What is simiriki, exactly?
simiriki is an operational-infrastructure platform for Microsoft 365 security, focused on Mexican mid-market companies. It evaluates insecure configuration with 201 detection rules and maintains a catalog of 188 playbooks that support remediation routes. It executes an approved change only when the exact rule-to-playbook binding is certified; guided and advisory routes remain clearly labeled as such. It reads Defender, Sentinel, Purview and Power Platform configuration where the consented APIs allow, with regulatory mapping to LFPDPPP / CNBV / NOM-151. It does not resell or implement Sentinel or Defender XDR as a managed SIEM/MSSP.
What does the free /scan do?
The free scan connects your Microsoft 365 tenant via read-only OAuth, runs the 155 Microsoft Graph rules of the 201-rule library and calculates an sIPO score (0–100) with grade A+ to F; the on-screen preview usually appears within a couple of minutes (larger tenants can take longer because Microsoft Graph is rate-limited) and the 3-page PDF Posture Brief is delivered in under an hour. No credit card required. The OAuth consent is strictly read-only — no rule writes to your tenant. The 46 Azure Resource Manager rules are added when you connect with admin consent and Reader role (Operación).
What data does the Auditoría actually read?
Only security configuration, never content. Via Microsoft Graph + Azure Resource Manager (read-only consent) we read: identity and conditional-access policies, MFA state and methods, privileged roles and assignments, application (OAuth) consents, Exchange/mail configuration (DKIM/DMARC/forwarding rules — not the mail itself), Purview DLP policies and labels, device/Intune configuration, SharePoint/OneDrive external sharing, and Azure resource configuration (NSGs, storage, encryption, Defender for Cloud). We never read the body of emails, files, chats, or calendars. You can revoke access anytime from your Microsoft 365 portal.
Where is my data stored?
Production runs on one Hetzner VPS in Ashburn, Virginia, published through Cloudflare Tunnel. PostgreSQL and Redis bind to loopback only. Sensitive tokens use application-layer AES-256-GCM; verified PostgreSQL backups are created hourly and the encrypted offsite channel is explicitly monitored. There is no multi-region failover. Portable data is provided in standard formats where applicable.
Do I need Microsoft 365 E5 licenses?
Not for the Escaneo or free Auditoría. Available checks and remediation paths depend on the licenses and APIs present in your tenant; for example, Conditional Access requires Microsoft Entra ID P1. Operación does not require or resell E5, Defender XDR, or Microsoft Sentinel. Controls that your licensing cannot verify are shown as pending or skipped rather than treated as passed.
Why are there 188 playbooks for 201 rules — and do they run on their own?
There are 188 rather than 201 because several rules share one remediation route. The catalog is mapped by capability and every change requires approval. Today, 21 playbooks have a real automatic Microsoft Graph executor; the remainder are guided, assisted, or report-only according to API capability and risk. A remediation route is not the same as automatic execution, and pending or unverified controls are shown as such.