The methodology behind the score
Ratings you cannot audit are opinions. Here are the weights, the modules that feed each segment, where the data comes from, how we handle false positives, and how you dispute a finding.
Segment weights and their modules
Compromises
× 0.40Highest weight: an active compromise is direct, present-tense risk, not a hypothetical.
- Leaked Data — Credentials and records tied to the domain found in third-party breach corpora.
- Git Leaks — Secrets, tokens and keys committed to public repositories.
- Sensitive Files — Indexed documents, backups and config files that should not be public.
Issues
× 0.30Scored by the highest confirmed severity and by the distribution across all findings.
- Vulnerability — Detected products and versions matched against NVD and CISA KEV.
- Misconfiguration — Weak DNS, mail (SPF/DKIM/DMARC) and TLS configuration on discovered assets.
Supply Chain
× 0.20Weighted average across identified dependencies, factored by vendor criticality.
- Supply Chain — Vendors and dependencies scored continuously, with DORA/NIS2 evidence per vendor.
- News / Threats — Ransomware actor activity and MITRE ATT&CK TTPs correlated to your sector and stack.
- Lookalike — Typosquatted and impersonating domains registered against the brand.
Exposure Surface
× 0.10Lowest weight: surface alone is not a finding — it is context for everything above.
- Domain — Domains, subdomains and DNS records tied to the organisation.
- IP — Hosts, open ports and services reachable from the internet.
- Certificate — TLS certificates, issuers and expiry across the estate.
- Technology — Stack fingerprinting on each exposed asset.
Data sources and their legal basis
Collection is passive and non-intrusive. We do not exploit, brute-force, or authenticate against any asset, and we do not deploy agents inside your environment.
Public DNS & WHOIS
Passive resolution and registration records. Public by design.
Certificate Transparency logs
Publicly mandated CT logs published by certificate authorities.
NVD & CISA KEV
Public vulnerability catalogues maintained by NIST and CISA.
MITRE ATT&CK
Public adversary tactics and techniques knowledge base.
Breach corpora
Third-party breach datasets already in public or broker circulation; we never purchase access to live criminal marketplaces.
Public code repositories
Repositories and gists that are public at the time of collection.
Open web & news
Indexed pages, leak sites and threat reporting.
Our position on false positives
No external, unauthenticated assessment is free of false positives — anyone claiming otherwise is either scanning intrusively or hiding their error rate.
We handle it in three ways. Findings carry a confidence level alongside severity. Version-inferred vulnerabilities are labelled as inferred, not confirmed. And a finding only moves the score once, in one segment — no double counting the same weakness across modules.
Every Vulnerability, Misconfiguration and Lookalike finding has a status: Open, In Progress, Resolved, Accepted Risk, Monitored. The score reflects what you actually close, and an Accepted Risk stays visible in evidence while stopping the repeat alert.
Disputing a finding
- 01Flag it in-platform — Open the finding and mark it disputed with a short reason. It is excluded from the score while under review.
- 02Analyst review — A PuReAI analyst re-checks the raw evidence — the record, the certificate, the banner, the commit — not just the derived finding.
- 03Outcome within 5 business days — Confirmed, corrected, or withdrawn. Every outcome is written back to the finding with the evidence used.
- 04Rule correction — If the cause is a detection rule rather than one asset, the rule is fixed for every customer, not suppressed for one.
Want the methodology for procurement?
The redacted sample report includes the scoring appendix your procurement and audit teams will ask for.