Why outside-in
beats a questionnaire.
A questionnaire records what a vendor said about themselves on one day. An outside-in rating records what their infrastructure actually shows the internet, today, on the same scale for every company you assess, with the evidence attached.
Same rubric for every company. No cooperation required from the company being assessed.
Used by teams at




What changes when you stop asking and start observing
Most vendor reviews today run on annual questionnaires. Here’s the practical difference.
| Annual questionnaire | GuardianGaze Enterprise | |
|---|---|---|
| How current it is | Answers from whenever the vendor filled it in, usually months old. | Scores update continuously from live scans. |
| What backs it up | The vendor’s own answers. | Each finding links to a dated scan result you can open. |
| Work for the vendor | Long forms, several rounds of chasing. | Nothing. The scan is external. |
| Comparing vendors | Difficult, every vendor answers differently. | Same score scale and method for every company. |
| When a vendor disagrees | Email threads. | They fix the finding, the next scan picks it up, the score updates. |
Where the difference shows up first
Your own external posture
Score yourself first. It's free, and it shows you exactly what the platform sees.
Vendor onboarding
Check a vendor's score before you sign, instead of sending them a 200-question spreadsheet.
Third-party risk
Keep a score on every supplier and get an alert when one drops.
Provider concentration
See which providers your suppliers share, and how much of the portfolio one outage would take with it.
Cyber insurance
Bring an evidence-backed score to renewal instead of a self-filled questionnaire.
Mergers and acquisitions
Score a target company before diligence starts.
RFP scoring
Attach a current security score to each bid so bids are comparable.
Board reporting
A trend report the board can read without a translator.
Situational awareness
When something big hits the news, check your whole portfolio for it in one view.
“Our vendor review used to be a quarterly spreadsheet. Now it’s a dashboard we check weekly. When a critical supplier’s score dropped, we called them about it before their own team had noticed.”
Common questions
Is an outside-in rating fair to the company being assessed?
It is the same rubric for everyone, applied to what their infrastructure publishes to the internet. There is no questionnaire to answer well or badly, and disagreement has a concrete remedy: fix the finding and the next scan reflects it.
Does a score replace a security review?
No. It replaces the part of a review that consists of asking a company to describe itself and hoping the description is current. Contractual, legal and operational review still belongs to your team.
What can an outside-in view not see?
Anything not exposed to the public internet: internal segmentation, endpoint controls, staff training, physical security. We are explicit about that boundary rather than implying the score covers everything.
Why does breadth matter more than the number?
Two platforms can give the same company a similar score from entirely different evidence. What changes a decision is the specific finding (a lookalike domain, a credential in breach data, a failed control) not the number attached to it.
Start with your own company's rating
It’s free, takes about a day, and shows you exactly what the platform would show you about your vendors. Plans start at £1,200 per month.
Run WordPress sites too? The plugin scans them free →