PuReAIpureAi
Free scan

The methodology behind the score

Ratings you cannot audit are opinions. Here are the weights, the modules that feed each segment, where the data comes from, how we handle false positives, and how you dispute a finding.

Score = (Compromises × 0.4) + (Issues × 0.3) + (Supply Chain × 0.2) + (Exposure Surface × 0.1)

Segment weights and their modules

Compromises

× 0.40

Highest weight: an active compromise is direct, present-tense risk, not a hypothetical.

  • Leaked DataCredentials and records tied to the domain found in third-party breach corpora.
  • Git LeaksSecrets, tokens and keys committed to public repositories.
  • Sensitive FilesIndexed documents, backups and config files that should not be public.

Issues

× 0.30

Scored by the highest confirmed severity and by the distribution across all findings.

  • VulnerabilityDetected products and versions matched against NVD and CISA KEV.
  • MisconfigurationWeak DNS, mail (SPF/DKIM/DMARC) and TLS configuration on discovered assets.

Supply Chain

× 0.20

Weighted average across identified dependencies, factored by vendor criticality.

  • Supply ChainVendors and dependencies scored continuously, with DORA/NIS2 evidence per vendor.
  • News / ThreatsRansomware actor activity and MITRE ATT&CK TTPs correlated to your sector and stack.
  • LookalikeTyposquatted and impersonating domains registered against the brand.

Exposure Surface

× 0.10

Lowest weight: surface alone is not a finding — it is context for everything above.

  • DomainDomains, subdomains and DNS records tied to the organisation.
  • IPHosts, open ports and services reachable from the internet.
  • CertificateTLS certificates, issuers and expiry across the estate.
  • TechnologyStack fingerprinting on each exposed asset.

Data sources and their legal basis

Collection is passive and non-intrusive. We do not exploit, brute-force, or authenticate against any asset, and we do not deploy agents inside your environment.

Public DNS & WHOIS

Passive resolution and registration records. Public by design.

Certificate Transparency logs

Publicly mandated CT logs published by certificate authorities.

NVD & CISA KEV

Public vulnerability catalogues maintained by NIST and CISA.

MITRE ATT&CK

Public adversary tactics and techniques knowledge base.

Breach corpora

Third-party breach datasets already in public or broker circulation; we never purchase access to live criminal marketplaces.

Public code repositories

Repositories and gists that are public at the time of collection.

Open web & news

Indexed pages, leak sites and threat reporting.

Our position on false positives

No external, unauthenticated assessment is free of false positives — anyone claiming otherwise is either scanning intrusively or hiding their error rate.

We handle it in three ways. Findings carry a confidence level alongside severity. Version-inferred vulnerabilities are labelled as inferred, not confirmed. And a finding only moves the score once, in one segment — no double counting the same weakness across modules.

Every Vulnerability, Misconfiguration and Lookalike finding has a status: Open, In Progress, Resolved, Accepted Risk, Monitored. The score reflects what you actually close, and an Accepted Risk stays visible in evidence while stopping the repeat alert.

Disputing a finding

  1. 01Flag it in-platformOpen the finding and mark it disputed with a short reason. It is excluded from the score while under review.
  2. 02Analyst reviewA PuReAI analyst re-checks the raw evidence — the record, the certificate, the banner, the commit — not just the derived finding.
  3. 03Outcome within 5 business daysConfirmed, corrected, or withdrawn. Every outcome is written back to the finding with the evidence used.
  4. 04Rule correctionIf the cause is a detection rule rather than one asset, the rule is fixed for every customer, not suppressed for one.

Want the methodology for procurement?

The redacted sample report includes the scoring appendix your procurement and audit teams will ask for.