GuardianGaze EnterpriseNothing for vendors to install

How the score
is calculated.

Each company gets a 0-100 risk score and a letter grade built from a published, versioned rubric. Click any component and you get the observation behind it, with the date it was collected.

The first score, on your own company, is free. It’s also how most evaluations start.

Used by teams at

BykeaApTaskHolisticoAmerican Healthcare Academy
0–100one risk score per company, benchmarked against its industry
6modules: brand, domain, attack surface, network, cloud, compliance, with 12 compliance frameworks mapped automatically
0installs or questionnaires needed from the companies you score
Enterprise dashboard: company risk score, threat distribution, industry benchmark, portfolio summary

One company's view: risk score, findings by severity, industry benchmark and all six modules

Scoring

A grade anyone in the meeting can read

Each company gets a 0–100 risk score and a letter grade, plus an industry benchmark that shows where it sits against peers in the same sector. The scoring method is published, so when someone asks “why is this a C”, there’s a documented answer.

A8.5–10
B7.0–8.4
C5.5–6.9
D4.0–5.4
F<4.0
Portfolio of company scores over time
Alerts list: dark-web exposure, DMARC policy p=none, missing TLS-RPT, exposed dev subdomains, each with severity, SLA and owner
Alerts

Specific findings, not vague warnings

Alerts name the actual problem: a DMARC policy left at p=none, a dev subdomain exposed to the internet, a dark-web mention of company credentials. Each one has a severity, an SLA timer and an owner, so findings get assigned and closed instead of sitting in an inbox.

  • Severity levels: critical, high, medium, low
  • SLA tracking per alert, with breach flags
  • Findings mapped to MITRE ATT&CK techniques
Compliance

Findings mapped to the frameworks you’re audited on

Scan results map to controls in ISO 27001, SOC 2, NIST CSF, GDPR, HIPAA, PCI DSS, FEDRAMP, DORA and others. For each framework you see which controls pass, which fail, and which fixes would clear the most failures at once. Evidence exports per control.

Compliance view: coverage heatmap across frameworks, remediation priorities, per-module control pass and fail counts
Security trend report for leadership
Reporting

Reports written for the people who read them

Trend reports show score movement over time, per company and across the portfolio. They’re written for a board audience, and every number in them traces back to a dated scan result if anyone wants to check.

Compared with questionnaires

What changes when you switch from questionnaires to scores

Most vendor reviews today run on annual questionnaires. Here’s the practical difference.

Annual questionnaireGuardianGaze Enterprise
How current it isAnswers from whenever the vendor filled it in, usually months old.Scores update continuously from live scans.
What backs it upThe vendor’s own answers.Each finding links to a dated scan result you can open.
Work for the vendorLong forms, several rounds of chasing.Nothing. The scan is external.
Comparing vendorsDifficult, every vendor answers differently.Same score scale and method for every company.
When a vendor disagreesEmail threads.They fix the finding, the next scan picks it up, the score updates.
Use cases

Where teams use it

Procurement

Vendor onboarding

Check a vendor's score before you sign, instead of sending them a 200-question spreadsheet.

Risk

Third-party risk

Keep a score on every supplier and get an alert when one drops.

Risk

Supply chain

See which suppliers your critical systems depend on, and how exposed each one is.

Leadership

Board reporting

A trend report the board can read without a translator.

Insurance

Cyber insurance

Bring an evidence-backed score to renewal instead of a self-filled questionnaire.

Corp dev

Mergers and acquisitions

Score a target company before diligence starts.

Procurement

RFP scoring

Attach a current security score to each bid so bids are comparable.

Internal

Your own company

Score yourself first. It's free, and it shows you what the platform sees.

Ops

Situational awareness

When something big hits the news, check your whole portfolio for it in one view.

Rollout

What the first quarter looks like

D0

Day 0: your own score, free

We scan your company first. You see the method, the findings and the dashboard on data you can verify yourself.

W1

Week 1: your ten most important vendors

Add them by domain. Scores and findings come in automatically and alerts are live the same day.

M1

Month 1: the rest of the portfolio

Bulk import, assign owners, set alert thresholds, turn on the compliance mappings you're audited against.

Q1

End of quarter: the first trend report

Score distribution across the portfolio, biggest movers, open criticals. This usually replaces the questionnaire cycle.

“Our vendor review used to be a quarterly spreadsheet. Now it’s a dashboard we check weekly. When a critical supplier’s score dropped, we called them about it before their own team had noticed.”
CISO · Mid-market financial services group
FAQ

Common questions

Do the companies we score have to install anything or agree to it?

No. Scans only look at what's already public: DNS records, certificates, exposed services, published applications. Companies can be invited to see their own findings and fix them, but nothing depends on their cooperation.

How is this different from a penetration test?

A pentest goes deep on one target at one point in time. Enterprise stays wide and current across your whole portfolio. Many customers use the scores to decide where a pentest is worth commissioning.

What if a vendor says their score is wrong?

They can look at the finding behind it. If it's fixed or was inaccurate, the next scan picks that up and the score updates, typically within days.

Will you pass our own security review?

We go through them regularly. DPA, architecture documentation and our own external score are part of the standard procurement pack.

How is it priced?

From £1,200 per month, based on how many companies you rate and which modules you turn on. No per-seat pricing. Every evaluation starts with a free rating of your own company, so you decide on real data.

Start with your own company's rating

It’s free, takes about a day, and shows you exactly what the platform would show you about your vendors. Plans start at £1,200 per month.

Run WordPress sites too? The plugin scans them free →