One platform.
Six modules. One rating.
Every module runs continuously against a company's public attack surface and feeds findings into a single 0-100 rating. Nothing to install, nothing to ask the vendor for, and every number traces back to a dated scan result.
Self-serve on your own domain. No scoping call, no contract to see the first rating.
Used by teams at





One company's view: risk score, findings by severity, industry benchmark and all six modules
A number anyone in the meeting can read
Each company gets a 0–100 risk score and a posture tier, plus an industry benchmark that shows where it sits against peers in the same sector. The scoring method is published, so when someone asks “why is this moderate”, there’s a documented answer.


Specific findings, not vague warnings
Alerts name the actual problem: a DMARC policy left at p=none, a dev subdomain exposed to the internet, a dark-web mention of company credentials. Each one has a severity, an SLA timer and an owner, so findings get assigned and closed instead of sitting in an inbox.
- Severity levels: critical, high, medium, low
- SLA tracking per alert, with breach flags
- Findings mapped to MITRE ATT&CK techniques
Findings mapped to the frameworks you report against
Findings are mapped to controls in ISO 27001, NIST, PCI DSS and GDPR, so an external exposure arrives already attached to the control it bears on and you can see which fixes touch the most controls at once. Evidence exports per control.
These are indicative, directional mappings from externally observable evidence. They are not an audit, not a confirmed-gap assessment, and not a certification.


Reports written for the people who read them
Trend reports show score movement over time, per company and across the portfolio. They’re written for a board audience, and every number in them traces back to a dated scan result if anyone wants to check.
From first scan to steady state
Day 0: your own score, free
We scan your company first. You see the method, the findings and the dashboard on data you can verify yourself.
Week 1: your ten most important vendors
Add them by domain. Scores and findings come in automatically and alerts are live the same day.
Month 1: the rest of the portfolio
Bulk import, assign owners, set alert thresholds, turn on the compliance mappings you're audited against.
End of quarter: the first trend report
Score distribution across the portfolio, biggest movers, open criticals. This usually replaces the questionnaire cycle.
“Our vendor review used to be a quarterly spreadsheet. Now it’s a dashboard we check weekly. When a critical supplier’s score dropped, we called them about it before their own team had noticed.”
Common questions
What do we need to install?
Nothing. Assessment runs from the public internet against domains you nominate. The one optional exception is cloud posture, which uses read-only scoped access to AWS, GCP or Cloudflare if you choose to connect an account.
How long until we see a first rating?
The first assessment on your own domain is self-serve and free. Discovery, scoring and the first report complete without a scoping call or a contract.
How many companies can we track?
Portfolios are multi-domain and multi-tenant. Most teams start with their own organisation plus a first set of critical vendors, then widen once alerting is tuned.
Who can see what?
Access is per tenant, with JWT authentication and OTP two-factor. Every action is recorded in an activity audit trail, including triage decisions and integration changes.
What happens when we fix something?
Trigger an on-demand rescan. Most domain and header findings clear automatically once the change is live, and the score updates without anyone marking it resolved by hand.
Start with your own company's rating
It’s free, takes about a day, and shows you exactly what the platform would show you about your vendors. Plans start at £1,200 per month.
Run WordPress sites too? The plugin scans them free →