Platform
Twelve modules, one domain in
Each module is an independent collector with its own sources and its own findings. They feed one Company Risk Score with published weights, and every finding keeps the evidence that produced it.
Module reference
Which score segment each module contributes to, and what it collects.
| Module | Score segment | What it collects |
|---|---|---|
| Domain | Exposure (0.1) | Domains, subdomains, DNS records and registrar data for the estate discovered from one seed domain. |
| IP | Exposure (0.1) | Resolved hosts, open services, hosting providers and geolocation of everything the domain estate points at. |
| Certificate | Exposure (0.1) | TLS certificates from certificate transparency: issuers, validity, weak configurations and forgotten hosts. |
| Technology | Exposure (0.1) | Stack fingerprinting of public services, which is what turns a vendor CVE into a finding that concerns you. |
| Vulnerability | Issues (0.3) | Findings matched against NVD and CISA KEV, each with severity, confidence and a status lifecycle. |
| Misconfiguration | Issues (0.3) | DNS, SPF, DKIM, DMARC and TLS deviations on discovered assets. |
| Leaked Data | Compromises (0.4) | Credentials and records tied to your domains that have appeared in breach and combolist data. |
| Git Leaks | Compromises (0.4) | Secrets, tokens and keys committed to public repositories linked to your organisation. |
| Sensitive Files | Compromises (0.4) | Indexed documents and exposed storage that should not be publicly reachable. |
| Lookalike | Supply chain and threats (0.2) | Typosquatted and homoglyph domains registered against your brand, with activity status. |
| News / Threats | Supply chain and threats (0.2) | Ransomware actor activity, leak site postings and incidents relevant to your sector and stack. |
| Supply Chain | Supply chain and threats (0.2) | The same analysis applied to your vendors, scored continuously rather than at renewal. |
How modules become a score
Findings are normalised per segment and combined with fixed weights: Compromises 0.4, Issues 0.3, Supply Chain 0.2, Exposure 0.1. The weights are published rather than proprietary, so any point of the score can be traced back to the findings that moved it.
The full calculation, the severity model and the dispute process are on the methodology page. Where the platform runs is covered under deployment.