LOADING…
Platform  /  Datasheets  /  Supplier Security Rating
Outside-in attack surface

See every supplierthe way an attacker does.

A continuous outside-in rating across nine security surfaces, scored into one defensible A-F grade and a shareable trust page - the attacker’s-eye view that sits alongside your Supplier Assurance questionnaire, with no agent and no supplier effort.

All datasheets
9 surfaces scoredA–F letter grade0 agents to deploy
9

security surfaces, scored from the outside for every supplier - with no agent and no supplier effort. It is the other half of supplier assurance: what an attacker can already see, sitting alongside your questionnaire and turned into one defensible grade, refreshed continuously.

The challenge

Your assessment cannot see the attacker’s view.

A questionnaire is answered from the inside on a single day, so it never shows the live external attack surface an adversary is already probing - and new exposure or a breach can appear in the months between assessments. The two columns below set that blind spot against a continuous outside-in rating fused into the same supplier signal.

The gap
An assessment is answered from the inside, at a point in time
No view of a supplier’s live external attack surface
New exposure or a breach appears between assessments
Premium ratings tools cost a fortune and sit in a silo
With E2ERisk
A continuous outside-in view of what an attacker sees
Nine surfaces scored into one grade, beside the assessment
Built in and fused with your questionnaire - one signal
The grade moves the day exposure changes
What it scans

Nine surfaces, one grade.

Every grade is built from keyless, passive checks against authoritative sources - nothing intrusive, and nothing the supplier has to action. Nine separate surfaces are scored and severity-weighted into a single letter grade.

Attack surface & exposure

Internet-facing services, open ports and forgotten infrastructure (Shodan InternetDB).

TLS & application security

Certificate and cipher strength (SSL Labs) plus headers, CSP and cookies (Mozilla Observatory).

DNS & email security

DNSSEC, resolver hygiene and SPF, DKIM and DMARC alignment.

Breach & infostealer exposure

Dark-web infostealer credentials tied to the supplier (Hudson Rock).

Reputation & compromise

Spamhaus, Barracuda and abuse.ch blocklists, plus ransomware-leak and botnet mentions.

Patching cadence

Open CVEs and time-to-patch trend - how quickly the supplier closes known holes.

At a glance

The numbers that matter.

The rating is deliberately simple to act on: nine security surfaces, scored with zero agents and zero supplier effort, into one shareable A-F letter grade that is refreshed continuously. The figures below are what that outside-in view comes down to in practice.

9
surfaces in the rating
0
agents or supplier effort
A–F
shareable letter grade
24/7
continuously refreshed
How it works

From a domain to a defensible grade.

The rating starts from nothing more than a supplier’s domain and ends with a grade you can defend to an auditor. The six steps below discover the supplier’s assets, scan them with keyless passive adapters, score and severity-weight nine surfaces, then fuse the result with your questionnaire evidence into one signal and publish it to a shareable trust page.

01
Discover
Domains & assets
Mapped per supplier
02
Scan
Keyless adapters
Passive, non-intrusive
03
Score
Nine surfaces
Severity-weighted
04
Grade
One A-F rating
Per surface + overall
05
Fuse
With SAQ evidence
One risk signal
06
Publish
Shareable trust page
Refreshed on change
Where it fits

A UK-public-sector answer to the ratings tools.

The outside-in surfaces line up with the control areas a UK public-sector or CNI organisation is already held against, so the grade is evidence rather than a vanity score. The mappings below tie the rating to NCSC CAF v4.0, ISO 27001:2022, Cyber Essentials, NIST CSF 2.0, NCSC supply-chain principles and MITRE ATT&CK initial-access techniques.

NCSC CAF v4.0B4 secure configuration and C1 security monitoring
ISO 27001:2022A.8 technological controls and vulnerability management
Cyber EssentialsBoundary firewalls, secure configuration and patching
NIST CSF 2.0Identify, Protect and Detect functions
NCSC Supply ChainVendor-risk principles for HMG and CNI suppliers
MITRE ATT&CKInitial-access exposure mapped to technique
What you get

Intelligence you can act on.

The rating lands as views you can work from, not a raw feed. A portfolio rating that ranks every supplier and surfaces where weak grades concentrate, a per-supplier scorecard with the findings behind each of the nine surfaces and the trend over time, and a public tokenised trust page a supplier can share to evidence its posture.

Portfolio rating view

Every supplier graded and ranked, with concentration of weak grades surfaced.

Per-supplier scorecard

The nine surfaces, the findings behind each and the trend over time.

Shareable trust page

A public, tokenised page a supplier can share to evidence its posture.

Next step

See your suppliers’ real grade.

A 30-minute walkthrough - we will rate your top suppliers live, no slides.

All datasheets →