v2.4 · Mar 2026
How Guardian Gaze risk scores combine static security posture with threat intelligence, exploits in the wild, sector susceptibility, and dark-web data. Cross-input correlation, severity mapping, and the asset-weighted aggregation.
Every scoring function, every weight, every signal is documented here. If the model is wrong for your organisation, you should be able to refute it with evidence. Black-box ratings are theatre.
The score is a weighted combination of four independent input streams. Each stream is collected from public sources, requires no access to your systems, and is independently auditable.
A CVSS base score on its own is not enough. Severity = base × exploitability multiplier × exposure multiplier × asset criticality. The same vulnerability on a marketing microsite and a customer billing API does not contribute the same risk.
Pre-auth RCE, mass scanning, or compromise tooling published. Findings carry a 4x multiplier into the module score.
Auth bypass, SQL injection, privilege escalation. Public proof-of-concept exists but no mass exploitation yet. 2.5x multiplier.
Weak TLS, missing security headers, information disclosure, deprecated services. 1.5x multiplier; aggregates fast across estates.
Server banners, version disclosure, stylistic issues. 1x weight; informational on report but visible to attackers.
Findings roll up to module scores (0-100). Module scores roll up to a company rating (A+ to F). We use a geometric mean rather than arithmetic: a single failing module pulls the rating down, even if the others are pristine. A chain is as strong as its weakest link.
Where modulei is the asset-weighted sum of severity-multiplied findings, normalised to 0-100. Critical assets (customer-facing apps, billing infrastructure) receive 4x weight; non-production receives 0.5x.
Every finding is disputable. Submit evidence through the platform or via email; an analyst reviews within two business days. If the dispute holds, the finding is suppressed, the score recalculates, and the audit trail records the change. False positives are tracked publicly; our target is < 2% of accepted findings.
Disputes are not negotiation. We don’t adjust scores to keep customers happy. Evidence wins.