Skip to content

How Trimtab works

Trimtab continuously checks the technical settings behind CMMC Level 2 and the HIPAA Security Rule, explains every gap in plain English, and tells you when anything drifts.

The daily cycle

flowchart LR
  A[Lookout scans the device] --> B[Results upload over HTTPS]
  C[Bridge scans the Microsoft 365 tenant] --> D[(The Bridge)]
  B --> D
  D --> E[Score, drift, and corrections]
  1. Lookout scans each device once a day and about 15 minutes after every restart. Each scan runs 37 read-only checks in under a minute.
  2. Results upload to the Bridge over HTTPS. If the device is offline, results wait in a local queue and upload later.
  3. The Bridge scans each connected Microsoft 365 tenant daily: 11 identity and sharing checks plus 8 Exchange Online and email checks.
  4. Every result is charted to the standards the client selected. The Bridge calculates a score, compares it to the previous scan, and flags anything that drifted.
  5. You correct course. Every finding comes with evidence, why it matters, and step-by-step instructions.

Key ideas

Fleet : All devices and tenants across your clients, on one page.

Client : An organization you manage. Each client has its own enrollment keys, devices, tenant, and selected standards.

Standards : The frameworks a client is scored against: CMMC Level 2, HIPAA, or both. See Standards and checks.

Drift : A check that passed on the previous scan and fails now.

Overdue : A device that hasn't reported in for 3 or more days.

Read-only : Lookout and the Microsoft 365 connection only read settings. Trimtab never changes a device or tenant.

What Trimtab doesn't prove

Technical checks prove technical settings. Policies, training, physical security, and other process requirements still need their own evidence. Each standard page lists exactly which requirements Trimtab covers.