Your external security posture,
continuously scored.
And every company you depend on.
GuardianGaze assesses everything an organisation exposes to the public internet: brand and domain abuse, email authentication, application and network exposure, dark-web and brand-mention intelligence, plus cloud posture when you connect an account. All of it resolves into one risk score that updates continuously. Run it on your own company, on a single vendor, or across an entire portfolio. Nothing to install, and no access to anyone's systems.
The first score, on your own company, is free. It’s also how most evaluations start.
Used by teams at




One number, six inputs, no scan schedule
Every company gets a risk score from 0 to 100, where lower is safer. Zero means nothing was found. Six factor scores are weighted and aggregated into a domain score; domain scores roll up into a company score; company scores roll up into a portfolio view, so a group with forty subsidiaries and a hundred vendors resolves to a single board-level picture.
Scores are recalculated as exposure changes rather than on a fixed schedule, and every point traces back to a dated observation you can open. Each company also carries a posture tier, so the number arrives with its own interpretation attached.
One thing worth saying plainly, because it catches people out: this runs the opposite way to letter-grade rating services. A company scoring 16 is in good shape. A company scoring 80 is not.
Brand Protection
Look-alike, typosquat and permutation domains, brand-impersonation exposure, brand-mention intelligence, and dark-web and breach exposure reported in aggregate.
Domain & Email Security
SPF, DKIM and DMARC, MX and mail provider, TLS/SSL and mail transport security, the records that decide whether anyone can send mail as you.
Application Security
Subdomain enumeration and liveness, security headers, external-script integrity (SRI), technology and version discovery, and CVE detection on the components identified.
Network Security
Exposed services, open ports and internet-facing service hygiene. Services and versions are identified and matched against known vulnerabilities. Nothing is exploited.
Cloud Security
Cloud posture checks across Azure, AWS and GCP. The one factor that is not purely external: it needs a cloud account connected with read-only scoped access.
Compliance
Findings mapped to ISO 27001, NIST, PCI DSS and GDPR controls as directional, indicative mappings, not an audit and not a certification.

One company's view: risk score, findings by severity, industry benchmark and all six modules
A number anyone in the meeting can read
Each company gets a 0–100 risk score and a posture tier, plus an industry benchmark that shows where it sits against peers in the same sector. The scoring method is published, so when someone asks “why is this moderate”, there’s a documented answer.


Specific findings, not vague warnings
Alerts name the actual problem: a DMARC policy left at p=none, a dev subdomain exposed to the internet, a dark-web mention of company credentials. Each one has a severity, an SLA timer and an owner, so findings get assigned and closed instead of sitting in an inbox.
- Severity levels: critical, high, medium, low
- SLA tracking per alert, with breach flags
- Findings mapped to MITRE ATT&CK techniques
Findings mapped to the frameworks you report against
Findings are mapped to controls in ISO 27001, NIST, PCI DSS and GDPR, so an external exposure arrives already attached to the control it bears on and you can see which fixes touch the most controls at once. Evidence exports per control.
These are indicative, directional mappings from externally observable evidence. They are not an audit, not a confirmed-gap assessment, and not a certification.


Reports written for the people who read them
Trend reports show score movement over time, per company and across the portfolio. They’re written for a board audience, and every number in them traces back to a dated scan result if anyone wants to check.
The layers above the assessment
The six factors are what gets measured. These are what turns the measurement into something a team can act on.
Third-party vendor risk
See who your vendors really are, and how much exposure they add. The providers a company depends on are discovered from its public footprint alone: mail providers, CDNs, hosting, cloud, DNS, certificate authorities, analytics, SaaS and JS-library hosts. Each is classified by category and criticality, scored, and tracked against the domains that rely on it. No questionnaires to chase.
Rates the vendor organisation. It does not analyse software packages or dependency versions.
MITRE ATT&CK coverage
Your external exposure in the language your SOC already speaks. Every finding maps to ATT&CK tactics and techniques, with a coverage view by tactic.
Mapping, not simulation. Nothing is emulated and no active attack is detected.
AI analysis
AI turns raw findings into an executive-ready narrative, what matters, why, and what to do next. Executive summaries, prioritised risk narratives, plain-language insight, and AI-assisted brand-mention intelligence.
AI-assisted and analyst-reviewable, never autonomous and never the final word.
Takedowns
From detection to takedown. Impersonating and phishing assets are identified, the evidence is packaged, and the request is tracked through to removal. Ties straight into Brand Protection.
Removal is driven, not guaranteed, the outcome rests with registrars and hosts.
Scores that update continuously, a portfolio view across everything you own or rely on, board-ready reports, and findings pushed straight into the tools you already run.
- Continuous scoring and re-scoring, with company and portfolio roll-up across many domains, subsidiaries or a vendor portfolio
- Alerting and ticketing through Slack, Jira, Microsoft Teams, ServiceNow, PagerDuty and common SIEMs, plus MISP export for threat-intel sharing
- Curated threat-intelligence and security-news context, including CISA KEV
- Executive and technical PDF reports, server-generated and board-ready
- Multi-tenant with role-based access, and sign-in secured by two-factor authentication over email OTP
Where teams use it
Your own external posture
Score yourself first. It's free, and it shows you exactly what the platform sees.
Vendor onboarding
Check a vendor's score before you sign, instead of sending them a 200-question spreadsheet.
Third-party risk
Keep a score on every supplier and get an alert when one drops.
Provider concentration
See which providers your suppliers share, and how much of the portfolio one outage would take with it.
Cyber insurance
Bring an evidence-backed score to renewal instead of a self-filled questionnaire.
Mergers and acquisitions
Score a target company before diligence starts.
RFP scoring
Attach a current security score to each bid so bids are comparable.
Board reporting
A trend report the board can read without a translator.
Situational awareness
When something big hits the news, check your whole portfolio for it in one view.
“Our vendor review used to be a quarterly spreadsheet. Now it’s a dashboard we check weekly. When a critical supplier’s score dropped, we called them about it before their own team had noticed.”
Common questions
Do the companies we score have to install anything or agree to it?
No. Scans only look at what's already public: DNS records, certificates, exposed services, published applications. Companies can be invited to see their own findings and fix them, but nothing depends on their cooperation.
How is this different from a penetration test?
A pentest goes deep on one target at one point in time. Enterprise stays wide and current across your whole portfolio. Many customers use the scores to decide where a pentest is worth commissioning.
What if a vendor says their score is wrong?
They can look at the finding behind it. If it's fixed or was inaccurate, the next scan picks that up and the score updates, typically within days.
Will you pass our own security review?
We go through them regularly. DPA, architecture documentation and our own external score are part of the standard procurement pack.
Start with your own company's rating
It’s free, takes about a day, and shows you exactly what the platform would show you about your vendors. Plans start at £1,200 per month.
Run WordPress sites too? The plugin scans them free →