GuardianGaze EnterpriseAgentless, nothing to install

Your external security posture,
continuously scored.
And every company you depend on.

GuardianGaze assesses everything an organisation exposes to the public internet: brand and domain abuse, email authentication, application and network exposure, dark-web and brand-mention intelligence, plus cloud posture when you connect an account. All of it resolves into one risk score that updates continuously. Run it on your own company, on a single vendor, or across an entire portfolio. Nothing to install, and no access to anyone's systems.

The first score, on your own company, is free. It’s also how most evaluations start.

Used by teams at

BykeaApTaskHolisticoAmerican Healthcare Academy
0–100one risk score per company, where lower is safer, benchmarked against its industry
6scored factors: brand, domain and email, application, network, cloud, compliance: with findings mapped to ISO 27001, NIST, PCI DSS and GDPR
0installs or questionnaires needed from the companies you score
How the score works

One number, six inputs, no scan schedule

Every company gets a risk score from 0 to 100, where lower is safer. Zero means nothing was found. Six factor scores are weighted and aggregated into a domain score; domain scores roll up into a company score; company scores roll up into a portfolio view, so a group with forty subsidiaries and a hundred vendors resolves to a single board-level picture.

Scores are recalculated as exposure changes rather than on a fixed schedule, and every point traces back to a dated observation you can open. Each company also carries a posture tier, so the number arrives with its own interpretation attached.

One thing worth saying plainly, because it catches people out: this runs the opposite way to letter-grade rating services. A company scoring 16 is in good shape. A company scoring 80 is not.

Growth and up

Brand Protection

Look-alike, typosquat and permutation domains, brand-impersonation exposure, brand-mention intelligence, and dark-web and breach exposure reported in aggregate.

All plans

Domain & Email Security

SPF, DKIM and DMARC, MX and mail provider, TLS/SSL and mail transport security, the records that decide whether anyone can send mail as you.

All plans

Application Security

Subdomain enumeration and liveness, security headers, external-script integrity (SRI), technology and version discovery, and CVE detection on the components identified.

All plans

Network Security

Exposed services, open ports and internet-facing service hygiene. Services and versions are identified and matched against known vulnerabilities. Nothing is exploited.

Growth and up

Cloud Security

Cloud posture checks across Azure, AWS and GCP. The one factor that is not purely external: it needs a cloud account connected with read-only scoped access.

All plans

Compliance

Findings mapped to ISO 27001, NIST, PCI DSS and GDPR controls as directional, indicative mappings, not an audit and not a certification.

Enterprise dashboard: company risk score, threat distribution, industry benchmark, portfolio summary

One company's view: risk score, findings by severity, industry benchmark and all six modules

Scoring

A number anyone in the meeting can read

Each company gets a 0–100 risk score and a posture tier, plus an industry benchmark that shows where it sits against peers in the same sector. The scoring method is published, so when someone asks “why is this moderate”, there’s a documented answer.

Healthy0–19
Low20–39
Moderate40–59
High60–79
Critical80–100
Portfolio of company scores over time
Alerts list: dark-web exposure, DMARC policy p=none, missing TLS-RPT, exposed dev subdomains, each with severity, SLA and owner
Alerts

Specific findings, not vague warnings

Alerts name the actual problem: a DMARC policy left at p=none, a dev subdomain exposed to the internet, a dark-web mention of company credentials. Each one has a severity, an SLA timer and an owner, so findings get assigned and closed instead of sitting in an inbox.

  • Severity levels: critical, high, medium, low
  • SLA tracking per alert, with breach flags
  • Findings mapped to MITRE ATT&CK techniques
Compliance

Findings mapped to the frameworks you report against

Findings are mapped to controls in ISO 27001, NIST, PCI DSS and GDPR, so an external exposure arrives already attached to the control it bears on and you can see which fixes touch the most controls at once. Evidence exports per control.

These are indicative, directional mappings from externally observable evidence. They are not an audit, not a confirmed-gap assessment, and not a certification.

Compliance view: coverage heatmap across frameworks, remediation priorities, per-module mapped control counts
Security trend report for leadership
Reporting

Reports written for the people who read them

Trend reports show score movement over time, per company and across the portfolio. They’re written for a board audience, and every number in them traces back to a dated scan result if anyone wants to check.

Built on top

The layers above the assessment

The six factors are what gets measured. These are what turns the measurement into something a team can act on.

Growth and up

Third-party vendor risk

See who your vendors really are, and how much exposure they add. The providers a company depends on are discovered from its public footprint alone: mail providers, CDNs, hosting, cloud, DNS, certificate authorities, analytics, SaaS and JS-library hosts. Each is classified by category and criticality, scored, and tracked against the domains that rely on it. No questionnaires to chase.

Rates the vendor organisation. It does not analyse software packages or dependency versions.

Growth and up

MITRE ATT&CK coverage

Your external exposure in the language your SOC already speaks. Every finding maps to ATT&CK tactics and techniques, with a coverage view by tactic.

Mapping, not simulation. Nothing is emulated and no active attack is detected.

AI analysis

AI turns raw findings into an executive-ready narrative, what matters, why, and what to do next. Executive summaries, prioritised risk narratives, plain-language insight, and AI-assisted brand-mention intelligence.

AI-assisted and analyst-reviewable, never autonomous and never the final word.

Growth and up

Takedowns

From detection to takedown. Impersonating and phishing assets are identified, the evidence is packaged, and the request is tracked through to removal. Ties straight into Brand Protection.

Removal is driven, not guaranteed, the outcome rests with registrars and hosts.

Scores that update continuously, a portfolio view across everything you own or rely on, board-ready reports, and findings pushed straight into the tools you already run.

  • Continuous scoring and re-scoring, with company and portfolio roll-up across many domains, subsidiaries or a vendor portfolio
  • Alerting and ticketing through Slack, Jira, Microsoft Teams, ServiceNow, PagerDuty and common SIEMs, plus MISP export for threat-intel sharing
  • Curated threat-intelligence and security-news context, including CISA KEV
  • Executive and technical PDF reports, server-generated and board-ready
  • Multi-tenant with role-based access, and sign-in secured by two-factor authentication over email OTP
Use cases

Where teams use it

Internal

Your own external posture

Score yourself first. It's free, and it shows you exactly what the platform sees.

Procurement

Vendor onboarding

Check a vendor's score before you sign, instead of sending them a 200-question spreadsheet.

Risk

Third-party risk

Keep a score on every supplier and get an alert when one drops.

Risk

Provider concentration

See which providers your suppliers share, and how much of the portfolio one outage would take with it.

Insurance

Cyber insurance

Bring an evidence-backed score to renewal instead of a self-filled questionnaire.

Corp dev

Mergers and acquisitions

Score a target company before diligence starts.

Procurement

RFP scoring

Attach a current security score to each bid so bids are comparable.

Leadership

Board reporting

A trend report the board can read without a translator.

Ops

Situational awareness

When something big hits the news, check your whole portfolio for it in one view.

“Our vendor review used to be a quarterly spreadsheet. Now it’s a dashboard we check weekly. When a critical supplier’s score dropped, we called them about it before their own team had noticed.”
CISO · Mid-market financial services group
FAQ

Common questions

Do the companies we score have to install anything or agree to it?

No. Scans only look at what's already public: DNS records, certificates, exposed services, published applications. Companies can be invited to see their own findings and fix them, but nothing depends on their cooperation.

How is this different from a penetration test?

A pentest goes deep on one target at one point in time. Enterprise stays wide and current across your whole portfolio. Many customers use the scores to decide where a pentest is worth commissioning.

What if a vendor says their score is wrong?

They can look at the finding behind it. If it's fixed or was inaccurate, the next scan picks that up and the score updates, typically within days.

Will you pass our own security review?

We go through them regularly. DPA, architecture documentation and our own external score are part of the standard procurement pack.

Start with your own company's rating

It’s free, takes about a day, and shows you exactly what the platform would show you about your vendors. Plans start at £1,200 per month.

Run WordPress sites too? The plugin scans them free →