Open source · AGPL-3.0 licensed

199 security checks. Zero blind spots.

The all-seeing security audit for Google Workspace. Check your tenant against CIS, CISA SCuBA, Google, and other best-practice frameworks — in minutes.

gws-auditor

$ gws-auditor --config config.yaml

◆ Authenticating (service_account)...

✓ Authentication successful

◆ Collecting data from 11 APIs...

✓ Directory, Gmail, Drive, Calendar, Chat, Meet, Groups, DNS

◆ Running 199 security checks...

✓ CIS (84) · CISA (82) · Google (20) · Other (13)

Results:

  ✓ 142 passed

  ✗ 28 failed

  ⚠ 12 warnings

  ✎ 5 manual review

◆ Reports generated:

  reports/audit_20260220.html

  reports/audit_20260220.json

  reports/audit_20260220.csv

✓ Audit complete — 76% pass rate

Checks aligned with

CISA SCuBA
Other Best Practices

Security posture in minutes, not weeks

Argus automates what takes consultants weeks. Connect, scan, and get actionable remediation — all from your terminal.

4 Frameworks

CIS Benchmark, CISA SCuBA, Google's Security Checklist, and other best-practice guides — all in one unified audit.

Open Source

AGPL-3.0 licensed. Every check is transparent, auditable, and community-reviewed. No black boxes in your security tooling.

AI Analyst

Chat with your audit findings. Get remediation guidance in natural language. Supports OpenAI, Anthropic, and Bedrock.

199
Security Checks
4
Frameworks
12+
GWS Services
AGPL
License

How it works

From connection to report in under 10 minutes.

1

Authenticate

Service account with domain-wide delegation or OAuth 2.0 user consent. Works with any GWS edition.

2

Collect

Automated data collection from Admin SDK, Cloud Identity, Gmail, Drive, Calendar, Groups, and DNS APIs.

3

Evaluate

199 checks run against collected data. Each produces PASS, FAIL, WARN, or MANUAL with remediation steps.

4

Report

HTML dashboard, JSON for automation, CSV for spreadsheets. AI analyst for interactive exploration.

Every service. Every setting.

Comprehensive coverage across all Google Workspace services your organization uses.

Gmail

32 checks

DMARC, SPF, DKIM, spam, phishing, DLP, forwarding, sync

Drive & Docs

21 checks

Sharing, external access, DLP, desktop sync, add-ons

Security

30+ checks

MFA, SSO, session management, recovery, app access, DLP

Calendar

8 checks

External sharing, interop, appointments, visibility

Chat

8 checks

History, external access, DLP, content reporting

Meet

7 checks

Join controls, recording, host management, external warnings

Groups

7 checks

External access, creation restrictions, visibility controls

Directory

4 checks

Super admins, user accounts, MFA enrollment, org units

Classroom

6 checks

Membership, API access, roster import, class creation

Why Argus?

More comprehensive than ScubaGoggles. 100x cheaper than consultants. Fully automated.

Argus ScubaGoggles Manual Audit Consultant
Frameworks 4 1 (CISA) Varies Varies
Security Checks 199 ~137 20-50 50-100
Cost Free / €15/mo Free Staff time $10K-50K
Automation Full Partial None None
AI Analysis Maybe
Remediation In-report Reference Manual PDF

Simple pricing

Open source forever. Cloud-hosted when you need it.

Open Source

$0 forever

Everything you need to audit your Google Workspace tenant.

  • All 199 security checks
  • 4 compliance frameworks
  • HTML, JSON, CSV reports
  • CLI + Docker + CI/CD
View on GitHub
Most Popular

Argus Cloud

€15 / month

Automated scans, trend tracking, and team collaboration.

  • Everything in Open Source
  • Automated daily/weekly scans
  • 12-month compliance trends
  • Slack/email regression alerts
  • AI Analyst included
Start Free Trial

Ready to see your security posture?

Run your first audit in under 10 minutes. Free, open source, no strings attached.