DarkRisk

Use cases

One scanner, many jobs.

From onboarding a single vendor to watching an entire supply chain, DarkRisk turns an outside-in scan into the answer your team actually needs.

01

Third-Party Risk Management

Grade every vendor from the outside, without waiting on a questionnaire.

Questionnaires measure what a vendor claims. DarkRisk measures what an attacker can actually see. Score any supplier in minutes and keep that score current as their exposure changes.

Email us to get started
  • No cooperation required

    Because the assessment is entirely external, you can grade a vendor before they ever fill in a form, credential a portal, or reply to an email.

  • One number per vendor

    Each supplier collapses into a single 0 to 100 score with a letter grade, so risk owners can compare a portfolio at a glance.

  • Evidence, not opinions

    Every deduction ties back to a concrete finding on a named host, so the score is defensible when a vendor pushes back.

02

Attack Surface Management

See your own estate the way an attacker maps it.

Point DarkRisk at your own domain to discover every reachable asset, not just the ones you remember owning. Forgotten subdomains and dangling records are where incidents start.

Email us to get started
  • Full asset discovery

    Subdomain enumeration via DNS, certificate transparency, and threat-intel feeds finds the hosts your inventory missed.

  • Every host scanned

    We probe every responsive asset across ten categories, so shadow IT is graded with the same rigour as your flagship domain.

  • Prioritised by severity

    Red-flag findings surface first and cap the score, so the exposures that matter cannot hide behind a healthy average.

03

Vendor Due Diligence

Turn onboarding from weeks into minutes.

Run a scan before you sign. A DarkRisk grade gives procurement and security a shared, objective read on a prospective supplier long before the paperwork lands.

Email us to get started
  • Decide before you commit

    A full external assessment lands in under five minutes for a typical estate, so a low grade never becomes a surprise after contract.

  • Consistent scoring

    Every candidate is measured against the same ten categories with the same weights, so comparisons are fair and repeatable.

  • Shareable reports

    Findings are packaged into a report you can attach to the vendor record and hand to auditors without extra work.

04

Continuous Monitoring

A vendor's posture can change the day after you approve them.

Point-in-time assessments go stale fast. Re-scan on a schedule to catch the moment a certificate expires, a database is exposed, or a new subdomain appears.

Email us to get started
  • Always current

    Repeat scans keep every score fresh, so the grade you rely on reflects the exposure that exists today, not last quarter.

  • Change you can see

    Track a domain over time and watch the score move as findings are introduced or remediated.

  • Nothing to install

    Read-only and outside-in means no agents, no credentials, and no maintenance window for you or the vendor.

05

Security Ratings

One honest number, earned rather than given.

Every asset starts at 100 and loses points for each finding, weighted by category. The headline is the weighted average across all responsive hosts, with hard ceilings for catastrophic exposure.

Email us to get started
  • A to F grades

    Scores map to five bands from Very Low to Critical, so a rating reads instantly across security and non-technical stakeholders.

  • Weighted by impact

    Network, email, and transport carry the most weight, so the rating tracks the exposure attackers exploit most.

  • Ceilings, not averages

    A single catastrophic finding caps the headline, so a clean average can never paper over an active incident.

06

Compliance & Governance

Evidence your external posture on demand.

DarkRisk checks the public governance signals auditors ask about and packages the results into a report, so you can evidence diligence across your supply chain without a spreadsheet marathon.

Email us to get started
  • Governance signals

    Privacy policy, terms of service, cookie consent, security.txt, and tracker hygiene are all inspected and scored.

  • Audit-ready output

    Each scan persists a full report you can hand to auditors as evidence of continuous third-party diligence.

  • Repeatable process

    The same ten categories run every time, so your programme is consistent and easy to defend at review.

Same scanner, every time.

Whichever job you point it at, DarkRisk discovers every asset, inspects ten categories, and returns one honest score.

Explore the platform

Contact

Let's quantify the risk.

Tell us about your external risk surface and we'll get you set up. Every engagement starts with a conversation, so reach out and the DarkRisk team will take it from there.

hello@darkrisk.io