As someone who previously held a CISO position I evaluate such tools by two main factors:
1. Simplicity
2. Value for money
I think that Bleach is a wonderful tool and ranks high in both. It is relatively easy to add assets, the insights are useful and easy to understand.
Why only 4 stars then?
1. I couldn’t add my Azure subscription. Kept getting invalid id
2. I got a few alerts that aren’t valid for the asset type (in other words, they only apply to users, not shared mailboxes, but they were still listed as a major issue on all shared mailboxes).
3. Most issues didn’t include a link or a reference to the solution, sending me to Google “how to fix”. I’m not expecting automatic fix for everything, but at least a link to the relevant article.
4. Unfortunately, I couldn’t get any “asset” scanning to work.
Having said that, this deal value-for-money is insane. For example if you are to fix just one issue in about 20 minutes from signing up. That alone is enough to justify the price.
Great job by Bleach team and I hope to see many improvements in the near future.