SecureGovMicrosoft 365 governance, in plain English

Product & Security Disclaimer

Last updated: August 26, 2026 · SecureGov.ca
SecureGov is a tool to help you understand your Microsoft 365 security posture. It is a helpful starting point — not a guarantee, a certification, or a substitute for professional judgment. Please read this before relying on anything the Service shows.

1. Informational and indicative only

Every score, verdict, “on track / at risk” signal, dollar figure, readiness indicator and recommendation the Service produces is indicative and for information only. It is a simplified interpretation of data made available by Microsoft at a point in time. It is not a definitive statement about the security, configuration, or compliance of your environment.

2. Not a guarantee of security

A favourable score or an “on track” result does not mean your environment is secure, cannot be breached, or is free of vulnerabilities. No tool can guarantee security. You remain responsible for securing your own environment.

3. Not a certification or audit

Mappings to frameworks such as CIS, NIST, or ISO/IEC 27001 are indicative cross-references to help you focus effort. They are not a formal audit, assessment, attestation, or certification against any framework, and confer no certified status. A formal audit or certification can only be issued by a qualified assessor.

4. Not professional advice

The Service does not provide legal, regulatory, insurance, accounting, or professional cybersecurity advice, and no professional relationship is created by using it. Before making decisions with legal, financial, insurance, or security consequences, consult a qualified professional.

5. Cyber-insurance indicators

Any “insurance readiness” or “would pass” indicator is an estimate based on common controls insurers ask about. It is not a representation, warranty, or communication to any insurer or broker, is not underwriting, and must not be relied upon to obtain, renew, or support a claim under any policy. Insurers and brokers make their own independent determinations, and coverage decisions are theirs alone.

6. Accuracy and completeness

Findings depend on the data Microsoft exposes, the read-only permissions you grant, and the moment the data is read. Information may be incomplete, delayed, out of date, or affected by your configuration or Microsoft changes. Some risks are not visible to a read-only view and are outside the Service’s scope. We do not warrant that any finding is accurate, complete, or current, and you should independently verify anything before acting on it.

7. Read-only — the Service does not fix anything

The Service only reads and displays; it does not change your environment or remediate any issue. Acting on a finding — and confirming it was done correctly — is your responsibility, or that of your IT provider.

8. Your responsibility

You are solely responsible for your security decisions, for verifying findings, for maintaining backups and safeguards, and for compliance with laws and obligations applicable to you. Reliance on the Service is at your own risk.

9. Limitation of liability

Your use of the Service is subject to the limitation of liability and “no warranty” provisions of our Terms of Service, which are incorporated here by reference — including the Québec carve-out for bodily/moral injury and intentional or gross fault.