One platform.
Nine risk conversations.
The same continuously-updated rating answers procurement, third-party risk, insurance renewals, M&A diligence and board reporting, so the security team and the business are finally reading the same number.
Pick the conversation you're having
Vendor onboarding →
Check a vendor's score before you sign, instead of sending a 200-question spreadsheet.
Cyber insurance →
Bring an evidence-backed score to renewal instead of a self-filled questionnaire.
Email security & DMARC →
Find out whether a stranger can send mail as your domain, and fix it in one DNS record.
One rating, read by five different departments
The reason security ratings spread across an organisation rather than staying in the security team is that the underlying question keeps recurring in different vocabulary. Procurement asks whether a supplier is safe to sign. Risk asks which vendors could hurt us. Finance asks what the insurer will say at renewal. Corporate development asks what we are buying. The board asks whether things are getting better.
All five are asking about the same observable thing: what an organisation's security looks like from outside, and whether it is moving. Historically each department answered it separately, with a different instrument, on a different cadence, producing answers that could not be reconciled, which is how a company ends up with a vendor rated acceptable by procurement and unacceptable by risk in the same quarter.
A continuously refreshed external rating gives all five the same number, derived the same way, with the evidence attached. The value is less about any individual assessment than about the arguments it stops.
The three properties every one of these use cases depends on
No participation required. Every workflow below works on companies who have not agreed to anything, prospective suppliers, acquisition targets, tender bidders, an entire insurance book. That is a direct consequence of assessing only what is published to the public internet, and it is what makes coverage a decision rather than a negotiation.
Continuous rather than point-in-time. An assessment describes a moment; the thing people actually want to know is when something changes. Every use case here degrades to a compliance exercise if the rating is refreshed annually, and becomes a control if it is refreshed continuously.
Evidence attached to every finding. A rating nobody can interrogate is a rating nobody will act on, because the first response to an uncomfortable number is to question the method. Findings that carry their evidence turn that into a factual conversation, and a finding that turns out to be wrong or stale should go.
What an outside-in rating does not tell you
Everything here is bounded by what is externally observable. That covers a great deal, because it is the same surface an attacker starts from, but it stops at the perimeter, and any vendor implying otherwise is overselling.
Not visible from outside: internal network segmentation, whether backups are tested and restorable, how privileged access is governed, what the incident response plan says, security training, and how data is handled once it is inside an environment. Those are real controls, they matter, and questionnaires and audit reports remain the right instruments for them.
So the model that works is triage rather than replacement. Rate everything continuously, because it is cheap and needs nobody's cooperation, then spend scarce questionnaire and audit capacity where the rating says something is wrong or where the data at stake demands assurance the outside cannot give. Most risk programmes are limited by capacity rather than intent, and this is what lets you aim the capacity you have.
Which use case belongs to whom
| Team | Question they are asking | Use case |
|---|---|---|
| Procurement | Is this supplier safe to sign? | Vendor onboarding, RFP scoring |
| Third-party risk | Which of our vendors could hurt us? | Third-party risk, supply chain |
| Security operations | Are we affected by this advisory? | Situational awareness |
| Infrastructure | What of ours is exposed that we do not know about? | Own enterprise visibility |
| Finance / insurance | What will the underwriter see at renewal? | Cyber insurance |
| Corporate development | What are we actually buying? | Mergers and acquisitions |
| Board / executive | Is our posture improving? | Board reporting |
| IT / messaging | Can a stranger send mail as us? | Email security and DMARC |
Pricing scales with the number of rated companies rather than per seat, so every team above can use the same portfolio.
Common questions
Do we need permission to rate another company?
No. Assessment observes only what an organisation publishes to the public internet, the same vantage point any visitor or attacker has. Nothing is exploited and no system is accessed, which is what makes vendor review, tender scoring and acquisition screening workable without a negotiation.
How long does a first rating take?
Within 24 hours of supplying a domain. There is nothing for the rated company to install and nothing for them to approve.
Does this replace security questionnaires?
No, and we would not claim it does. Ratings cover what is externally observable; questionnaires and audit reports cover internal controls like segmentation, backup testing and access governance. Ratings tell you where to spend limited questionnaire capacity.
Which use case do most teams start with?
Rating their own organisation. It is free, every finding can be checked against what you already know to be true, and it shows you what a prospective customer or underwriter sees when they rate you. If the findings are accurate on the environment you understand best, the vendor ratings are worth acting on.
How many companies can we monitor?
Pricing scales with the number of monitored companies rather than per seat, so the whole team uses it. Most programmes begin with ten to forty critical suppliers and widen once the alerting has proved itself.
What happens when a rating changes?
You are alerted with the specific findings that moved it. The value of continuous monitoring is not the score: it is being told the week it changes rather than at the next annual review.

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out
Put your vendors on the board
Start with ten vendors. Expand when the first alert pays for the year.