DarkRisk

About

One weak third party is all it takes.

Most breaches now start somewhere in the supply chain, with a vendor or a forgotten asset nobody was watching. DarkRisk exists to make that external surface measurable, so security teams can act on evidence instead of questionnaires.

How we think

Measure what attackers see.

  • Attacker's point of view

    We only measure what is publicly reachable, because that is exactly what a real adversary sees first. No inside knowledge, no assumptions.

  • Read-only by design

    Nothing we run is destructive, and nothing is installed on your network. Scans require no credentials and no cooperation from the target.

  • Honest scoring

    A single score, earned by deducting points for real findings. Catastrophic exposure caps the headline so a clean average never hides a crisis.

Security & trust

Straight about where we stand.

Trust is earned the same way our scores are. Here is how we operate today, stated plainly.

  • Non-intrusive scanning

    Every scan is outside-in and read-only. We never authenticate to a target, never run destructive checks, and never install anything.

  • Data minimisation

    We collect only what a scan needs to produce a score, and we hold reports for as long as you need them and no longer.

  • ISO 27001, in progress

    We are actively working towards ISO 27001 certification. We are not certified yet, and we will say so plainly until we are.

Contact

Let's quantify the risk.

Tell us about your external risk surface and we'll get you set up. Every engagement starts with a conversation, so reach out and the DarkRisk team will take it from there.

hello@darkrisk.io