PuReAIpureAi
Free scan

Platform

Twelve modules, one domain in

Each module is an independent collector with its own sources and its own findings. They feed one Company Risk Score with published weights, and every finding keeps the evidence that produced it.

Module reference

Which score segment each module contributes to, and what it collects.

ModuleScore segmentWhat it collects
DomainExposure (0.1)Domains, subdomains, DNS records and registrar data for the estate discovered from one seed domain.
IPExposure (0.1)Resolved hosts, open services, hosting providers and geolocation of everything the domain estate points at.
CertificateExposure (0.1)TLS certificates from certificate transparency: issuers, validity, weak configurations and forgotten hosts.
TechnologyExposure (0.1)Stack fingerprinting of public services, which is what turns a vendor CVE into a finding that concerns you.
VulnerabilityIssues (0.3)Findings matched against NVD and CISA KEV, each with severity, confidence and a status lifecycle.
MisconfigurationIssues (0.3)DNS, SPF, DKIM, DMARC and TLS deviations on discovered assets.
Leaked DataCompromises (0.4)Credentials and records tied to your domains that have appeared in breach and combolist data.
Git LeaksCompromises (0.4)Secrets, tokens and keys committed to public repositories linked to your organisation.
Sensitive FilesCompromises (0.4)Indexed documents and exposed storage that should not be publicly reachable.
LookalikeSupply chain and threats (0.2)Typosquatted and homoglyph domains registered against your brand, with activity status.
News / ThreatsSupply chain and threats (0.2)Ransomware actor activity, leak site postings and incidents relevant to your sector and stack.
Supply ChainSupply chain and threats (0.2)The same analysis applied to your vendors, scored continuously rather than at renewal.

How modules become a score

Findings are normalised per segment and combined with fixed weights: Compromises 0.4, Issues 0.3, Supply Chain 0.2, Exposure 0.1. The weights are published rather than proprietary, so any point of the score can be traced back to the findings that moved it.

The full calculation, the severity model and the dispute process are on the methodology page. Where the platform runs is covered under deployment.

Run the twelve on your own domain