Your church, nonprofit, or small business runs on Google Workspace or Microsoft 365 — and the break-in evidence lands in an admin console nobody has time to read. Org Guard is a real Security Architect plus an always-on detection engine, watching your organization's accounts, alerts, and audit logs so a stolen password becomes a phone call from us, not a crisis.
Read-only by design · Plain-English reports · Call or text (940) 281-6672
Renewal coming up? Org Guard is also how a church or small organization gets ready for the cyber-insurance questionnaire. Looking for per-inbox scam monitoring for a larger group of staff or members instead? That's our Organizations plans, from $8–15 per inbox — Org Guard covers the platform itself, and many organizations run both.
Security vendors love percentages without denominators. Here are ours with the denominators attached — read straight from our production database on August 30, 2026.
That is the difference between a filter and a guardian: an automated system that guesses wrong interrupts you every time it guesses. Ours guesses, then a person decides. When the phone does ring, it matters. These are real numbers from a young service — small denominators, honestly stated — and as the fleet grows we'll keep publishing them, denominators attached.
A staff password leaks in a data breach, someone signs in from the other side of the world, and quietly reads the finance inbox for weeks. Your admin console logged every step — if anyone had been watching.
Attackers persist by adding a silent forwarding rule or tricking staff into granting a shady app access to email. Both show up plainly in the audit log — and almost nobody checks.
The end goal is money: a redirected vendor payment, a changed payroll deposit, a tampered donation payout. We watch the warning signs upstream and put simple money-protecting procedures in place.
Insurers now demand MFA, monitoring, and backups before they'll cover you — and the renewal form is due whether you understand it or not. We help you get insurable, then keep you that way — with evidence your broker can hold in their hand. How cyber-insurance readiness works →
Coverage starts with the platform your organization lives on, then extends outward to your domain, website, and the places your money moves.
| Surface | What we monitor | What you get |
|---|---|---|
| Google Workspace | Security alerts, suspicious sign-ins, admin changes, risky app access grants, forwarding rules, file-sharing anomalies, MFA coverage. | Hardening to best practice, takeover response, and a posture score your board can read. |
| Microsoft 365 | Risky sign-ins, mailbox rules, audit log, external sharing, Secure Score, legacy sign-in attempts. | The same watchful coverage, plus a Secure Score improvement plan and license right-sizing. |
| Domain & email trust | SPF/DKIM/DMARC enforcement, spoofing attempts against your domain, lookalike-domain registrations. | Nobody impersonates your organization to target your members — and you see the blocked attempts monthly. |
| Website | Uptime, defacement, malware blocklist status, stale admin accounts. | A flagged or hijacked website becomes a fast fix, not a reputation crisis. |
| Staff credentials | We check your domain against the published breach catalogue — every recorded breach of your organization, when it happened, how many accounts, and whether passwords were among what leaked. Per-address monitoring (which of your specific people appear in dumps) is available once you verify domain ownership with the breach provider. | A named list of what leaked and when, so you can force resets on the accounts that actually matter — before someone tries the stolen login. |
| Exposed services | Anything of yours facing the internet is cross-referenced against CISA's catalogue of vulnerabilities being exploited right now — not a severity score, the list of what attackers are actually using this week. | A short, ranked "fix this first" list, with the ones tied to ransomware campaigns called out. We tell you plainly this is read from public version banners, not from testing your systems. |
| Giving & finance platforms | Admin access reviews and payout-change controls for donation, payroll, and accounting tools. | Written money-movement and payout-change controls, reviewed before funds move. |
Most security reports hand you a list of assertions and a score. You cannot check an assertion, and a score tells you nothing about whether anything actually changed. So every finding we give you arrives with three things attached.
Not "your email authentication is weak" — the actual record we read, quoted: v=DMARC1; p=none, published at that exact name. Not "you have a lookalike domain" — the domain, and the mail server it is configured to send from. You can verify every line yourself, and so can your IT person, your insurer, or your board.
Fixing something is only half of it; knowing it stayed fixed is the other half. Every finding is tracked from the day we first saw it. When you fix one, we re-run the same check and report back "confirmed closed, re-checked on the 14th" — and if it ever comes back, we tell you it came back and how many times.
If a check could not run — a source was down, a lookup timed out — the report says so on the front page and counts it as unknown, not clean. A finding never quietly disappears into "fixed" because we failed to look. This sounds like a small thing. It is the single most common way security reporting lies to people, and we designed it out.
On a screen-share with whoever holds your admin password, we connect read-only monitoring together — you grant it, you can revoke it anytime, and we never ask for credentials. You get a plain-English "State of Your Security" report the same week.
We close the gaps the assessment found — MFA everywhere, admin accounts separated, risky defaults fixed — with every change explained first. Then the engine watches around the clock and the Security Architect reviews what it finds.
Urgent findings are a phone call with the fix already in motion. Routine findings arrive in a weekly digest. Each month, a one-page report your board or elders can actually read — which doubles as your insurance evidence. It shows what is open, what is new, and what we re-checked and confirmed fixed, with the date we confirmed it.
Org Guard runs on the same promise as everything Family Sentinel builds: least-privilege, read-only access by default, every action logged and explained. One exception, stated plainly: the Google Alert Center connection also permits dismissing alerts, so we can clear a backlog of duplicates for you on request. We never use it otherwise. If a response ever requires hands on the wheel, we ask first — and you stay in the driver's seat.
Real security firms won't take clients this size. IT companies sell support with security bolted on. Org Guard is security only, done properly, priced for the organizations that need it most.
Churches and nonprofits receive 20% off Essentials, Guardian and Guardian Plus (Essentials is $79); Guardian Complete is quoted individually. For comparison: managed-security providers typically charge $100–$300 per user per month — $2,000+ even for a 15-person staff — and most won't take an organization this size at all. Monitoring runs around the clock; analyst response is business hours with urgent after-hours paging — and we say exactly that, because we'd rather earn your trust than oversell coverage. These are founding-client rates. We take on a small number of organizations at a time so every one of them gets the white glove — and the rate you join at is the rate you keep. As the roster fills, later clients will pay more; you won't. Every limit is published, not buried: exactly what's included — and what isn't → · Getting ready for renewal? Start with cyber-insurance readiness →
No — ever. You grant read-only monitoring access from your own admin console while we're on a call together, and you can revoke it in one click at any time. We show you exactly what was granted, in writing, on day one.
No. We are your security team, not your help desk — we don't do printers, password resets, or email migrations. That discipline is why the service stays sharp and affordable. We're happy to work alongside whoever handles your IT.
Our engine flags it, our Security Architect verifies it's real, and then — only then — you hear from us. Urgent issues (like a break-in in progress) are a phone call the moment we confirm it — with the exact fix laid out step by step, walked through together with you or your IT. Routine findings arrive in your weekly digest with plain-English explanations.
Yes — it's one of the most valuable things we do. On Guardian Plus and above we sit down with the questionnaire, close the gaps it exposes, and hand you an evidence packet at renewal time; the one-time Cyber-Insurance Readiness Checkup does the same once, with a scorecard your broker can read. What that does: it strengthens the controls insurers commonly evaluate and puts the evidence in your hands before renewal — which may support improved insurability, coverage terms or pricing. What it cannot do: promise a premium. The insurer decides, and we will never tell you otherwise.
You revoke our access from your own console — it works instantly and doesn't need our permission. We hand you an export of your security records and certify deletion of our copies within 30 days. No contracts designed to trap you.
Those are excellent enterprise email-security products — built, priced, and staffed for organizations with a security team to receive their output. If you have a SOC and one of those contracts, Org Guard fits beside it: we cover the layers they don't touch — your admin console, cloud configuration, attack surface, breach exposure, and insurance evidence. If you don't have a security team, comparing us to them misses the point: they hand verdicts to analysts you'd still need to hire. Org Guard is the analyst — a flat-price fractional security team with its limits published in writing, which none of them will show you before a demo.
Alongside them, and they usually like us. Your MSP keeps things running and typically watches devices — endpoint protection, patches, backups. We watch the layer where organizational fraud actually starts: the email itself, the admin console, forwarding rules, sign-ins, and the money-movement pretexts no endpoint agent can see, because a fraudulent wire request contains no malware and never executes anything on a computer. When we find something, your MSP gets a precise, evidence-backed fix list instead of a vague alarm — we make them look good.
They're genuinely good — at what they were built for: bulk junk, known-bad links, malware. Keep them; we sit behind them, read-only. What they miss is the message written once, for one person, from a clean account — the vendor "banking update," the payroll-change request, the pastor asking for gift cards — because there is nothing technically wrong with it. And neither of them watches your admin console, where takeover evidence quietly accumulates. Our own measured month is above: of everything the built-in filters delivered, our engine plus a human found exactly one thing worth a phone call — and made it.
No, and that is deliberate. Everything we check reads public records and the logs you have granted us read-only access to — we never send an attack at your systems, never test whether a weakness can actually be exploited, and never capture or reuse your staff's credentials. Tools that do those things need signed authorization, specialist insurance and an incident plan for when a test goes wrong; that is a different product sold to organizations with a security team to receive it. Where a finding is inferred rather than directly observed — for example reading a software version a server advertises publicly — we label it as inferred and tell you to confirm it against your real patch level. Exactly what we can and cannot touch →
Because we run the same check again and report the result with a date. Every finding is tracked from the day we first saw it, and it is only marked closed after a re-check actually ran and could not find it. If the check itself fails, the finding stays open and the report says the check could not run — we never let something drift into "fixed" simply because we stopped being able to see it. And if a fixed issue comes back, the report says it came back, and how many times.
Fifteen minutes on the phone, a few questions about how your organization runs — and we'll tell you honestly where you stand and whether Org Guard is worth it for you. No pressure, nothing sold that you don't need.
Request the free reviewOr simply call — (940) 281-6672 — and talk to the Security Architect directly.