Documentation, whitepapers
and reports.
Methodology, buyer’s guides, datasheets and report templates. Everything a procurement or security review tends to ask for, published rather than sent on request.
Technical depth, in full
Scoring methodology
How risk scores combine static posture with threat intelligence, exploits in the wild, sector susceptibility and dark-web data, cross-input correlation, severity mapping and asset-weighted aggregation. Read →
Buyer's guide
A vendor-neutral framework for evaluating any attack-surface platform. Sixteen questions to ask, useful against any vendor brochure including ours. Read →
Platform datasheet
Six-module coverage, integrations, deployment model and how the rating works. Written to drop straight into a procurement folder. Read →
Board pack template
A board-ready quarterly cyber posture report: cover, executive summary, six-module breakdown, supply-chain hotspots and an action plan. Read →
Written for the people who have to justify the decision
Security ratings get bought by a security team and paid for by somebody else. The methodology whitepaper, the buyer's guide, the datasheet and the board pack template exist because each of those audiences asks a different question, and none of them are satisfied by a product page.
Procurement wants to know how the number is produced and whether it can be challenged. A rating nobody can interrogate does not survive a supplier dispute, so the methodology document sets out the model in full: weighted inputs, severity handling, aggregation, versioning, and how to refute a finding with evidence.
The board wants a page they can act on. The board pack template is the quarterly structure we would use ourselves, executive summary, module breakdown, supply-chain concentration, and an action plan with named owners rather than intentions.
Sixteen questions, including the ones we answer badly
The buyer's guide is deliberately vendor-neutral, and the reason is self-interested rather than noble: an evaluation framework written to flatter the vendor who published it is worthless to a buyer, and everybody can tell.
It covers discovery method, attribution confidence, scoring transparency, coverage across modules, false-positive handling, dispute process, operational fit and commercials. Several of those are questions where a competitor answers better than we do, install base and track record among them, and the guide says so.
Use it against us. A buyer who runs the same sixteen questions across three vendors gets a comparable answer, which is more than a feature matrix produces and the only kind of comparison that survives an internal review.
Which document answers which objection
If the objection is that the score is a black box, the methodology whitepaper answers it, because the model is deterministic and versioned rather than proprietary and vague.
If the objection is that external ratings cannot see enough, the honest answer is in every one of these documents: internal controls, segmentation, backup testing and access governance are not externally observable, and ratings are a triage instrument that tells you where to spend audit capacity rather than a replacement for it.
If the objection is cost, the datasheet sets out what is included at each tier: all six modules and the compliance mappings ship in every tier, priced by how many companies you rate rather than by seats or module selection.
Common questions
Are these gated behind a form?
They are written for procurement and security review, and the intention is that they are useful before you talk to us rather than a mechanism for collecting an email address.
Is the buyer's guide really vendor-neutral?
It is written to be used against us as well as anyone else, and it includes questions where competitors answer better than we do. A framework written to flatter its publisher is worthless to a buyer.
What is in the methodology whitepaper?
The full scoring model: weighted input streams, contextual severity multipliers, asset-weighted aggregation, versioning, and the evidence-based route to refute any finding.
Can we use the board pack template as-is?
It is the structure we would use ourselves. Adapt it rather than adopting it wholesale, because the useful version reflects your own reporting conventions.
What does the datasheet cover?
What is included at each tier. All six modules and the compliance mappings ship in every tier; pricing scales with how many companies you rate.
Or see the platform on your own domain
Documents describe the model; a rating on a domain you know well demonstrates it.
Free for your own organisation. No access required.