Six modules.
One rating.
Each module runs continuously against a company’s public attack surface and feeds findings into a single 0–100 rating. Nothing to install, nothing to ask the vendor for, and every number traces back to a dated scan result.
What each module observes
Brand Protection →
Lookalike domains, typosquats, dark-web mentions and impersonation. Takedown included.
Application Security →
Public applications, APIs, security headers and exposed environments.
Compliance →
Every finding mapped automatically to twelve frameworks, with evidence exports.
Six modules, one score, and why the split matters
Each module answers a different question about the same organisation, from the same vantage point: what is observable from the public internet. Domain security asks whether mail can be forged. Network security asks what is reachable and what is running on it. Application security asks whether the web layer is maintained. Cloud security asks what is exposed and whether it is attributable. Brand protection asks who is impersonating you. Compliance asks which framework controls the findings break.
They are scored separately because they fail separately and they are owned separately. A messaging team fixes a DMARC policy; an infrastructure team closes an exposed management interface; a web team adds a security header. A single blended number tells none of them what to do, which is why a rating that cannot decompose is a board metric rather than an operational one.
The aggregate score exists for comparison and trend, is this vendor better or worse than that one, is our own posture improving across quarters. The module breakdown exists for action. Both are needed and they are not interchangeable.
What every module shares
Deterministic scoring. The same evidence produces the same score, every time, and the model is versioned so a change in methodology is distinguishable from a change in posture. A rating that moves because we changed our mind is a rating nobody can trend.
Evidence on every finding. A finding that cannot be interrogated will not be acted on, because the first response to an uncomfortable number is to question the method. Findings carry the observation they were derived from, which makes a dispute factual, and a finding that turns out to be wrong or stale should go.
No access required. Every module works on companies who have agreed to nothing, which is what makes vendor assessment, tender scoring and acquisition screening possible. The single exception is deeper cloud posture, which uses read-only scoped access to an account you choose to connect.
What none of these modules can see
Everything here stops at the perimeter. Internal network segmentation, whether backups are tested and restorable, how privileged access is governed, incident response procedure, staff training, and how data is handled once inside an environment are not externally observable and never will be.
That is not a gap we intend to close, because closing it would require access, and needing access is precisely what makes questionnaires slow and vendor assessment negotiable. The value of outside-in assessment is that it scales to every company you care about without any of them agreeing to anything.
So the working model is triage. Rate everything continuously because it is cheap and needs nobody's cooperation, then spend scarce questionnaire and audit capacity where the ratings say something is wrong, or where the data at stake demands assurance the outside cannot provide.
What each module covers, and what it does not
| Module | Answers | Cannot see |
|---|---|---|
| Domain security | Can mail be spoofed as this domain? | Internal mail routing and content filtering |
| Network security | What is reachable, running what version? | Anything behind authentication; exploitation is never attempted |
| Application security | Is the web layer maintained and exposed correctly? | Authorisation logic and business logic flaws |
| Cloud security | What cloud assets are exposed and attributable? | IAM policy and encryption at rest, without connected access |
| Brand protection | Who is registering infrastructure to impersonate you? | Impersonation with no infrastructure footprint |
| Compliance | Which framework controls do these findings break? | Governance, policy, training, access reviews |
All six ship in every tier. Pricing scales with the number of rated companies, not with which modules you turn on.
Common questions
Do we have to choose which modules to buy?
No. All six are included in every tier. Pricing scales with the number of companies you rate rather than with module selection, because a partial view of an attack surface is not a cheaper product: it is a misleading one.
Why score modules separately rather than giving one number?
Because they fail separately and they are owned by different teams. A messaging team fixes DMARC, an infrastructure team closes an exposed interface, a web team adds a header. A blended number tells none of them what to do. The aggregate is for comparison and trend; the breakdown is for action.
Does any module require access to our systems?
Only deeper cloud posture, and only if you choose to connect a read-only scoped account. Everything else observes what is published to the public internet, which is what makes rating vendors and acquisition targets possible at all.
Can we dispute a finding?
Yes. Every finding carries the evidence it was derived from, so a dispute is a factual conversation rather than an argument about methodology. If the evidence is wrong or stale, the finding goes.
Is the scoring model stable over time?
It is deterministic and versioned, so the same evidence produces the same score and a methodology change is distinguishable from a posture change. A score that moves because we changed our mind would make trending meaningless.
What do these modules deliberately not cover?
Anything requiring access: segmentation, backup testing, access governance, incident response, training and internal data handling. Those need an audit or a questionnaire, and no amount of external scanning substitutes for one.

All six modules, summarised against one company's rating
Rate your own company first
See what attackers and insurers see. Free for your own organisation.