliance roadmap.
- Endpoint - endpoint posture, TATER Tuning, and hardening.
- Identity - identity security and threat detection (ITDR).
- Cloud - cloud resources and multi-cloud posture.
- Evidence - the evidence library and the collection agent.
- Guidance & Posture - remediation, playbooks, implementation guides, and posture scoring.
- Governance & Risk - risks, exceptions, change control, audits, and the rest of the GRC suite.
- Authorization (ATO) - POA&M, the RMF tracker, and the SSP generator.
- Frameworks - custom and built-in frameworks.
- Assets - devices, compliance zones, people, and data classification.
- Vendors & TPRM - the vendor register, RFPs, contracts, and security ratings.
- Reports - generated reports, the trust center, DLP & DMARC signals, and evidence freshness.
- Knowledge - the TATERpedia wiki, documentation, and the policy library.
- Community - feed, achievements, and leaderboard; this icon opens My TATER directly.
- Settings - org configuration and integrations, as role-filtered tiles.
Three more modules appear only for the roles that use them: TATER Audit (the auditor-firm engagement workbench, shown to audit-firm organizations), MSP (cross-client management, for service providers), and Administration (tenant administration, SuperAdmin only).
Above the rail sits the app switcher - a row of small buttons for the six sister apps - and below it a Search menu box that filters the nav across every module. Press Ctrl+K anywhere for the universal search overlay (recent pages, quick actions, and cross-record search).
Core capabilities
Compliance scanning & frameworks
Run M365 cloud audits, Windows / Server OS CIS benchmark scans, and endpoint vulnerability scans. Map every control to the frameworks you report against, with cross-framework overlap detection and per-org compliance narratives.
- Running Scans - cloud, OS, endpoint, plus STIG/SCAP
.cklimport. - Frameworks & Standards - the 30+ frameworks and how they map.
- Predict the Unknown - infer likely status of Manual Review controls.
- Configuration Inventory - raw tenant config values with drift detection.
Dashboard & reporting
At-a-glance compliance posture, trend charts, risk scoring, and drift alerts. Generate executive, auditor, and technical reports in PDF and CSV. For deep, filterable, exportable reporting across the whole platform, use TATER Insights.
Endpoints & fleet
Track your device fleet with compliance scoring and MDE integration, manage endpoints (live shell, patching, software deployment, BitLocker escrow, USB/app/JIT/DNS policies), and dial in hardening per device group.
- Fleet Management · Endpoint Management (UEM)
- TATER Tuning - dial-based hardening · Interactive Remote Control
Remediation & hardening
Close findings with one-click automated remediation (Azure Automation), admin-defined self-service fixes the agent exposes to end users, and curated step-by-step implementation guides with verification and rollback.
Evidence & audit
Collect compliance evidence automatically, keep a tamper-evident audit trail, and give external auditors time-limited read-only access.
GRC modules
A full governance, risk, and compliance suite sits inside TATER Security: Risk Register, Exceptions, Audit Management, BCP/DR, Data Classification, Training, Control Testing, Change Control, Vendor Risk, Questionnaires, Regulatory Change, Access Reviews, AI Governance, Governance Meetings, and SOC 2 readiness.
Federal / DoD ATO
The authorization pipeline for federal and DoD work: POA&M, the RMF 6-step tracker, and an OSCAL-capable SSP generator.
AI analyst & MCP
A built-in conversational AI analyst works your scan data, and the MCP server lets Claude or Microsoft 365 Copilot act on your compliance posture - always audit-tracked.
Getting started
- Sign in at app.tatersecurity.com with Microsoft Entra ID.
- Run the Setup Wizard or follow Getting Started to connect your tenant and configure scanning.
- Run your first scan, review posture on the dashboard, then assign controls, accept risks, or trigger remediation.
TATER