We don’t hand-wave the model. Here’s exactly how findings become module scores, how modules become a company rating, and how the rating maps to a letter grade.
We start with CVSS where it applies, plus our own rubric for issues CVSS doesn’t cover (no CVSS exists for a typosquatted domain). Every finding falls into Critical, High, Medium, Low or Info.
A missing security header on your billing portal isn’t the same as one on your blog. Every asset gets an inferred value weight (high if it’s a login, payment endpoint or API; low if it’s a marketing page or status site). You can override our inferred weights any time.
A module score (0–100) is the result of mapping the sum of weighted finding impacts onto a sigmoid curve calibrated against breach incidence data. The curve is steeper at the bottom, a few criticals tank the score quickly, and gentler at the top, passing one extra control doesn’t flip you from B to A.
We use this shape because it matches reality. Going from no DMARC to p=quarantine is a bigger change than going from p=quarantine to p=reject.
The company rating is an asset-weighted geometric mean across the six modules. Geometric mean (not arithmetic) means one terrible module pulls the company score down more than one stellar module pulls it up, which is how breaches actually work.
The numeric score maps to a familiar A–F grade for board-level reporting. The cut-offs are calibrated annually against breach outcomes in our customer base. If A-grade companies started getting breached at the same rate as B-grade, we’d recalibrate.
Three ways to refute a finding: Dispute (the asset isn’t ours), Mitigated (we’ve handled it, here’s the evidence), or Accept (it’s a real finding we’re actively working). Every dispute reaches a human analyst within one business day. Mitigations that pass review remove the finding from your score immediately.
Severity weights and exploit multipliers are recalibrated quarterly against breach outcome data. Structural changes, new input streams, or changes to the aggregation formula are reviewed annually and always logged below. Every rated company moves onto a new methodology version at the same time, so relative standing between peers stays meaningful.
Weighted at 10% of the overall score; credential and source-code exposure now factor into the rating directly.
EPSS thresholds updated against 2025 breach outcome data; high-severity cutoffs tightened.
Findings on customer-facing and payment infrastructure now weighted above marketing/status pages.
Severity weights and multipliers are recalibrated quarterly against breach outcome data; input streams and structural changes are reviewed annually. Every change is logged in the version history below.
Yes, methodology updates are applied uniformly across all rated companies at the same time, so relative standing between peers stays meaningful even as the absolute scoring model evolves.
Yes, the complete methodology whitepaper, including every formula, weight, and worked example, is available below and on the Resources page.
Anyone with access to the rated company’s account can submit a dispute with evidence. An analyst reviews within one business day.