FAQ

Frequently asked questions about the Platform Architecture Authority (PAA) platform.

General

How is PAA different from a one-off assessment?

A traditional assessment is point-in-time: scan, deliver a report, move on. PAA runs continuously — it re-checks your environment on a schedule, tracks how your posture changes between runs, automatically resolves findings once they are fixed, and keeps the evidence trail an auditor will ask for.

Does PAA change my environment?

No — not unless you ask it to. PAA connects with read-only, least-privilege access and is built for assessment, not deployment. It generates infrastructure-as-code (Bicep/Terraform) and remediation guidance for your team to apply, and the few write integrations — such as pushing findings into Microsoft Defender for Cloud — are strictly opt-in.

What if I disagree with a finding?

Findings are evidence and trade-offs, not mandates — the decision is yours. When you choose to accept a risk, you record it in the Control Exception Register: an approver-gated, time-limited waiver with a full audit trail, so the acceptance is governed rather than forgotten.

Can PAA help with NIS2 attestation?

Yes. PAA includes a self-attestation workflow for NIS2 and the Dutch NIS2 control set (Cbw), where the controls PAA can prove are auto-evidenced directly from your scans — so you only judge what genuinely needs human input. Every control carries an auditor-facing evidence trail (resource → check → control → framework, with confidence, source, and freshness), and a consistency check flags any answer that contradicts what your latest scan actually shows before you sign off. The result is a signed, framework-aware PDF you can hand to a regulator or auditor.

How is my data handled?

Carefully. PAA accesses your tenant through least-privilege, read-only service principals authenticated by a self-rotating certificate — no long-lived secrets to manage. Data is processed and stored in the EU. NDAs and a remediation / penetration-test summary are available to enterprise customers and auditors on request.

Getting started

How quickly can we start?

Minutes. Connect your Azure subscriptions and Microsoft 365 tenant — an onboarding script automates the service-principal and app-registration setup — then run your first scan from the assessments page.

What’s the commitment?

Pro is billed monthly, with roughly 20% off if you pay annually. A Day Pass is a one-off for a single assessment. The Fractional Architect plan asks for a three-month minimum, since dedicated advisory time takes a while to show its full value.

Is there more than one plan tier?

There is a single Pro plan — every Pro customer gets the full platform and all agents, with no feature gating. The other options are different shapes rather than tiers: a one-off Day Pass, an MSP plan for managing client tenants, and Fractional Architect for teams that want dedicated architect time alongside the platform.

What happens if key team members leave?

The platform is the continuity. Assessment history, tracked findings, exceptions, and the audit trail persist independently of who is on your team, so knowledge does not walk out the door.

Practical

What does PAA integrate with?

Your existing workflow. PAA pushes findings to Jira and ServiceNow, sends webhook events on assessment and finding activity, and exports branded PDF and PowerPoint reports. It is not prescriptive about your stack.

Is PAA always available?

Yes — it is a hosted platform that runs continuously, including scheduled scans between your sign-ins. Support is provided in European time zones (CET/CEST) and accommodates global customers.

Which platforms does PAA assess?

Azure, Microsoft 365, and Zero Trust, mapped across every supported compliance framework. PAA is focused on the Microsoft cloud — AWS and GCP are not on our roadmap. If multi-cloud coverage matters to you, reach out; we’d like to hear it.

Still have questions?

Contact us — we’re happy to discuss whether PAA fits your environment.