Trusted security · Built from London
Products
Buyer’s guide

For procurement · CISO · security ops

A vendor-neutral evaluation framework.

Twenty-plus questions to ask any attack-surface platform. Use it against us. Use it against anyone. The questions are the questions; the answers are how you tell platforms apart.

01 · Discovery

Can it find what you don’t know you own?

Shadow IT, M&A inheritance, abandoned cloud accounts. The platform is only as good as its discovery.

  • Q1

    From a single seed domain, how many of our 60+ subdomains do you find?

    Look for: passive DNS, certificate transparency, ASN enumeration, Wayback, code-search.

  • Q2

    How do you attribute cloud assets that don’t carry our brand?

    Look for: bucket-naming heuristics, IP reputation linkage, SSL SAN cross-reference, code-repo signals.

  • Q3

    When we refute an attribution, how does the model learn?

    Look for: confidence scoring, suppression workflow, audit trail. Avoid: opaque ML black box.

  • Q4

    What’s your false positive rate on discovered assets?

    Look for: a number, with measurement methodology. Avoid: “industry-leading accuracy.”

02 · Scoring

Can you explain the number?

If the platform produces a rating, you should be able to defend it to a board, an auditor, and the vendor it’s scoring.

  • Q5

    Is the scoring methodology public?

    Look for: published whitepaper, exact weights, formula. Avoid: “proprietary algorithm.”

  • Q6

    Can a vendor dispute a finding? What’s the SLA?

    Look for: documented workflow, named analyst, < 5 business days. Avoid: “email support.”

  • Q7

    How often does the rating refresh?

    Look for: continuous (within 24h of a finding change). Avoid: monthly recompute.

  • Q8

    Show me a low-rated company you couldn’t explain.

    Look for: a candid answer with examples. Avoid: deflection.

03 · Coverage

What disciplines are covered?

A platform that only does TLS hygiene is not an attack-surface platform.

  • Q9-Q14

    Do you cover brand, domain, attack surface, network, cloud, compliance?

    Look for: dedicated modules, not feature checkboxes. Avoid: “via integration.”

  • Q15

    How many compliance frameworks do you map automatically?

    Look for: 10+, with named frameworks. Avoid: “customisable templates.”

  • Q16

    Brand takedowns. Are they included or extra?

    Look for: included, with SLA. Avoid: “professional services engagement.”

04 · Operations

Can it land inside your team?

A platform that doesn’t route findings to the right owner is a dashboard nobody opens.

  • Q17

    Native integrations with Jira, ServiceNow, Slack, SIEM?

    Look for: out-of-the-box, with field mapping. Avoid: “via Zapier.”

  • Q18

    Onboarding time from contract signed to first useful rating?

    Look for: hours to days. Avoid: 4-6 weeks of scoping.

  • Q19

    API access. Rate limits. Sandbox.

    Look for: REST & webhooks, documented limits, free sandbox. Avoid: API as paid add-on.

05 · Commercial

Is the pricing comprehensible?

  • Q20

    Is pricing on the website?

    Look for: tiered pricing, transparent inclusions. Avoid: “contact us.”

  • Q21

    What scales the price? Assets? Users? Vendors?

    Look for: one clear axis. Avoid: per-user fees on a platform you already pay for.

  • Q22

    Free trial or paid pilot?

    Look for: a free rating, no scoping call. Avoid: 90-day paid POC.