We don’t just integrate platforms. We build them.
Avalon is a services-and-products firm. The engineering discipline we sell in engagements — non-destructive by default, governed, audit-friendly — also ships in our own tools: open-core where it makes sense, least-privilege always.
Avalon CloudSec
- Managed service
- Available now
- Onboarding by request
A read-only visibility and assurance service for the security signals your Microsoft 365 tenant already produces. Ten modules collect from Defender XDR, Entra ID, Intune, Defender for Office 365 and Microsoft 365 service health — plus OAuth consent grants, connected AI apps and license waste — and land on one dashboard instead of ten portals, with no agent installed anywhere and no write scope ever requested.
Built for the IT and security teams who own a Microsoft 365 tenant but have no full-time analyst watching it — the organizations where Secure Score, risky sign-ins, OAuth grants, device compliance and phishing volume each live in a different console, and nobody has the hour a day it takes to check them all. Onboarding is a single read-only app registration and takes under an hour.
Design guarantees
- The Microsoft Graph scopes requested are read-only. There is no write path in the product, so neither an operator error nor a compromise of CloudSec can change a policy, dismiss an alert, or touch a user in your tenant.
- Message bodies, files and chats are never read. CloudSec collects security and assurance telemetry only — scores and improvement actions, incident and alert metadata, identity risk signals, device inventory and compliance state, directory and usage reports.
- Remediation stays in Microsoft-native tools. Every finding deep-links to the Microsoft portal that owns it, so CloudSec can surface a problem but is structurally unable to be the thing that quietly fixes — or hides — it.
- The collection credential is encrypted at rest with AES-256-GCM under a key held in the runtime configuration, separate from the database. Full-resolution snapshots thin to one per day after roughly thirty days, daily history is deleted after twelve months, and an offboarded customer's data is purged after ninety days.
Spec sheet
- Secure Score trend and overall tenant posture on a single view
- Entra ID identity protection — risky users, risky sign-ins, MFA coverage and privileged role visibility
- Defender XDR incidents and alerts with severity KPIs, deep-linked to the Microsoft portal that owns them
- Intune device compliance — managed devices, compliance state, stale devices and endpoint health
- Defender for Office 365 email signals — phishing, malware and spam, with trend views
- Application and OAuth governance — every enterprise app and consent grant inventoried, with explainable risk ratings for privileged and tenant-wide access
- Connected AI governance — which AI apps reach your tenant, what they can access, who published them, and an approval workflow
- Continuous compliance evidence — control observations mapped to HIPAA, NIST CSF, PCI DSS, CIS, ISO 27001 and SOC 2, with frozen evidence snapshots
- License intelligence — disabled accounts still holding licenses, inactivity candidates with evidence, and estimated optimization value
- Microsoft 365 service advisories and incident status alongside license utilization
- Ten modules shipped, collected on a fifteen-minute cadence at the fastest tier, into a per-organization private dashboard your team signs into with existing work email
Microsoft Graph (read-only scopes) · Entra ID app registration · Vercel · Supabase (managed PostgreSQL) · Proprietary · managed service
Proprietary · managed service/read-only, onboarding by request
EMaigrator
- Open-core · Apache-2.0
- Available now
- Self-hostable
A non-destructive, streaming, self-hostable engine for migrating mailboxes between AWS WorkMail, Microsoft 365, and Google Workspace. It copies a mailbox provider-to-provider — folder structure, flags, and original dates preserved — without ever modifying the source or writing message bodies to disk.
Built for the people who run migrations: IT admins consolidating or replatforming one organization, and MSPs and consultants moving hundreds of mailboxes across clients — batch mapping, CSV import, and bring-your-own OAuth included. There is no separate “pro” mode.
Design guarantees
- The source mailbox is opened read-only. Nothing on it is ever deleted, moved, or rewritten.
- Body persistence is structurally impossible: the message envelope has no body field, and a schema test fails the build the moment a forbidden column appears.
Spec sheet
- Read-only source — nothing at the origin is deleted, moved, or rewritten
- Streaming pipeline — message bodies are never persisted to disk
- Idempotent & resumable — a per-message identity ledger means re-runs never duplicate
- Reconcile mode — diffs source against destination and copies only what's missing
- Read-only preflight scan — credentials, connectivity, and structural limits checked before data moves
- IMAP, Microsoft Graph, and Gmail API connectors
- Live progress dashboard (SignalR) and a CLI for headless runs
- Per-tenant provider rate limits and a downloadable PDF migration report
- One docker-compose stack: Postgres, RabbitMQ, Redis, API, workers, web UI
.NET 10 · MassTransit + RabbitMQ · PostgreSQL · Redis · React 19 · Apache-2.0 (open-core engine)
Prebuilt images: Docker Hub
Open source · Apache-2.0/available now, self-hostable
Mirsat
- Private beta · invite-only
- In active development
- Managed service
A multi-cloud container console that replaces tab-juggling between the AWS, Azure and GCP consoles with one interface for discovery, logs, deploys, env vars, rollback and container exec. Every change is written as a commit to a state repository the customer owns, so rollback is a git revert and the audit trail exists by construction rather than by discipline.
Built for small engineering teams — roughly one to ten people — running containerized workloads on managed cloud runtimes who would rather not learn three cloud consoles to ship, and who need a junior engineer to be able to deploy without holding console credentials.
Design guarantees
- Onboarding is least-privilege: the starting policy lets Mirsat verify identity, list services and read logs. No write, deploy, or secret access is granted.
- The customer's state repository is never force-pushed. Every write takes an advisory lock and writes an audit row, and CI fails the build if a force-push appears.
- Manual edits to committed state are detected and held for review in the dashboard before anything is applied.
- Exec shipped with recording and RBAC together — there is deliberately no mode that execs without recording.
Spec sheet
- Discovery and live log tail across six runtimes — ECS, Azure Container Apps, Container Instances, ACA Jobs, Cloud Run and Cloud Run Jobs
- Deploy, roll back and edit environment variables on AWS ECS; Azure and GCP write support is roadmap, not shipped
- Browser exec into a running ECS task, owner/admin only, with full session recording and replay
- Every change committed to a customer-owned GitHub state repo — rollback is git revert plus apply
- Brownfield adoption of workloads that already exist, plus read-only drift detection against the last commit
- Multi-tenant isolation enforced at the database by Postgres row-level security
- Audit log of every write action, filterable, with streaming CSV export
- Deploy API tokens for CI/CD, with a worked GitHub Actions example
- Cloud credentials envelope-encrypted at rest under a per-org data key sealed by KMS
.NET 10 · React 19 · PostgreSQL 16 + RLS · SignalR + Redis · Auth0
Proprietary · closed beta/invite-only while we harden it
Tell us what'skeeping you upat night.
Most engagements start with a Cloud Health Check — one week, full audit, top-10 findings, 90-day roadmap. Many turn into a longer engagement; either way, you walk away with a prioritized plan you own.