DarkRisk

The platform

The DarkRisk Scanner.

A non-intrusive, outside-in security scanner that grades your domain across ten risk categories in under five minutes, with no installation and no agents. We inspect a domain the way an attacker would, from the outside, and turn what they can see into one honest number.

12
Scan modules
250+
Distinct findings
800+
Tech fingerprints
71
Ports inspected

Why DarkRisk

Security visibility, without the noise.

Questionnaires measure what a vendor claims. DarkRisk measures what an attacker can actually see, continuously, and without waiting on anyone.

  • Outside-in visibility

    We inspect a domain the way an attacker would, from the outside. No portal access, no cooperation from the vendor required.

  • Answers in minutes

    A full external assessment lands in under five minutes for a typical estate. Skip the six-week questionnaire round-trip.

  • Nothing to install

    Non-intrusive and read-only. No agents, no credentials, no scheduled maintenance window. Nothing touches the internal network.

  • One number, honestly earned

    Every asset starts at 100 and loses points per finding. Red-flag exposures cap the headline so a clean average can't hide a crisis.

How it works

Discover. Inspect. Score.

We resolve every reachable asset, probe each one across ten distinct risk categories, and roll the results into a single, honest score between 0 and 100.

  1. 01 / 03

    Discover every asset

    Subdomain enumeration via DNS, certificate transparency, and threat-intel feeds. Every responsive host gets scanned, not just the apex.

  2. 02 / 03

    Inspect ten categories

    Network, email, TLS, application, DNS, brand, breach, cloud, technology, and compliance signals, probed in parallel with strict timeouts.

  3. 03 / 03

    Score one honest number

    Findings collapse into a single 0 to 100 score with a letter grade. Catastrophic findings cap the score, so weakness is never hidden.

12
Scan modules
250+
Distinct findings
800+
Tech fingerprints
71
Ports inspected

What we check

Ten categories. One picture.

Each category contributes a weighted slice of the final score. The bigger the weight, the more it moves the needle. Together they cover the surface an attacker sees without ever touching your internal network.

  • 01

    Network Security

    20%

    Open ports, exposed databases, DNS blacklist hits, SSH posture, cloud and PTR hygiene.

  • 02

    Email Security

    15%

    SPF, DMARC, DKIM, MTA-STS and BIMI, the controls that stop your brand being spoofed.

  • 03

    TLS & Transport

    15%

    Certificate validity, key strength, protocol versions, HSTS and HTTPS enforcement.

  • 04

    Application Security

    15%

    Exposed secrets, security headers, CORS, cookie flags, admin panels and debug endpoints.

  • 05

    DNS Security

    10%

    Nameserver redundancy, DNSSEC, CAA, dangling records and zone transfer hygiene.

  • 06

    Brand Protection

    5%

    Typosquats, IDN homoglyphs and adverse-media signals that target your customers.

  • 07

    Breach Intelligence

    5%

    Known breach exposure, leaked credentials and dark-web flags tied to your domain.

  • 08

    Cloud & Infrastructure

    5%

    Open storage buckets, container registries and the WAF or CDN sitting in front.

  • 09

    Technology Intelligence

    5%

    Versioned tech fingerprinting cross-referenced against live CVE feeds.

  • 10

    Compliance & Governance

    5%

    Privacy policy, terms of service, cookie consent, security.txt and tracker count.

The score

0 to 100. Earned, not given.

Every asset starts at 100. Each finding deducts points proportional to its severity and category weight. The headline is the weighted average across all of your responsive hosts.

A

85-100

Very Low

Excellent posture. Nothing material on the outside.

B

70-84

Low

Solid baseline with minor hardening opportunities.

C

50-69

Medium

Material gaps that an opportunistic attacker would notice.

D

30-49

High

Serious issues. Likely to be exploited if left unchecked.

F

0-29

Critical

Catastrophic exposure. Treat as an active incident.

Red flags, score ceilings

Certain findings can never be averaged away. When one fires, we cap the headline and report both the cap and the trigger, every time, so weakness is never hidden behind a clean average.

  • 30CatastrophicAn exposed .env, an open database, or a public storage bucket caps the headline at 30.
  • 55SevereAn expired certificate or a critically vulnerable service caps the headline at 55.
  • 75SignificantA missing DMARC policy or weak transport posture caps the headline at 75.

How a scan runs

Six phases. Under five minutes.

Each scan progresses through six phases with live progress updates. Nothing is destructive, no authentication is required, and nothing is installed on your network.

  1. 01

    Preflight

    Validate the domain, load credentials, and allocate a worker tier sized to the target.

  2. 02

    Root Scan

    Run all twelve modules against the apex domain in parallel.

  3. 03

    Discovery

    Enumerate subdomains via threat-intel feeds and verify which ones respond.

  4. 04

    Asset Scan

    Re-run the appropriate module set against every responsive subdomain.

  5. 05

    Analysis

    Aggregate per-category scores, collect red flags, and apply ceilings.

  6. 06

    Report

    Persist the full report and stream it to the portal in real time.

2-4 min
Median scanFor a domain with 10 to 30 responsive hosts.
60 min
Hard ceilingLarge estates with 1,000+ subdomains.
2,000
Asset capSubdomains discovered per scan.

FAQ

Questions, answered.

Everything you need to know about how the DarkRisk scanner works and what it measures.

DarkRisk is a third-party risk management platform built around a non-intrusive, outside-in security scanner. It resolves every reachable asset a domain exposes, probes each one across ten risk categories, and rolls the results into a single 0 to 100 score with a letter grade.

No. The scanner is read-only and outside-in, so it inspects only what is publicly reachable. Nothing is installed, no authentication is required, and nothing destructive is ever run against your network.

A domain with 10 to 30 responsive hosts typically completes in two to four minutes. Large estates with over a thousand subdomains have a hard ceiling of 60 minutes, and each scan discovers up to 2,000 subdomains.

Every asset starts at 100. Each finding deducts points proportional to its severity and category weight, and the headline is the weighted average across all responsive hosts. Catastrophic findings apply a hard ceiling so a clean average can never hide an active exposure.

Yes. Because the assessment is entirely external, you can score any domain without the vendor's cooperation, credentials, or portal access, which is ideal for onboarding due diligence and continuous monitoring across your supply chain.

Certain findings, such as an exposed .env, an open database, an expired certificate, or a public storage bucket, can never be averaged away. A catastrophic finding caps the headline at 30, a severe finding at 55, and a significant finding at 75. We report the cap and the trigger every time.

Contact

Let's quantify the risk.

Tell us about your external risk surface and we'll get you set up. Every engagement starts with a conversation, so reach out and the DarkRisk team will take it from there.

hello@darkrisk.io