Platform datasheet.
Six-module coverage, integrations, deployment model and how the rating works, everything a procurement or security review asks for, on one page.
Six disciplines, one rating
Brand protection
Typosquats, lookalike domains, brand impersonation on social, fake app stores and phishing kits. Takedowns included.
Domain security
DNS hygiene, SPF/DKIM/DMARC, certificate management, registrar lock and domain-takeover risk.
Application security
Exposed apps, leaked credentials, vulnerable software versions, dangling subdomains and public buckets.
Network security
TLS configuration, exposed admin services, IP reputation, ASN posture and firewall fingerprinting.
Cloud security
Misattributed cloud assets, public IAM, exposed metadata endpoints and shadow accounts.
Compliance
Findings mapped to ISO 27001, NIST, PCI DSS and GDPR, each mapping traced to the finding behind it. Indicative, not an audit.
Ships into your existing stack
| Ticketing | Jira, ServiceNow, Linear, Asana |
| Chat | Slack, Microsoft Teams |
| SIEM | Splunk, Sentinel, Elastic, Sumo |
| SOAR | Palo Alto XSOAR, Tines |
| Identity | Okta, Azure AD, Google Workspace |
| GRC | Vanta, Drata, OneTrust, ServiceNow GRC |
| API | REST, webhooks, GraphQL |
| Export | CSV, JSON, PDF, STIX 2.1 |
Hand us a domain. That is it.
Outside-in means no agents, no credentials and no scoping call. From a single seed domain we discover, attribute, scan, score and report. Onboarding completes in hours, not weeks.
Built to a defensible standard
| Certification | SOC 2 Type II coverage; ISO 27001 in progress |
| Data | UK and EU regions, encrypted at rest and in transit |
| Privacy | GDPR-compliant, DPA available, no personal data ingested |
| Access | SAML, OIDC and SCIM, with MFA enforced |
From £1,200/month, quoted to your portfolio
That figure is a floor rather than a rate card: the final price is quoted against your actual portfolio, because it scales with how many companies you rate. All modules are included on every tier, along with brand takedowns and the compliance frameworks. No per-user fees. Annual or monthly, and a free rating on request.
Every module, every tier
All six scoring modules (domain security, network security, application security, cloud security, brand protection and compliance mapping) ship in every tier, along with the compliance framework mappings. Tiers differ by how many companies you rate and how much history and support you need, not by which parts of an attack surface you are permitted to see.
That is deliberate rather than a packaging accident. A partial view of an attack surface is not a cheaper product; it is a misleading one. Selling domain security separately from network security would let a customer hold a rating that looked complete while a whole category of exposure sat outside their subscription.
There is also no per-seat charge. Everyone who needs the dashboard has it, because per-seat pricing on a risk tool encourages credential sharing and then penalises the customer for it.
Nothing to install, on either side
There is no agent, no appliance, and nothing for a rated company to approve. Assessment observes what is published to the public internet, which is why it works on vendors, acquisition targets and tender bidders who have agreed to nothing.
The single exception is deeper cloud posture, which uses read-only scoped access to a cloud account you choose to connect. That is optional, it applies only to your own estate, and everything else works without it.
First ratings return within 24 hours of supplying a domain and refresh continuously thereafter, with on-demand rescans when you need a current answer rather than a recent one.
What we hold and how it is handled
What is stored is the observed evidence behind each finding and the scoring history derived from it. That history is what makes trending meaningful and what lets a finding be disputed on facts rather than on methodology.
Scoring is deterministic and versioned, so the same evidence produces the same score and a change in methodology is distinguishable from a change in posture. A rating that moved because we changed our mind would make quarter-on-quarter comparison worthless.
Findings carry the evidence they were derived from. If evidence is wrong or stale, the finding goes: that is the mechanism, and a platform without it accumulates disputed findings until security teams stop reading the feed.
Common questions
Do we have to choose modules?
No. All six ship in every tier, along with the compliance mappings. Tiers differ by how many companies you rate, not by which parts of an attack surface you can see.
Is there a per-seat charge?
No. Pricing scales with rated companies rather than users, so the whole team uses it.
Is there anything to install?
No agent and no appliance, and nothing for a rated company to approve. The only optional exception is read-only scoped cloud access for deeper posture on your own estate.
How quickly does a first rating arrive?
Within 24 hours of supplying a domain, then continuously, with on-demand rescans when you need a current answer.
Is the scoring model stable over time?
It is deterministic and versioned, so the same evidence produces the same score and a methodology change is distinguishable from a posture change.
What happens to a finding we can disprove?
It goes. Findings carry the evidence they came from, so a dispute is factual, and a platform without that mechanism accumulates disputed findings until nobody reads the feed.
Drop it in the folder, then test it
A datasheet describes the platform; a rating on your own domain demonstrates it.
Free for your own organisation. No access required.