The platform
A non-intrusive, outside-in security scanner that grades your domain across ten risk categories in under five minutes, with no installation and no agents. We inspect a domain the way an attacker would, from the outside, and turn what they can see into one honest number.
Why DarkRisk
Questionnaires measure what a vendor claims. DarkRisk measures what an attacker can actually see, continuously, and without waiting on anyone.
We inspect a domain the way an attacker would, from the outside. No portal access, no cooperation from the vendor required.
A full external assessment lands in under five minutes for a typical estate. Skip the six-week questionnaire round-trip.
Non-intrusive and read-only. No agents, no credentials, no scheduled maintenance window. Nothing touches the internal network.
Every asset starts at 100 and loses points per finding. Red-flag exposures cap the headline so a clean average can't hide a crisis.
How it works
We resolve every reachable asset, probe each one across ten distinct risk categories, and roll the results into a single, honest score between 0 and 100.
Subdomain enumeration via DNS, certificate transparency, and threat-intel feeds. Every responsive host gets scanned, not just the apex.
Network, email, TLS, application, DNS, brand, breach, cloud, technology, and compliance signals, probed in parallel with strict timeouts.
Findings collapse into a single 0 to 100 score with a letter grade. Catastrophic findings cap the score, so weakness is never hidden.
What we check
Each category contributes a weighted slice of the final score. The bigger the weight, the more it moves the needle. Together they cover the surface an attacker sees without ever touching your internal network.
Open ports, exposed databases, DNS blacklist hits, SSH posture, cloud and PTR hygiene.
SPF, DMARC, DKIM, MTA-STS and BIMI, the controls that stop your brand being spoofed.
Certificate validity, key strength, protocol versions, HSTS and HTTPS enforcement.
Exposed secrets, security headers, CORS, cookie flags, admin panels and debug endpoints.
Nameserver redundancy, DNSSEC, CAA, dangling records and zone transfer hygiene.
Typosquats, IDN homoglyphs and adverse-media signals that target your customers.
Known breach exposure, leaked credentials and dark-web flags tied to your domain.
Open storage buckets, container registries and the WAF or CDN sitting in front.
Versioned tech fingerprinting cross-referenced against live CVE feeds.
Privacy policy, terms of service, cookie consent, security.txt and tracker count.
The score
Every asset starts at 100. Each finding deducts points proportional to its severity and category weight. The headline is the weighted average across all of your responsive hosts.
85-100
Very Low
Excellent posture. Nothing material on the outside.
70-84
Low
Solid baseline with minor hardening opportunities.
50-69
Medium
Material gaps that an opportunistic attacker would notice.
30-49
High
Serious issues. Likely to be exploited if left unchecked.
0-29
Critical
Catastrophic exposure. Treat as an active incident.
Red flags, score ceilings
Certain findings can never be averaged away. When one fires, we cap the headline and report both the cap and the trigger, every time, so weakness is never hidden behind a clean average.
How a scan runs
Each scan progresses through six phases with live progress updates. Nothing is destructive, no authentication is required, and nothing is installed on your network.
Validate the domain, load credentials, and allocate a worker tier sized to the target.
Run all twelve modules against the apex domain in parallel.
Enumerate subdomains via threat-intel feeds and verify which ones respond.
Re-run the appropriate module set against every responsive subdomain.
Aggregate per-category scores, collect red flags, and apply ceilings.
Persist the full report and stream it to the portal in real time.
FAQ
Everything you need to know about how the DarkRisk scanner works and what it measures.
DarkRisk is a third-party risk management platform built around a non-intrusive, outside-in security scanner. It resolves every reachable asset a domain exposes, probes each one across ten risk categories, and rolls the results into a single 0 to 100 score with a letter grade.
No. The scanner is read-only and outside-in, so it inspects only what is publicly reachable. Nothing is installed, no authentication is required, and nothing destructive is ever run against your network.
A domain with 10 to 30 responsive hosts typically completes in two to four minutes. Large estates with over a thousand subdomains have a hard ceiling of 60 minutes, and each scan discovers up to 2,000 subdomains.
Every asset starts at 100. Each finding deducts points proportional to its severity and category weight, and the headline is the weighted average across all responsive hosts. Catastrophic findings apply a hard ceiling so a clean average can never hide an active exposure.
Yes. Because the assessment is entirely external, you can score any domain without the vendor's cooperation, credentials, or portal access, which is ideal for onboarding due diligence and continuous monitoring across your supply chain.
Certain findings, such as an exposed .env, an open database, an expired certificate, or a public storage bucket, can never be averaged away. A catastrophic finding caps the headline at 30, a severe finding at 55, and a significant finding at 75. We report the cap and the trigger every time.
Contact
Tell us about your external risk surface and we'll get you set up. Every engagement starts with a conversation, so reach out and the DarkRisk team will take it from there.
hello@darkrisk.io