AccessDecom Run a free access audit
The average ex-contractor still has live access 3 months after leaving

Offboard in one click.
Prove the access is actually gone.

When someone leaves, AccessDecom revokes their access across every SaaS and cloud tool — then re-checks each grant to confirm it's really closed and hands you an audit-ready certificate. Because a checklist that says "done" isn't proof.

Flat-rate from $49/mo · EU-hosted · No per-seat pricing · No SSO required

Your offboarding checklist is a liability

The average SMB now runs 40–60 SaaS tools. The shared Google Doc that worked in 2019 misses something every single time — and the consequences are a data breach, IP theft, or a failed audit.

#9

Most painful business problem across 148K+ analysed complaints (BigIdeasDB). High impact, severe consequences.

€10M

GDPR Art. 32 max fine for inadequate access controls (or 2% of global turnover). SOC 2 & ISO 27001 require documented revocation.

3 mo

How long a real contractor kept production-DB access after leaving — found only because they logged in from another country. — r/sysadmin

"Offboarding compliance is one of the most underestimated security and operational nightmares many companies face today." — security practitioner, LinkedIn

Discover → Revoke → Verify → Certify

Connect your stack once via OAuth. From then on, offboarding is one click — and every click ends in proof.

1 · Discover

Map the person to every account they hold — Google Workspace, Slack, GitHub, AWS IAM, Jira, Notion and more — by work email.

2 · Revoke

Suspend accounts, remove org membership, kill IAM keys, revoke tokens — across the whole stack in one orchestrated pass.

3 · Verify ★

We re-check every grant to confirm it's actually gone. The revoke that returned 200 but left the seat live gets caught — not ticked off.

4 · Certify

Get a timestamped, tamper-evident certificate mapped to SOC 2, ISO 27001 and GDPR Art. 32 — the document an auditor accepts.

The difference: we catch the revoke that lied

A SCIM "deactivate" returns success but the Slack seat is still live. A checklist ticks the box. AccessDecom re-checks, flags it red, and refuses to call the offboarding clean.

ACCESS REVOCATION CERTIFICATE
============================================================
Employee : Dana Ortiz (contractor) <dana@acme.example>
Status   : INCOMPLETE  (3/4 grants verified closed, 1 outstanding)
------------------------------------------------------------
 GitHub Org         prod-write   dortiz              revoked
 Google Workspace   admin        billing-group       revoked
 Google Workspace   member       dana@acme.example   revoked
✗ Slack (SCIM)       member       U123DANA            active
------------------------------------------------------------
OUTSTANDING — NOT SAFE TO CLOSE:
  ! Slack · member: revoke reported success but grant still ACTIVE on re-check
------------------------------------------------------------
Controls evidenced: SOC 2 CC6.2/6.3 · ISO 27001 A.5.11/A.8 · GDPR Art.32
Audit chain head (integrity anchor): 62d8975f8d4c7dc2…

Every step is sealed into an append-only hash chain: edit, delete, or reorder any record and verification breaks (content tampered at seq 2). Your evidence can't be quietly backdated — which is exactly what an auditor needs.

Built for the audit, hosted in the EU

Certificates map directly to the controls your auditor checks. Data stays in the EU (Hetzner, Germany). The immutable evidence copy lives in WORM storage with object lock — it cannot be deleted, even by us.

  • SOC 2 CC6.2 / CC6.3 — access revoked on termination
  • ISO 27001 A.5.11 / A.8 — removal of access rights
  • GDPR Art. 32 — security of processing
  • Tamper-evident hash chain + WORM evidence retention
  • Dry-run by default · explicit confirm per offboarding

30-day monitor

Offboarding isn't a moment, it's a guarantee. For 30 days after, AccessDecom keeps re-checking revoked grants and alerts you if access reappears — or if the ex-employee's account logs in.

⚠ Alert · GitHub access for dortiz reappeared 6 days after offboarding (re-added as outside collaborator). Revoked again automatically.

Flat-rate. No per-seat tax on doing the right thing.

One prevented incident pays for years. Unlimited offboardings on every plan.

Starter
$49/mo
  • Up to 25 employees
  • 10 integrations
  • Manual offboarding + certificates
Start free audit
Pro · most popular
$99/mo
  • Up to 100 employees
  • 25 integrations
  • One-click offboarding
  • Audit-ready certificates (PDF)
Start free audit
Business
$249/mo
  • Up to 250 employees
  • All integrations
  • 30-day monitoring
  • SSO + priority support
Talk to us

MSPs: white-label AccessDecom for your clients. Partner with us →

Find out who still has access — in 2 minutes

Run a free, read-only audit of your domain. We'll show you which ex-employees and contractors still have live access to your public-facing services. No card, no commitment.

EU-hosted · GDPR-native · We never store more than each check needs.