Solutions
Vendor Security Score (SecOps Score)
Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.
TL;DR
A vendor security score is a rating computed from findings observable from the outside: DNS and TLS configuration, exposure surface, HTTP headers, presence in known data breaches. It does not replace a declarative assessment, but it dates it and sometimes contradicts it — and it costs the vendor no effort.
What is a vendor security score?
A posture score is a summary rating computed from technical signals observable from the outside, without access to the third party's information system. CISAPP's SecOps score therefore gives an immediate reading of a vendor's technical maturity — not a self-declaration.
What the score measures
| Dimension | Signal observed | What it indicates |
|---|---|---|
| DNS | Exposed records and configuration | Domain management hygiene |
| TLS | Versions, ciphers, certificate validity | Configuration maintenance |
| Exposure surface | Publicly reachable services | Breadth of the attack surface |
| Data breaches | Presence in known breaches | Credential exposure |
| HTTP headers | Security headers present or missing | Attention paid to web good practice |
History keeps the score's evolution over time, with the findings attached to each scan.
A score that serves both sides
On the company side, the score prioritises reviews and reminders on the most exposed vendors. On the vendor side, a score visible from the My exposure workspace becomes a commercial argument with its own customers — it can run a scan and track its improvement before sharing it.
See also the vendor security questionnaire and vendor risk management.
FAQ
It is a summary rating of a third party's security posture, computed from technical signals observable from the outside, without access to its information system. It gives a dated, comparable reading where a questionnaire gives a statement.
Sources
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours