Modules · Enterprise

Six modules.
One rating.

Each module runs continuously against a company’s public attack surface and feeds findings into a single 0–100 rating. Nothing to install, nothing to ask the vendor for, and every number traces back to a dated scan result.

Coverage

What each module observes

Module 01

Brand Protection →

Lookalike domains, typosquats, dark-web mentions and impersonation. Takedown included.

Module 02

Domain Security →

SPF, DKIM, DMARC, DNSSEC and certificate hygiene, checked continuously.

Module 03

Application Security →

Public applications, APIs, security headers and exposed environments.

Module 04

Network Security →

Passive port and service fingerprinting across your full IP range.

Module 05

Cloud Security →

AWS, Azure and GCP exposure found from the outside, without keys or roles.

Module 06

Compliance →

Every finding mapped automatically to twelve frameworks, with evidence exports.

How it fits together

Six modules, one score, and why the split matters

Each module answers a different question about the same organisation, from the same vantage point: what is observable from the public internet. Domain security asks whether mail can be forged. Network security asks what is reachable and what is running on it. Application security asks whether the web layer is maintained. Cloud security asks what is exposed and whether it is attributable. Brand protection asks who is impersonating you. Compliance asks which framework controls the findings break.

They are scored separately because they fail separately and they are owned separately. A messaging team fixes a DMARC policy; an infrastructure team closes an exposed management interface; a web team adds a security header. A single blended number tells none of them what to do, which is why a rating that cannot decompose is a board metric rather than an operational one.

The aggregate score exists for comparison and trend, is this vendor better or worse than that one, is our own posture improving across quarters. The module breakdown exists for action. Both are needed and they are not interchangeable.

Common properties

What every module shares

Deterministic scoring. The same evidence produces the same score, every time, and the model is versioned so a change in methodology is distinguishable from a change in posture. A rating that moves because we changed our mind is a rating nobody can trend.

Evidence on every finding. A finding that cannot be interrogated will not be acted on, because the first response to an uncomfortable number is to question the method. Findings carry the observation they were derived from, which makes a dispute factual, and a finding that turns out to be wrong or stale should go.

No access required. Every module works on companies who have agreed to nothing, which is what makes vendor assessment, tender scoring and acquisition screening possible. The single exception is deeper cloud posture, which uses read-only scoped access to an account you choose to connect.

Honest scope

What none of these modules can see

Everything here stops at the perimeter. Internal network segmentation, whether backups are tested and restorable, how privileged access is governed, incident response procedure, staff training, and how data is handled once inside an environment are not externally observable and never will be.

That is not a gap we intend to close, because closing it would require access, and needing access is precisely what makes questionnaires slow and vendor assessment negotiable. The value of outside-in assessment is that it scales to every company you care about without any of them agreeing to anything.

So the working model is triage. Rate everything continuously because it is cheap and needs nobody's cooperation, then spend scarce questionnaire and audit capacity where the ratings say something is wrong, or where the data at stake demands assurance the outside cannot provide.

At a glance

What each module covers, and what it does not

ModuleAnswersCannot see
Domain securityCan mail be spoofed as this domain?Internal mail routing and content filtering
Network securityWhat is reachable, running what version?Anything behind authentication; exploitation is never attempted
Application securityIs the web layer maintained and exposed correctly?Authorisation logic and business logic flaws
Cloud securityWhat cloud assets are exposed and attributable?IAM policy and encryption at rest, without connected access
Brand protectionWho is registering infrastructure to impersonate you?Impersonation with no infrastructure footprint
ComplianceWhich framework controls do these findings break?Governance, policy, training, access reviews

All six ship in every tier. Pricing scales with the number of rated companies, not with which modules you turn on.

FAQ

Common questions

Do we have to choose which modules to buy?

No. All six are included in every tier. Pricing scales with the number of companies you rate rather than with module selection, because a partial view of an attack surface is not a cheaper product: it is a misleading one.

Why score modules separately rather than giving one number?

Because they fail separately and they are owned by different teams. A messaging team fixes DMARC, an infrastructure team closes an exposed interface, a web team adds a header. A blended number tells none of them what to do. The aggregate is for comparison and trend; the breakdown is for action.

Does any module require access to our systems?

Only deeper cloud posture, and only if you choose to connect a read-only scoped account. Everything else observes what is published to the public internet, which is what makes rating vendors and acquisition targets possible at all.

Can we dispute a finding?

Yes. Every finding carries the evidence it was derived from, so a dispute is a factual conversation rather than an argument about methodology. If the evidence is wrong or stale, the finding goes.

Is the scoring model stable over time?

It is deterministic and versioned, so the same evidence produces the same score and a methodology change is distinguishable from a posture change. A score that moves because we changed our mind would make trending meaningless.

What do these modules deliberately not cover?

Anything requiring access: segmentation, backup testing, access governance, incident response, training and internal data handling. Those need an audit or a questionnaire, and no amount of external scanning substitutes for one.

Enterprise dashboard showing all six modules feeding one rating

All six modules, summarised against one company's rating

Rate your own company first

See what attackers and insurers see. Free for your own organisation.