Org Guard · Google Workspace & Microsoft 365 monitoring

Someone should be watching
your admin console. We are.

Your church, nonprofit, or small business runs on Google Workspace or Microsoft 365 — and the break-in evidence lands in an admin console nobody has time to read. Org Guard is a real Security Architect plus an always-on detection engine, watching your organization's accounts, alerts, and audit logs so a stolen password becomes a phone call from us, not a crisis.

Read-only by design · Plain-English reports · Call or text (940) 281-6672
Renewal coming up? Org Guard is also how a church or small organization gets ready for the cyber-insurance questionnaire. Looking for per-inbox scam monitoring for a larger group of staff or members instead? That's our Organizations plans, from $8–15 per inbox — Org Guard covers the platform itself, and many organizations run both.

Read-onlyWe watch with access you grant and can revoke in one click — we never hold your passwords.
Human-reviewedDetections are triaged by our engine, then verified by our Security Architect before you ever hear about them.
One meaningful callNo alert flood. Urgent findings get a phone call; everything else waits for your weekly digest.
Measured, not promised

What "no alert flood" means, in real numbers.

Security vendors love percentages without denominators. Here are ours with the denominators attached — read straight from our production database on August 30, 2026.

3,183messages our engine read and analyzed across protected inboxes in the last 30 days.
23of those were flagged for human review — everything the machine even suspected went to our Security Architect, not straight to you.
1alert actually reached a customer. The other 22 were judged not worth frightening anyone over — that judgment is the product.

That is the difference between a filter and a guardian: an automated system that guesses wrong interrupts you every time it guesses. Ours guesses, then a person decides. When the phone does ring, it matters. These are real numbers from a young service — small denominators, honestly stated — and as the fleet grows we'll keep publishing them, denominators attached.

Why it matters

The attacks on organizations start where nobody is looking.

Account takeover

A staff password leaks in a data breach, someone signs in from the other side of the world, and quietly reads the finance inbox for weeks. Your admin console logged every step — if anyone had been watching.

Hidden forwarding rules & rogue apps

Attackers persist by adding a silent forwarding rule or tricking staff into granting a shady app access to email. Both show up plainly in the audit log — and almost nobody checks.

Wire & payout fraud

The end goal is money: a redirected vendor payment, a changed payroll deposit, a tampered donation payout. We watch the warning signs upstream and put simple money-protecting procedures in place.

The cyber-insurance questionnaire

Insurers now demand MFA, monitoring, and backups before they'll cover you — and the renewal form is due whether you understand it or not. We help you get insurable, then keep you that way — with evidence your broker can hold in their hand. How cyber-insurance readiness works →

What we watch

Your whole digital footprint, one watchful eye.

Coverage starts with the platform your organization lives on, then extends outward to your domain, website, and the places your money moves.

SurfaceWhat we monitorWhat you get
Google WorkspaceSecurity alerts, suspicious sign-ins, admin changes, risky app access grants, forwarding rules, file-sharing anomalies, MFA coverage.Hardening to best practice, takeover response, and a posture score your board can read.
Microsoft 365Risky sign-ins, mailbox rules, audit log, external sharing, Secure Score, legacy sign-in attempts.The same watchful coverage, plus a Secure Score improvement plan and license right-sizing.
Domain & email trustSPF/DKIM/DMARC enforcement, spoofing attempts against your domain, lookalike-domain registrations.Nobody impersonates your organization to target your members — and you see the blocked attempts monthly.
WebsiteUptime, defacement, malware blocklist status, stale admin accounts.A flagged or hijacked website becomes a fast fix, not a reputation crisis.
Staff credentialsWe check your domain against the published breach catalogue — every recorded breach of your organization, when it happened, how many accounts, and whether passwords were among what leaked. Per-address monitoring (which of your specific people appear in dumps) is available once you verify domain ownership with the breach provider.A named list of what leaked and when, so you can force resets on the accounts that actually matter — before someone tries the stolen login.
Exposed servicesAnything of yours facing the internet is cross-referenced against CISA's catalogue of vulnerabilities being exploited right now — not a severity score, the list of what attackers are actually using this week.A short, ranked "fix this first" list, with the ones tied to ransomware campaigns called out. We tell you plainly this is read from public version banners, not from testing your systems.
Giving & finance platformsAdmin access reviews and payout-change controls for donation, payroll, and accounting tools.Written money-movement and payout-change controls, reviewed before funds move.
How we report

Prove it, don't assume it.

Most security reports hand you a list of assertions and a score. You cannot check an assertion, and a score tells you nothing about whether anything actually changed. So every finding we give you arrives with three things attached.

1

The evidence, not the verdict

Not "your email authentication is weak" — the actual record we read, quoted: v=DMARC1; p=none, published at that exact name. Not "you have a lookalike domain" — the domain, and the mail server it is configured to send from. You can verify every line yourself, and so can your IT person, your insurer, or your board.

2

We check again, and say the date

Fixing something is only half of it; knowing it stayed fixed is the other half. Every finding is tracked from the day we first saw it. When you fix one, we re-run the same check and report back "confirmed closed, re-checked on the 14th" — and if it ever comes back, we tell you it came back and how many times.

3

Gaps are stated, never hidden

If a check could not run — a source was down, a lookup timed out — the report says so on the front page and counts it as unknown, not clean. A finding never quietly disappears into "fixed" because we failed to look. This sounds like a small thing. It is the single most common way security reporting lies to people, and we designed it out.

How it works

White glove means we do it with you — in under an hour.

1

Connect & assess

On a screen-share with whoever holds your admin password, we connect read-only monitoring together — you grant it, you can revoke it anytime, and we never ask for credentials. You get a plain-English "State of Your Security" report the same week.

2

Harden & watch

We close the gaps the assessment found — MFA everywhere, admin accounts separated, risky defaults fixed — with every change explained first. Then the engine watches around the clock and the Security Architect reviews what it finds.

3

Hear only what matters — then hear that it's closed

Urgent findings are a phone call with the fix already in motion. Routine findings arrive in a weekly digest. Each month, a one-page report your board or elders can actually read — which doubles as your insurance evidence. It shows what is open, what is new, and what we re-checked and confirmed fixed, with the date we confirmed it.

The guarantee

Watchful, never intrusive.

Org Guard runs on the same promise as everything Family Sentinel builds: least-privilege, read-only access by default, every action logged and explained. One exception, stated plainly: the Google Alert Center connection also permits dismissing alerts, so we can clear a backlog of duplicates for you on request. We never use it otherwise. If a response ever requires hands on the wheel, we ask first — and you stay in the driver's seat.

  • We cannot read, send, or alter your staff's email content.
  • We cannot move or touch any funds, donations, or payroll.
  • We never hold your passwords; access is granted by you and revocable in one click.
  • Every organization is isolated — your data never mixes with anyone else's.
  • We never sell data or train AI on your organization's information.
Plans & pricing

A security team, at a small-organization price.

Real security firms won't take clients this size. IT companies sell support with security bolted on. Org Guard is security only, done properly, priced for the organizations that need it most.

Cyber-Insurance Readiness Checkup
$750 one-time
  • Full posture assessment of your Google Workspace or Microsoft 365
  • Scorecard against the 12 controls insurers probe — each line pass / gap / evidence quoted
  • A one-page, broker-ready summary you hand to your agent at renewal
  • Prioritized fix list, walked through with you on a call
  • Up to 15 users included; $35 per user beyond 15
  • Credited toward your first month if you continue
Book the checkup →
Essentials
$99/mo
  • Small offices: up to 10 staff inboxes
  • Every inbox watched in real time for scams, fraud & takeover signs
  • Domain spoofing protection (DMARC) & lookalike-domain watch
  • Breach-catalogue check & exploited-vulnerability watch on your public services
  • Website monitoring · monthly report
  • No admin-console monitoring, hardening or insurance concierge — that starts at Guardian
Get started →
Guardian
$249/mo
  • Up to 15 staff accounts included, then $12 per additional account (to 25)
  • Google Workspace or Microsoft 365 monitored & hardened
  • Everything in Essentials, plus the admin console: sign-ins, rules, rogue apps, MFA coverage
  • Weekly digest · monthly report
  • Urgent findings = a phone call from your Security Architect
  • Annual threat-awareness talk for staff & volunteers
Get started →
Guardian Plus Insurance Ready
$549/mo
  • Cyber-insurance concierge — the questionnaire, the gaps, and an evidence packet at every renewal
  • Up to 50 staff accounts included, then $12 per additional account (to 75)
  • Everything in Guardian, plus:
  • Giving, payroll & accounting platform reviews
  • Social-media account takeover protection
  • Quarterly access reviews (who can touch what)
  • Annual phishing simulation for staff
Get started →
Guardian Complete
$999/mo
  • Up to 25 staff accounts & devices, then $20 per additional seat — scales cleanly to 100+ endpoints
  • Everything in Guardian Plus, plus:
  • Managed protection on staff computers (EDR)
  • Managed password manager for the whole staff
  • Managed cloud backup & annual restore test
  • Twice-yearly incident practice run with leadership
  • Priority incident response · underwriter follow-ups handled with you
Talk to us →

Churches and nonprofits receive 20% off Essentials, Guardian and Guardian Plus (Essentials is $79); Guardian Complete is quoted individually. For comparison: managed-security providers typically charge $100–$300 per user per month — $2,000+ even for a 15-person staff — and most won't take an organization this size at all. Monitoring runs around the clock; analyst response is business hours with urgent after-hours paging — and we say exactly that, because we'd rather earn your trust than oversell coverage. These are founding-client rates. We take on a small number of organizations at a time so every one of them gets the white glove — and the rate you join at is the rate you keep. As the roster fills, later clients will pay more; you won't. Every limit is published, not buried: exactly what's included — and what isn't → · Getting ready for renewal? Start with cyber-insurance readiness →

Questions organizations ask

Fair questions, straight answers.

Do you need our passwords?

No — ever. You grant read-only monitoring access from your own admin console while we're on a call together, and you can revoke it in one click at any time. We show you exactly what was granted, in writing, on day one.

Is this an IT support service?

No. We are your security team, not your help desk — we don't do printers, password resets, or email migrations. That discipline is why the service stays sharp and affordable. We're happy to work alongside whoever handles your IT.

What happens when you find something?

Our engine flags it, our Security Architect verifies it's real, and then — only then — you hear from us. Urgent issues (like a break-in in progress) are a phone call the moment we confirm it — with the exact fix laid out step by step, walked through together with you or your IT. Routine findings arrive in your weekly digest with plain-English explanations.

Can you help with our cyber-insurance forms?

Yes — it's one of the most valuable things we do. On Guardian Plus and above we sit down with the questionnaire, close the gaps it exposes, and hand you an evidence packet at renewal time; the one-time Cyber-Insurance Readiness Checkup does the same once, with a scorecard your broker can read. What that does: it strengthens the controls insurers commonly evaluate and puts the evidence in your hands before renewal — which may support improved insurability, coverage terms or pricing. What it cannot do: promise a premium. The insurer decides, and we will never tell you otherwise.

What if we want to stop?

You revoke our access from your own console — it works instantly and doesn't need our permission. We hand you an export of your security records and certify deletion of our copies within 30 days. No contracts designed to trap you.

How is this different from Proofpoint, Mimecast, or Abnormal?

Those are excellent enterprise email-security products — built, priced, and staffed for organizations with a security team to receive their output. If you have a SOC and one of those contracts, Org Guard fits beside it: we cover the layers they don't touch — your admin console, cloud configuration, attack surface, breach exposure, and insurance evidence. If you don't have a security team, comparing us to them misses the point: they hand verdicts to analysts you'd still need to hire. Org Guard is the analyst — a flat-price fractional security team with its limits published in writing, which none of them will show you before a demo.

We already have an IT provider or MSP — where do you fit?

Alongside them, and they usually like us. Your MSP keeps things running and typically watches devices — endpoint protection, patches, backups. We watch the layer where organizational fraud actually starts: the email itself, the admin console, forwarding rules, sign-ins, and the money-movement pretexts no endpoint agent can see, because a fraudulent wire request contains no malware and never executes anything on a computer. When we find something, your MSP gets a precise, evidence-backed fix list instead of a vague alarm — we make them look good.

Isn't Microsoft Defender or Google's built-in protection enough?

They're genuinely good — at what they were built for: bulk junk, known-bad links, malware. Keep them; we sit behind them, read-only. What they miss is the message written once, for one person, from a clean account — the vendor "banking update," the payroll-change request, the pastor asking for gift cards — because there is nothing technically wrong with it. And neither of them watches your admin console, where takeover evidence quietly accumulates. Our own measured month is above: of everything the built-in filters delivered, our engine plus a human found exactly one thing worth a phone call — and made it.

Do you try to hack us to prove the risk?

No, and that is deliberate. Everything we check reads public records and the logs you have granted us read-only access to — we never send an attack at your systems, never test whether a weakness can actually be exploited, and never capture or reuse your staff's credentials. Tools that do those things need signed authorization, specialist insurance and an incident plan for when a test goes wrong; that is a different product sold to organizations with a security team to receive it. Where a finding is inferred rather than directly observed — for example reading a software version a server advertises publicly — we label it as inferred and tell you to confirm it against your real patch level. Exactly what we can and cannot touch →

How do I know something we fixed is actually fixed?

Because we run the same check again and report the result with a date. Every finding is tracked from the day we first saw it, and it is only marked closed after a re-check actually ran and could not find it. If the check itself fails, the finding stays open and the report says the check could not run — we never let something drift into "fixed" simply because we stopped being able to see it. And if a fixed issue comes back, the report says it came back, and how many times.

Start with a free posture review.

Fifteen minutes on the phone, a few questions about how your organization runs — and we'll tell you honestly where you stand and whether Org Guard is worth it for you. No pressure, nothing sold that you don't need.

Request the free review

Or simply call — (940) 281-6672 — and talk to the Security Architect directly.

security@familysentinel.org

Related guides