A continuous outside-in rating across nine security surfaces, scored into one defensible A-F grade and a shareable trust page - the attacker’s-eye view that sits alongside your Supplier Assurance questionnaire, with no agent and no supplier effort.
security surfaces, scored from the outside for every supplier - with no agent and no supplier effort. It is the other half of supplier assurance: what an attacker can already see, sitting alongside your questionnaire and turned into one defensible grade, refreshed continuously.
Keyless, passive checks against authoritative sources - nothing intrusive, nothing the supplier has to action.
Internet-facing services, open ports and forgotten infrastructure (Shodan InternetDB).
Certificate and cipher strength (SSL Labs) plus headers, CSP and cookies (Mozilla Observatory).
DNSSEC, resolver hygiene and SPF, DKIM and DMARC alignment.
Dark-web infostealer credentials tied to the supplier (Hudson Rock).
Spamhaus, Barracuda and abuse.ch blocklists, plus ransomware-leak and botnet mentions.
Open CVEs and time-to-patch trend - how quickly the supplier closes known holes.
Every supplier graded and ranked, with concentration of weak grades surfaced.
The nine surfaces, the findings behind each and the trend over time.
A public, tokenised page a supplier can share to evidence its posture.
A 30-minute walkthrough - we will rate your top suppliers live, no slides.