Your insurer just asked if MFA is enforced for every account. Prove it.

MFAproof reads your Google Workspace or Microsoft 365 directly and produces a dated, verifiable evidence report built for cyber insurance applications and client security questionnaires. Nothing is self-reported.

Top of a sample MFAproof evidence report: verified MFA enforcement verdict and per-status counts for a 23-person company
Sample report
Read-only access Revoke anytime from your admin console We never see passwords or MFA secrets

The security section is where applications stall.

Insurance applications, renewals, and enterprise procurement all ask the same question, and "I think so" is not an answer any of them accept. MFAproof turns the question into a one-page verified artifact.

Keep the deal moving

Whether it is a cyber policy or a customer contract, the MFA question stalls it. Attach a verified answer and move to signature while your competitors are still scheduling a call with their IT guy.

Find the gap before it costs you

Registered is not enforced. One admin account outside your MFA policy can undermine a claim when you need it most. MFAproof names the exact accounts with gaps so you can fix them the same day.

Answer every asker with one artifact

Insurers, enterprise customers, vendor-risk reviews: same question, different letterhead. Generate the report once and hand it to all of them, refreshed whenever you need it current.

How it works

Connect read-only

Your admin authorizes read-only access through your provider's own consent screen. About five minutes, revocable at any time.

We verify enforcement

We read what your identity provider actually enforces for every account, not what a spreadsheet or a memory says.

Download your evidence

A dated PDF naming every account and its status, with a verification link any insurer or reviewer can check independently.

Brokers: stop losing cyber policies to the security section.

Send a client one link and get back a clean, dated MFA evidence pack with your agency's name on it. Your client clears the application hump; you bind the policy. White-label reports and a multi-client dashboard are built for agencies.

$299 one-time

One verified Evidence Report, plus 30 days of refreshed re-runs so your submitted copy is never stale. Continuous monitoring plans arrive at launch.

Early-access signups lock founding pricing below $299.

Common questions

Is the access really read-only?
Yes. Your admin grants read-only scopes through Google's or Microsoft's own consent flow. We cannot change any setting, and we never see passwords or MFA secrets. You can revoke access from your admin console at any time.
Which providers are supported?
Google Workspace at early access. Microsoft 365 / Entra ID at launch, including the messy parts: Conditional Access, Security Defaults, and legacy per-user MFA reconciled into one answer.
Will my insurer accept this?
The report is built as application and questionnaire evidence: every value read directly from your identity provider, timestamped, with an independent verification link. Acceptance is always the insurer's call, which is exactly why nothing in the report is self-reported.
When is launch?
Early access opens to this list first, in signup order. The sample report is available right now so you can see precisely what you would be buying.