A rating you can argue with
is a rating worth having.
A score nobody can interrogate is just a number with a colour. This is the whole model: how findings become module scores, how modules become a company rating, and exactly what moves it.
Three rules the model follows
Everything below follows from these. Where a design decision was a trade-off, it went in favour of being defensible.
Same inputs, same score
The rubric is weighted and versioned. Two companies with identical observable posture receive identical scores, and a rescan that finds nothing new does not move the number.
Every point traceable
A score is an aggregate of findings, and every finding carries the observation that produced it. You can always walk from the grade back to the raw evidence.
Only what is observable
Scores are built from what can be seen from the public internet. Nothing is inferred from a questionnaire, and nothing depends on the company under assessment cooperating.
From finding to grade
Six module scores, one weighted rating, one letter band.
| 0–100 per module | Each of the six modules is scored independently, so a strong perimeter cannot hide a weak brand posture. |
| Weighted aggregate | Module scores combine into one company rating using published weights rather than an average. |
| Letter grade | The rating maps to a letter band for reporting, so a board sees a grade and an engineer sees the number. |
| Severity-driven | A single critical finding moves a score further than a long tail of low-severity ones, count alone does not drive the result. |
What actually moves a score
Scores should move when posture changes and stay still when it does not.
| Score drops | A new critical or high finding, a newly published CVE affecting a detected technology, a newly registered lookalike domain, or fresh credential exposure. |
| Score rises | A finding is remediated and the next scan confirms it cleared, most domain findings clear automatically once the record changes. |
| Score holds | A rescan that finds nothing new. Scores do not drift with time or decay for inactivity. |
| Score is corrected | A finding is triaged as a false positive or accepted risk, with the rationale recorded in the audit trail. |
What the score is built from
- Findings observed from the public internet, across six modules
- Severity, with exploitability weighted via CVSS, EPSS and KEV
- Evidence recorded for every finding
- Analyst verification on brand-protection indicators
- Triage decisions you have recorded
What it is deliberately not built from
- Self-reported questionnaire answers
- Raw vulnerability counts
- Company size, sector or revenue
- Anything requiring access to your environment
- Time decay, a score does not drift on its own

The rating, with the six module scores underneath that produced it
Common questions
Is the score comparable between companies?
Yes, that is the point of a deterministic rubric. The same observation is scored the same way for every company, which is what makes a vendor portfolio meaningful rather than a collection of unrelated opinions.
Can a company improve its score without improving security?
Not meaningfully. Scores move on findings, and findings are observations rather than assertions: there is no questionnaire to answer favourably. The fastest legitimate improvements tend to be domain and header findings, which are genuine fixes that happen to be quick.
What if you flag something that is not a real risk for us?
Triage it. Findings governance covers false-positive marking and accepted-risk decisions with a recorded rationale, and the score reflects those decisions rather than the finding silently reappearing on the next scan.
Do you publish raw vulnerability counts?
No, deliberately. A raw count rewards noise and punishes a large estate. Findings are prioritised and evidence-backed, and the score is driven by severity and exploitability rather than volume.
How often is a score recalculated?
Continuously, with on-demand rescans when you want to confirm a fix. The rating reflects the estate as observed, not as reviewed last quarter.
Run the model against your own company
The quickest way to test a scoring model is on a company whose posture you already know.
Free for your own organisation. Assessed by domain, no access required.