Your customers can see your security grade. You probably can't.
Rating platforms score companies from the outside, continuously, whether or not you are their customer — and the companies that buy from you can look you up. Most businesses find out when a customer asks about the letter next to their name.
The signals they score are public, observable, and mostly configuration. We measure the same ones, tell you which are costing you, and give you the exact change to make.
What they score, in their own words
Each item below appears in a rating vendor's own published methodology. We measure all of them.
How your site answers
- Content-Security-Policy missing, or weakened by unsafe-inline / wildcards
- HSTS missing or too short
- X-Frame-Options / frame-ancestors
- X-Content-Type-Options
- Session cookies without Secure or HttpOnly
How your connection is set up
- Weak TLS protocols and cipher suites
- Certificate expiry, mismatch or chain problems
- Plain HTTP that serves content or fails to redirect
Whether your domain can be forged
- SPF missing, malformed, or ending in a soft fail
- DMARC absent, or published as p=none, which reports and blocks nothing
- DKIM key length
What is out there with your name on it
- Hostnames in Certificate Transparency logs you had forgotten
- Lookalike and typosquat domains registered against your brand
- Files and panels reachable in your web root
What we won't tell you
We are not affiliated with any rating platform and have no access to their systems. We cannot see your score, how they weight an issue for your company, or when they will next re-collect your data.
We will not promise a grade. Anyone quoting you a number you will reach is guessing. We can tell you what is in a bad state and exactly how to fix it; what a vendor does with that is theirs to decide.
Their scores include things we cannot see — breach and leaked-credential data, large-scale port scanning across your IP space, patching cadence, network reputation. What we cover is the web, transport, email and exposed-surface part, which is where most of the fixable loss sits for a smaller company, because it is configuration rather than infrastructure.
This is not a penetration test, and we will not call it one. It is an external review of what your systems tell the internet about themselves. If you need someone to try to break in, that is a different engagement.
The one that isn't in the score
No rating platform can see whether one of your customers can read another's data by changing a number in a URL, because from outside it looks like a perfectly normal response. In 2019 the French regulator fined a company €400,000 for exactly that: “a slight modification of the URL displayed in the browser” let any applicant download other applicants' identity documents, tax assessments and bank details — 290,870 files belonging to 29,440 people.
Finding that takes two accounts and a person comparing what each one receives. It is the one thing here that no scanner does — ours included. See how IDOR testing works, or ask about a deep audit.
€290, one domain, one-off
PDF report in three business days, a 30-minute walkthrough, and a free re-check once you have fixed things. No subscription, no retainer.