A continuous outside-in rating across nine security surfaces, scored into one defensible A-F grade and a shareable trust page - the attacker’s-eye view that sits alongside your Supplier Assurance questionnaire, with no agent and no supplier effort.
security surfaces, scored from the outside for every supplier - with no agent and no supplier effort. It is the other half of supplier assurance: what an attacker can already see, sitting alongside your questionnaire and turned into one defensible grade, refreshed continuously.
A questionnaire is answered from the inside on a single day, so it never shows the live external attack surface an adversary is already probing - and new exposure or a breach can appear in the months between assessments. The two columns below set that blind spot against a continuous outside-in rating fused into the same supplier signal.
Every grade is built from keyless, passive checks against authoritative sources - nothing intrusive, and nothing the supplier has to action. Nine separate surfaces are scored and severity-weighted into a single letter grade.
Internet-facing services, open ports and forgotten infrastructure (Shodan InternetDB).
Certificate and cipher strength (SSL Labs) plus headers, CSP and cookies (Mozilla Observatory).
DNSSEC, resolver hygiene and SPF, DKIM and DMARC alignment.
Dark-web infostealer credentials tied to the supplier (Hudson Rock).
Spamhaus, Barracuda and abuse.ch blocklists, plus ransomware-leak and botnet mentions.
Open CVEs and time-to-patch trend - how quickly the supplier closes known holes.
The rating is deliberately simple to act on: nine security surfaces, scored with zero agents and zero supplier effort, into one shareable A-F letter grade that is refreshed continuously. The figures below are what that outside-in view comes down to in practice.
The rating starts from nothing more than a supplier’s domain and ends with a grade you can defend to an auditor. The six steps below discover the supplier’s assets, scan them with keyless passive adapters, score and severity-weight nine surfaces, then fuse the result with your questionnaire evidence into one signal and publish it to a shareable trust page.
The outside-in surfaces line up with the control areas a UK public-sector or CNI organisation is already held against, so the grade is evidence rather than a vanity score. The mappings below tie the rating to NCSC CAF v4.0, ISO 27001:2022, Cyber Essentials, NIST CSF 2.0, NCSC supply-chain principles and MITRE ATT&CK initial-access techniques.
The rating lands as views you can work from, not a raw feed. A portfolio rating that ranks every supplier and surfaces where weak grades concentrate, a per-supplier scorecard with the findings behind each of the nine surfaces and the trend over time, and a public tokenised trust page a supplier can share to evidence its posture.
Every supplier graded and ranked, with concentration of weak grades surfaced.
The nine surfaces, the findings behind each and the trend over time.
A public, tokenised page a supplier can share to evidence its posture.
A 30-minute walkthrough - we will rate your top suppliers live, no slides.