Trusted security · Built from London
Products
Whitepaper

v2.4 · Mar 2026

Scoring methodology.

How Guardian Gaze risk scores combine static security posture with threat intelligence, exploits in the wild, sector susceptibility, and dark-web data. Cross-input correlation, severity mapping, and the asset-weighted aggregation.

Every scoring function, every weight, every signal is documented here. If the model is wrong for your organisation, you should be able to refute it with evidence. Black-box ratings are theatre.

01 · Inputs

Four input streams.

The score is a weighted combination of four independent input streams. Each stream is collected from public sources, requires no access to your systems, and is independently auditable.

STREAM A · 45%

Static posture

Findings from the six scanning modules. TLS configuration, HTTP security headers, exposed services, DNS hygiene, certificate management, cloud posture. Snapshotted continuously.

STREAM B · 25%

Threat intelligence

CVE feed cross-referenced against detected versions, known-exploited vulnerabilities (CISA KEV), exploit availability scores (EPSS), active-campaign sightings from sector-peer telemetry.

STREAM C · 20%

Sector susceptibility

Industry attack base rates, geographic threat density, vertical-specific ransomware activity, and breach frequency at companies of comparable size and posture.

STREAM D · 10%

Dark-web signal

Credentials, source code, and customer data observed in criminal marketplaces, ransom-leak sites, paste sites, and underground forums attributable to your organisation.

02 · Severity

Severity is contextual.

A CVSS base score on its own is not enough. Severity = base × exploitability multiplier × exposure multiplier × asset criticality. The same vulnerability on a marketing microsite and a customer billing API does not contribute the same risk.

Critical

Active exploitation observed

CVSS 9.0+ · KEV listed · EPSS > 0.7

Pre-auth RCE, mass scanning, or compromise tooling published. Findings carry a 4x multiplier into the module score.

High

Reliable exploitation path

CVSS 7.0-8.9 · EPSS 0.3-0.7

Auth bypass, SQL injection, privilege escalation. Public proof-of-concept exists but no mass exploitation yet. 2.5x multiplier.

Medium

Defensible misconfiguration

CVSS 4.0-6.9

Weak TLS, missing security headers, information disclosure, deprecated services. 1.5x multiplier; aggregates fast across estates.

Low

Hygiene signal

CVSS 0.1-3.9

Server banners, version disclosure, stylistic issues. 1x weight; informational on report but visible to attackers.

03 · Aggregation

Asset-weighted, geometric mean.

Findings roll up to module scores (0-100). Module scores roll up to a company rating (A+ to F). We use a geometric mean rather than arithmetic: a single failing module pulls the rating down, even if the others are pristine. A chain is as strong as its weakest link.

FORMULA
rating = 100 − (∏i=1..6 modulei)1/6

Where modulei is the asset-weighted sum of severity-multiplied findings, normalised to 0-100. Critical assets (customer-facing apps, billing infrastructure) receive 4x weight; non-production receives 0.5x.

Letter grade mapping

A+
90-100
A
80-89
B
70-79
C
60-69
D
50-59
F
0-49
04 · Disputes

Refute any finding.

Every finding is disputable. Submit evidence through the platform or via email; an analyst reviews within two business days. If the dispute holds, the finding is suppressed, the score recalculates, and the audit trail records the change. False positives are tracked publicly; our target is < 2% of accepted findings.

Disputes are not negotiation. We don’t adjust scores to keep customers happy. Evidence wins.