Observe the external edge
Connect domains, exposed services and configuration signals to the verified assets they describe.
- Domain and asset discovery
- DNS health and email security posture
- Transport and exposed service signals
Cyber Health Score connects discovery, authorised assessment, prioritisation, remediation, verification and assurance so every score has context and every improvement has proof. It does not certify compliance or guarantee security.
Verified root
northbridge.example
Observe
12 signals
Attribute
6 assets
Prioritise
4 actions
Discover
Map the verified external estate and meaningful change.
Assess
Run authorised exposure assessment within declared scope.
Assure
Demonstrate trust with evidence freshness and review state.
Cyber Health Score keeps observation, priority, action and proof connected, so teams can explain what they saw, what they changed and what a completed reassessment confirmed.
Follow the evidence trailWhere context is lost
Disconnected checks make it difficult to see which external exposures matter most.
Findings, owners and remediation evidence often live in separate systems.
Leadership needs more than a closed task to understand whether exposure changed.
Connect domains, exposed services and configuration signals to the verified assets they describe.
Turn completed assessment observations into a clear order of work using severity, exposure and organisational context.
Keep remediation, supporting evidence, completed reassessment and stakeholder reporting in one traceable sequence.
Cyber Health Score connects meaningful external change, authorised continuous assessment and remediation verification so teams can manage exposure as an ongoing practice, not a one-off scan.
Focus on externally visible changes that matter for posture, not every raw observation.
See cadence, due work and authorised scope clearly. Reconciliation checks for due work are not the same as scanning every asset on that interval.
Request an authorised targeted recheck when remediation is ready, then keep before and after evidence with the outcome.
One connected External Trust Platform keeps the verified subject, observed signal, priority, approved action, verification and assurance evidence in view. Choose a stage to inspect what changes and what remains bounded. No certification claims. No guaranteed security outcomes.
Build and maintain a structured view of your organisation's externally visible attack surface. Identify assets, detect surface changes and understand what is publicly observable.
| Asset | Type | Status | Changes |
|---|---|---|---|
| example.com | Domain | Verified | - |
| vpn.example.com | Host | Review | New |
| api.example.com | Host | Verified | - |
| mail.example.com | Host | Verified | - |
| staging.example.com | Host | Candidate | New |
Illustrative sample data. Example organisations and assets are fictional.
Discovery, assurance, governance and reporting use the same verified asset, authority and evidence language across the workspace.
Alert rules, email and webhook destinations with delivery monitoring.
Controls, Evidence Vault and compliance-evidence workflows.
Candidate and similarity signals for brand observations within your attack surface.
Contextual CVE and KEV information where supported to help prioritise findings.
Conservative percentile context within eligible CHS organisations.
Bounded external assessments plus the AI-Powered Social Engineering Evaluator for authorised campaigns.
Authenticated, tenant-scoped, read-only assistant for supported workspace information.
Connected by design
Every capability returns to posture, action or proof.
Move from posture to findings, governance, evidence and reporting without losing the verified asset or organisational context behind the decision.
Cyber Health Score
Completed assessments produce a Cyber Health Score with category context so teams can see overall posture at a glance.
Posture overview. Illustrative Cyber Health Score for Northbridge Labs
Fiducia brings Supplier Assurance into the workspace so teams can register suppliers, track reviews, request evidence and understand dependency concentration. A commercial relationship never automatically authorises active assessment of supplier infrastructure.
Relationship metadata only by default. Active supplier scanning is not introduced in this release.
Supplier Assurance is not a complete vendor-risk assessment platform, and questionnaire responses are not independently verified unless supporting evidence has been reviewed.
Explore platform capabilitiesIllustrative sample only. Not live supplier data and not a complete vendor-risk assessment.
Illustrative campaign metrics only. Not live tenant data.
Run controlled, authorised email-based phishing simulations to help teams recognise and respond to suspicious email. Campaign workflows include recipient setup, preview, delivery tracking, education pages, and reporting within your workspace.
Record what changed, attach supporting evidence, reassess the exposure, and communicate the outcome. Evidence is the proof. Reporting communicates the result.
Attach supporting files, screenshots, or configuration exports directly to a finding's remediation record. Evidence is scoped to the finding and visible in generated reports.
Attaching a document does not automatically prove compliance or resolution. Verification through reassessment is a separate step.
Generate technical and executive reports from within your workspace. Different report types suit different audiences, from detailed findings to high-level progress summaries.
CHS is designed for organisations that take data responsibility seriously.
Each organisation operates within its own isolated workspace. Data is not shared between tenants.
Access within your workspace is controlled by role. Invite team members with appropriate permissions.
Multi-factor authentication is supported to protect access to your organisation workspace.
Activity within your workspace is logged. Review history supports governance and accountability requirements.
Support access to your workspace is scoped and controlled. You remain in control of your data.
Reports can be shared securely with stakeholders where the feature is supported by your workspace plan.
Start with domain posture assessment and grow as your requirements expand.
£0 / month
Understand your current external posture.
£79 / month
£790 / year(same monthly entitlements)
Continuous external security for smaller organisations.
£199 / month
£1,990 / year(same monthly entitlements)
Advanced EASM for growing security programmes.
Contact sales
Scaled security, assurance, and contractual requirements.
Not sure which plan suits your organisation? Contact sales or view full pricing.
Understand your exposure. Prioritise what matters. Demonstrate progress.
Based on completed assessments of verified assets. Not real-time monitoring or penetration testing.