About
Most breaches now start somewhere in the supply chain, with a vendor or a forgotten asset nobody was watching. DarkRisk exists to make that external surface measurable, so security teams can act on evidence instead of questionnaires.
How we think
We only measure what is publicly reachable, because that is exactly what a real adversary sees first. No inside knowledge, no assumptions.
Nothing we run is destructive, and nothing is installed on your network. Scans require no credentials and no cooperation from the target.
A single score, earned by deducting points for real findings. Catastrophic exposure caps the headline so a clean average never hides a crisis.
Security & trust
Trust is earned the same way our scores are. Here is how we operate today, stated plainly.
Every scan is outside-in and read-only. We never authenticate to a target, never run destructive checks, and never install anything.
We collect only what a scan needs to produce a score, and we hold reports for as long as you need them and no longer.
We are actively working towards ISO 27001 certification. We are not certified yet, and we will say so plainly until we are.
Contact
Tell us about your external risk surface and we'll get you set up. Every engagement starts with a conversation, so reach out and the DarkRisk team will take it from there.
hello@darkrisk.io