How secure are the
companies you work with?
Enterprise scans a company's public systems (domains, subdomains, mail records, exposed services, dark web mentions) and turns the results into a security score that updates continuously. Teams use it for vendor reviews, insurance renewals, M&A checks and board reporting.
The first score, on your own company, is free. It’s also how most evaluations start.
Used by teams at





One company's view: risk score, findings by severity, industry benchmark and all six modules
A grade anyone in the meeting can read
Each company gets a 0–100 risk score and a letter grade, plus an industry benchmark that shows where it sits against peers in the same sector. The scoring method is published, so when someone asks “why is this a C”, there’s a documented answer.


Specific findings, not vague warnings
Alerts name the actual problem: a DMARC policy left at p=none, a dev subdomain exposed to the internet, a dark-web mention of company credentials. Each one has a severity, an SLA timer and an owner, so findings get assigned and closed instead of sitting in an inbox.
- Severity levels: critical, high, medium, low
- SLA tracking per alert, with breach flags
- Findings mapped to MITRE ATT&CK techniques
Findings mapped to the frameworks you’re audited on
Scan results map to controls in ISO 27001, SOC 2, NIST CSF, GDPR, HIPAA, PCI DSS, FEDRAMP, DORA and others. For each framework you see which controls pass, which fail, and which fixes would clear the most failures at once. Evidence exports per control.


Reports written for the people who read them
Trend reports show score movement over time, per company and across the portfolio. They’re written for a board audience, and every number in them traces back to a dated scan result if anyone wants to check.
What changes when you switch from questionnaires to scores
Most vendor reviews today run on annual questionnaires. Here’s the practical difference.
| Annual questionnaire | GuardianGaze Enterprise | |
|---|---|---|
| How current it is | Answers from whenever the vendor filled it in, usually months old. | Scores update continuously from live scans. |
| What backs it up | The vendor’s own answers. | Each finding links to a dated scan result you can open. |
| Work for the vendor | Long forms, several rounds of chasing. | Nothing. The scan is external. |
| Comparing vendors | Difficult, every vendor answers differently. | Same score scale and method for every company. |
| When a vendor disagrees | Email threads. | They fix the finding, the next scan picks it up, the score updates. |
Where teams use it
Vendor onboarding
Check a vendor's score before you sign, instead of sending them a 200-question spreadsheet.
Third-party risk
Keep a score on every supplier and get an alert when one drops.
Supply chain
See which suppliers your critical systems depend on, and how exposed each one is.
Board reporting
A trend report the board can read without a translator.
Cyber insurance
Bring an evidence-backed score to renewal instead of a self-filled questionnaire.
Mergers and acquisitions
Score a target company before diligence starts.
RFP scoring
Attach a current security score to each bid so bids are comparable.
Your own company
Score yourself first. It's free, and it shows you what the platform sees.
Situational awareness
When something big hits the news, check your whole portfolio for it in one view.
What the first quarter looks like
Day 0: your own score, free
We scan your company first. You see the method, the findings and the dashboard on data you can verify yourself.
Week 1: your ten most important vendors
Add them by domain. Scores and findings come in automatically and alerts are live the same day.
Month 1: the rest of the portfolio
Bulk import, assign owners, set alert thresholds, turn on the compliance mappings you're audited against.
End of quarter: the first trend report
Score distribution across the portfolio, biggest movers, open criticals. This usually replaces the questionnaire cycle.
“Our vendor review used to be a quarterly spreadsheet. Now it’s a dashboard we check weekly. When a critical supplier’s score dropped, we called them about it before their own team had noticed.”
Common questions
Do the companies we score have to install anything or agree to it?
No. Scans only look at what's already public: DNS records, certificates, exposed services, published applications. Companies can be invited to see their own findings and fix them, but nothing depends on their cooperation.
How is this different from a penetration test?
A pentest goes deep on one target at one point in time. Enterprise stays wide and current across your whole portfolio. Many customers use the scores to decide where a pentest is worth commissioning.
What if a vendor says their score is wrong?
They can look at the finding behind it. If it's fixed or was inaccurate, the next scan picks that up and the score updates, typically within days.
Will you pass our own security review?
We go through them regularly. DPA, architecture documentation and our own external score are part of the standard procurement pack.
How is it priced?
From £1,200 per month, based on how many companies you rate and which modules you turn on. No per-seat pricing. Every evaluation starts with a free rating of your own company, so you decide on real data.
Start with your own company's rating
It’s free, takes about a day, and shows you exactly what the platform would show you about your vendors. Plans start at £1,200 per month.
Run WordPress sites too? The plugin scans them free →