New
SaaS governance · built for Australia

Govern the SaaS
your enterprise didn't
know it was running.

ThreatLynx helps discover third-party applications connected to your Google Workspace and Microsoft 365 tenants via OAuth, scores them against framework-grade criteria, and gives security teams an audit trail their regulators can review.

Agentless
OAuth API only — no endpoint software.
Read-only
Platform never writes to tenant data.
No lock-in
Cancel and full-export on request.
AU resident
Security telemetry stored in Australia — AWS Sydney (ap-southeast-2).
app.threatlynx.com.au/discovery
Production · AWS Sydney
⌘K
Discovered SaaS
1,248
↑ 12 this week
High-risk apps
34
needs review
OAuth permissions
8,592
across 4 tenants
Posture · E8
92%
aligned
Shadow IT discovery · past 30 days
+ 41 new apps · 6 newly classified high-risk
7d30d90d
Applications· 1,248
Source: Google WorkspaceLast sync 4m ago
ApplicationCategoryUsersScopesRiskStatusFirst seen
N
Notion AI
notion.so
AI · Productivity14214
78
ReviewOct 04
L
Loom
loom.com
Video868
42
ApprovedAug 22
O
Otter.ai
otter.ai
AI · Transcription3811
71
ReviewSep 18
G
Grammarly
grammarly.com
AI · Writing2119
64
ApprovedApr 01
F
Figma
figma.com
Design645
28
ApprovedFeb 11
Z
Zapier
zapier.com
Automation1217
81
BlockedJun 09
Live demo · sample tenant · Globalcorp Pty LtdSwitch tabs → to explore
Coverage
Built to connect with your stack.
Google Workspace and Microsoft 365 are live today via read-only OAuth. Additional enterprise integrations are on the roadmap.
Live · 2 active integrations
Google Workspace
Microsoft 365
Okta
Slack
Atlassian
Salesforce
GitHub
Zoom
Box
Notion
The platform

Shadow IT visibility — without an agent on a single endpoint.

Four product surfaces working from one inventory of truth. Built for security and IT teams that need operational visibility, not another endpoint to patch.

01 · Discovery

See every third-party application — sanctioned or not.

Continuous SaaS discovery runs as new OAuth grants are issued. Inventory connected vendors, the users who authorised them, and the scopes they granted. ThreatLynx helps identify connected applications as they appear in your tenant.

  • 01OAuth-grant capture across Workspace and M365
  • 02User-by-user authorisation history with timestamps
  • 03Domain, category, vendor domicile, and prior-seen flags
Read the Discovery reference
app.threatlynx.com.au/discovery
Production · AWS Sydney
⌘K
Discovered SaaS
1,248
↑ 12 this week
High-risk apps
34
needs review
OAuth permissions
8,592
across 4 tenants
Posture · E8
92%
aligned
Shadow IT discovery · past 30 days
+ 41 new apps · 6 newly classified high-risk
7d30d90d
Applications· 1,248
Source: Google WorkspaceLast sync 4m ago
ApplicationCategoryUsersScopesRiskStatusFirst seen
N
Notion AI
notion.so
AI · Productivity14214
78
ReviewOct 04
L
Loom
loom.com
Video868
42
ApprovedAug 22
O
Otter.ai
otter.ai
AI · Transcription3811
71
ReviewSep 18
G
Grammarly
grammarly.com
AI · Writing2119
64
ApprovedApr 01
F
Figma
figma.com
Design645
28
ApprovedFeb 11
Z
Zapier
zapier.com
Automation1217
81
BlockedJun 09
02 · Risk Scoring

A risk model your auditor can read.

Every discovered app receives a composite score across four explicit dimensions — data breadth, permission sensitivity, vendor domicile, and affected user count. No black-box AI label. Every score is fully explainable from the inputs.

  • 01Composite score 0–100 with per-dimension contributors
  • 02Tunable thresholds — your tolerance, your policy
  • 03Per-vendor history — see how risk has shifted over time
Read the Risk Scoring reference
app.threatlynx.com.au/risk
Production · AWS Sydney
⌘K
Risk catalog · all vendors
Sorted by composite risk · breadth, sensitivity, domicile, exposure
High · 34Med · 92Low · 1,122
#ApplicationCompositeData breadthSensitivityDomicileExposure
01Zapier
81
7369US12 users
02Notion AI
78
7066US142 users
03Otter.ai
71
6460US38 users
04Grammarly
64
5854US211 users
05Miro
47
4240NL92 users
06Loom
42
3836US86 users
07Calendly
35
3230US174 users
03 · OAuth Intelligence

Permission visibility down to the scope.

See exactly what each connected app can read, write, or delete — Gmail, Drive, Calendar, Contacts, and Admin Directory. Triage by impact and revoke high-risk grants without leaving the console.

  • 01Scope-level read / write / delete breakdown
  • 02Sensitivity classification (Standard, Restricted, Admin)
  • 03One-click revocation routed through the OAuth API
Read the OAuth Intelligence reference
app.threatlynx.com.au/oauth/notion-ai
Production · AWS Sydney
⌘K
Notion AI — OAuth grants
14 scopes · 142 grants · client_id 8841…0bc2
Risk 78 · High
ServiceScopeReadWriteDeleteGrants
Gmailgmail.readonly142
Drivedrive.file142
Drivedrive.metadata142
Calendarcalendar.events142
Adminadmin.directory.user4
Contactscontacts.readonly142
Selected scope
admin.directory.user
Sensitivity
High · Restricted
Affects
Org directory · all users
Granted by
4 admins · last 90d
Frameworks
E8 · App Control, APRA CPS 234
Suggested action · Revoke admin directory access for non-essential apps. Restrict re-grants via OAuth allow-list policy.
04 · Governance Workflows

Approve, restrict, or block — with the audit trail to prove it.

Codify your governance posture as policies. Assign owners, document decisions, and let ThreatLynx record every action against every application, automatically. Export point-in-time evidence for access reviews and regulator requests.

  • 01Approve / Review / Block with assigned owners
  • 02Policy-driven automation for predictable enforcement
  • 03Audit trail with actor, action, timestamp, and rationale
Read the Governance Workflows reference
app.threatlynx.com.au/policies
Production · AWS Sydney
⌘K
Governance policies
4 active · 18 triggered events past 7 days
PolicyScopeOwner7d triggersStatus
Block apps with admin.directory.* writeOAuth scopesS. Patel12Active
Require review for AI tools with PII accessCategory · AIM. Chen8Active
Auto-approve apps with vendor SOC 2 + region AUVendor postureAuto24Active
Notify owner on new high-risk discoveryRisk ≥ 70Auto6Active
Audit trail · last 24h
09:42S. Patel blocked zapier.com · policy matchBlock08:17Auto approved calendly.com · vendor postureApprove07:55M. Chen assigned owner to otter.aiAssign
Enterprise trust

Built for Australian regulated sectors.

ThreatLynx provides governance visibility and evidence workflows relevant to financial services, healthcare, and government environments. Framework mappings are rules-based references to support governance readiness — not compliance certification.

Residency
AWS Sydney · ap-southeast-2
Customer security telemetry stored in Australia (Sydney), encrypted at rest with authenticated encryption and key rotation; per-tenant AWS KMS envelope encryption is rolling out. Email and billing use named US subprocessors.
Compliance posture
Updated 2 May 2026
ISO/IEC 27001
Mapping available
Annex A — asset mgmt, access control
SOC 2 Type II
Planned · Q2
Trust services — security, availability
Essential Eight
Mapping available
ML2 app control evidence support
APRA CPS 234
Mapping available
Third-party information asset register
Australian Privacy
Evidence support
APP 8, 11 — overseas disclosure visibility
IRAP
On request
Assessment-ready evidence package
Framework alignment
Download mapping pack
References support governance readiness — they do not certify compliance.
BodyScopeAlignmentEvidence
ASD / ACSCEssential EightML2 mappingApp control evidence export
APRACPS 234Asset register · access mgmtThird-party information assets
OAICPrivacy Act · APPAPP 1, 8, 11PII exposure surface inventory
ISO/IEC27001:2022Annex A 5.19, 5.20, 8.7Vendor inventory, scope register
DTAHosting StrategyAU sovereigntyap-southeast-2 residency
Deployment

Operational in under ten minutes.

No infrastructure changes. No endpoint software. No procurement gauntlet. Just an OAuth authorisation and an inventory waiting on the other side.

STEP 01

Authorise — read-only

Sign in as a Workspace or M365 administrator and authorise ThreatLynx via OAuth. We request a scoped, read-only token. No agents, no proxies, no changes to tenant configuration.

· Workspace admin1 person
· OAuth scopesreadonly
· Provisioning time< 2 min
STEP 02

Discovery runs automatically

ThreatLynx maps every connected application, permission scope, and affected user. Your full SaaS inventory — including apps IT didn't know existed — is available within minutes.

· Initial scan~6 min
· Continuous sync15 min cadence
· Backfill24 mo of grants
STEP 03

Review, govern, evidence

Triage by composite risk, record governance decisions against each application, and export point-in-time evidence packs for stakeholders, access reviews, and regulators.

· Audit trailper-action
· Evidence exportCSV / JSON / PDF
· APIfor SIEM forwarding
Pricing

Organisation-size pricing — never per seat.

Predictable platform pricing based on organisational complexity and risk exposure. All amounts in Australian Dollars, excluding GST. Regulated or multi-entity organisations should contact us for a tailored proposal.

Plans
Compare features across tiers. Need something between Growth and Enterprise? Talk to us — we'll scope it.
Starter
Up to 75 employees
A$499/ month
Small businesses beginning their Shadow IT programme.
Subscribe
Recommended
Growth
76 – 500 employees
A$1,990/ month
IT and security teams running active governance.
Subscribe
Enterprise
500+ employees · regulated
From A$45,000/ year
Regulated and multi-entity organisations.
Talk to our team
Coverage
Google Workspace
Microsoft 365
Multi-tenant / multi-entity
Discovery & risk
Automated SaaS discovery
OAuth permission inventory
AI-tool visibility & governance
Composite risk scoring
Basic
Advanced
Advanced
Historical trend & 24-month replayRoadmap
Governance
Approve / restrict / block workflows
Framework tagging — E8, APP, CPS 234
CPS 234 alignment assessment support
Executive posture summaries
Evidence & integrations
Monthly posture reportRoadmap
Audit-ready evidence export
API access
SIEM / SOAR integrationRoadmap
Australian data residency (AU by default)
Service
Support
Business hours
Priority
Dedicated engineer
Uptime SLA
Available on Enterprise agreement
Onboarding
Starter
A$2,500 onboarding
White-glove
· No per-seat billing.· Cancel any time — full data export on request.· Annual billing available on Growth and Enterprise.· Pricing in AUD, exclusive of GST.· Items marked “Roadmap” are in development and not yet generally available.· Microsoft 365 discovery is read-only — Entra ID apps, service principals, and delegated OAuth grants.· Framework tagging supports governance readiness — it does not constitute compliance certification or legal advice.
Regulated sectors

Operating under APRA, IRAP, or residency obligations?

We work directly with financial services, healthcare, and government teams to scope deployments around APRA CPS 234 obligations, IRAP assessment support, Australian data residency, and SIEM forwarding.

Talk to the security team
We'll route your enquiry to a security engineer. Typical response within one business day.