Skip to main content
Cyber Health Score
Get started
External Trust Platform

See your external edge. Turn signals into evidence.

Cyber Health Score connects discovery, authorised assessment, prioritisation, remediation, verification and assurance so every score has context and every improvement has proof. It does not certify compliance or guarantee security.

  1. 01

    Discover

    Map the verified external estate and meaningful change.

  2. 02

    Assess

    Run authorised exposure assessment within declared scope.

  3. 03

    Assure

    Demonstrate trust with evidence freshness and review state.

01
Externally observable assessment
Based on publicly accessible information and completed assessments
02
Prioritised findings
Ordered by severity, exposure, and organisational context
03
Evidence-backed remediation
Record what changed, attach evidence, and verify improvement
04
Stakeholder-ready reporting
Technical and executive outputs for different audiences
05
Secure multi-tenant workspace
Tenant-isolated data, role-aware access, and audit history
The evidence gap

Security work fragments when the evidence trail disappears.

Cyber Health Score keeps observation, priority, action and proof connected, so teams can explain what they saw, what they changed and what a completed reassessment confirmed.

Follow the evidence trail

Where context is lost

01

Signals without context

Disconnected checks make it difficult to see which external exposures matter most.

02

Action without continuity

Findings, owners and remediation evidence often live in separate systems.

03

Progress without proof

Leadership needs more than a closed task to understand whether exposure changed.

One connected system

Observe. Prioritise. Prove.

01

Observe the external edge

Connect domains, exposed services and configuration signals to the verified assets they describe.

  • Domain and asset discovery
  • DNS health and email security posture
  • Transport and exposed service signals
02

Prioritise with context

Turn completed assessment observations into a clear order of work using severity, exposure and organisational context.

  • Severity-ordered findings
  • Score and category context
  • Ownership and overdue visibility
03

Prove what changed

Keep remediation, supporting evidence, completed reassessment and stakeholder reporting in one traceable sequence.

  • Evidence-backed remediation
  • Completed reassessment
  • Technical and executive reporting
Continuous exposure operations

Keep watching what changed, then prove the response.

Cyber Health Score connects meaningful external change, authorised continuous assessment and remediation verification so teams can manage exposure as an ongoing practice, not a one-off scan.

01

Detect meaningful change

Focus on externally visible changes that matter for posture, not every raw observation.

02

Operate continuous assessment

See cadence, due work and authorised scope clearly. Reconciliation checks for due work are not the same as scanning every asset on that interval.

03

Verify the fix

Request an authorised targeted recheck when remediation is ready, then keep before and after evidence with the outcome.

Auctoritas product loop

Discover, understand, assess, prioritise, act, verify, assure.

One connected External Trust Platform keeps the verified subject, observed signal, priority, approved action, verification and assurance evidence in view. Choose a stage to inspect what changes and what remains bounded. No certification claims. No guaranteed security outcomes.

01Discover

Know what is exposed.

Build and maintain a structured view of your organisation's externally visible attack surface. Identify assets, detect surface changes and understand what is publicly observable.

  • Asset Inventory
  • Passive Discovery
  • Change Detection
  • Attack Surface Graph
  • Brand Protection
  • External Exposure Visibility

Illustrative sample data. Example organisations and assets are fictional.

Platform depth

Specialist capabilities, one evidence model.

Discovery, assurance, governance and reporting use the same verified asset, authority and evidence language across the workspace.

01

Alerts and Integrations

Alert rules, email and webhook destinations with delivery monitoring.

02

Governance and Evidence

Controls, Evidence Vault and compliance-evidence workflows.

03

Brand Protection

Candidate and similarity signals for brand observations within your attack surface.

04

Vulnerability Intelligence

Contextual CVE and KEV information where supported to help prioritise findings.

05

Privacy-Safe Benchmarking

Conservative percentile context within eligible CHS organisations.

06

Assessments and ASPE

Bounded external assessments plus the AI-Powered Social Engineering Evaluator for authorised campaigns.

07

CHS Agent

Authenticated, tenant-scoped, read-only assistant for supported workspace information.

Connected by design

Every capability returns to posture, action or proof.

Inside the workspace

Keep the subject in view as the work changes.

Move from posture to findings, governance, evidence and reporting without losing the verified asset or organisational context behind the decision.

Cyber Health Score

See your external security posture in one prioritised score.

Completed assessments produce a Cyber Health Score with category context so teams can see overall posture at a glance.

  • Overall Cyber Health Score with category breakdown
  • Score movement after completed assessments
  • Severity-ordered findings summarised alongside posture
Explore security scans

Posture overview. Illustrative Cyber Health Score for Northbridge Labs

Supplier Assurance
Available

Supplier inventory, assurance workflow and third-party risk context

Fiducia brings Supplier Assurance into the workspace so teams can register suppliers, track reviews, request evidence and understand dependency concentration. A commercial relationship never automatically authorises active assessment of supplier infrastructure.

Relationship metadata only by default. Active supplier scanning is not introduced in this release.

  • Maintain a supplier register with ownership and criticality
  • Track assurance reviews, evidence requests and questionnaires
  • Understand shared-provider concentration and service dependencies
  • Summarise assurance factors with clear source attribution

Supplier Assurance is not a complete vendor-risk assessment platform, and questionnaire responses are not independently verified unless supporting evidence has been reviewed.

Explore platform capabilities
Supplier assurance summaryIllustrative
Example infrastructure provider
example-infra.co.uk
Medium
4 observationsLast reviewed Sample date
Example managed IT provider
example-managed.co.uk
Low
2 observationsLast reviewed Sample date
Example SaaS platform
example-saas.io
Review
7 observationsLast reviewed Sample date

Illustrative sample only. Not live supplier data and not a complete vendor-risk assessment.

ASPE campaign dashboardAuthorised
Sample awareness exercise
Illustrative · sample participants
Complete
48
Sent
17
Clicked
31
Did not click

Illustrative campaign metrics only. Not live tenant data.

ASPE

AI-Powered Social Engineering Evaluator (ASPE)

Run controlled, authorised email-based phishing simulations to help teams recognise and respond to suspicious email. Campaign workflows include recipient setup, preview, delivery tracking, education pages, and reporting within your workspace.

Authorised email campaign workflows
Plan email simulations scoped to participants you configure
Controlled email delivery
Configurable intensity, timeline, and email scenario context
Delivery and click reporting
De-duplicated click engagement metrics from your campaign dashboard
Post-simulation education
Education pages help explain missed signals after a simulation
Evidence & Reporting

Move beyond a list of findings

Record what changed, attach supporting evidence, reassess the exposure, and communicate the outcome. Evidence is the proof. Reporting communicates the result.

1
Finding
Observation from completed assessment
2
Remediation
Work recorded, ownership assigned
3
Evidence
Supporting document attached
4
Reassessment
Exposure verified by next assessment
5
Verified outcome
Confirmed improvement recorded
6
Report
Communicated to relevant audience

Evidence records

Attach supporting files, screenshots, or configuration exports directly to a finding's remediation record. Evidence is scoped to the finding and visible in generated reports.

  • Linked to specific finding
  • Verification state tracked
  • Visible in report output
  • Maintained as audit history

Attaching a document does not automatically prove compliance or resolution. Verification through reassessment is a separate step.

Reports

Generate technical and executive reports from within your workspace. Different report types suit different audiences, from detailed findings to high-level progress summaries.

  • Technical report with full finding detail
  • Executive summary with score and trend
  • Evidence package for audit preparation
  • Secure sharing where supported
Security & trust

Built with responsible data handling in mind

CHS is designed for organisations that take data responsibility seriously.

Tenant isolation

Each organisation operates within its own isolated workspace. Data is not shared between tenants.

Role-aware access

Access within your workspace is controlled by role. Invite team members with appropriate permissions.

MFA support

Multi-factor authentication is supported to protect access to your organisation workspace.

Audit history

Activity within your workspace is logged. Review history supports governance and accountability requirements.

Scoped support access

Support access to your workspace is scoped and controlled. You remain in control of your data.

Secure report sharing

Reports can be shared securely with stakeholders where the feature is supported by your workspace plan.

Plans

Plans for every stage

Start with domain posture assessment and grow as your requirements expand.

For organisations getting started

Free

£0 / month

Understand your current external posture.

  • 1 monitored root domain
  • 3 assessments per month
  • Argus external posture visibility within Free bounds
  • 1 lifetime ASPE evaluation up to 100 recipients
  • Current posture and supported security findings
  • Bounded Free history
Start free
Most popular
For smaller organisations

Plus

£79 / month

£790 / year(same monthly entitlements)

Continuous external security for smaller organisations.

  • 3 monitored root domains
  • 15 assessments per month
  • Recursive Argus monitoring with provenance
  • Vulnerability intelligence, CISA KEV, and EPSS
  • Exposure Priority and in-app Alerts
  • Remediation workflow
  • 90-day history target
  • Bounded self-service reports
  • 1 ASPE campaign per month
  • 100 recipients per campaign
  • Tenant Agent (rate limited)
  • Standard support
Create free workspace
For growing security programmes

Pro

£199 / month

£1,990 / year(same monthly entitlements)

Advanced EASM for growing security programmes.

  • 15 monitored root domains
  • 60 assessments per month
  • Full available Argus intelligence within Pro limits
  • Vulnerability intelligence, CISA KEV, and EPSS
  • Exposure Priority, Alerts, and full remediation workflow
  • 180-day history target
  • Full self-service reports
  • 5 ASPE campaigns per month
  • 250 recipients per campaign
  • Tenant Agent
  • Priority support positioning where operationally supported
Create free workspace
For contractual scale and assurance

Business

Contact sales

Scaled security, assurance, and contractual requirements.

  • Custom monitored root domain scale
  • Contract-configured assessment volume
  • Contract-configured ASPE campaigns and recipients
  • Contract-configured retention and support where supported
  • Support access policy and grant controls where supported
Contact sales

Not sure which plan suits your organisation? Contact sales or view full pricing.

FAQ

Common questions

More detail is available in our documentation.

Get started today

Make your external cyber posture easier to understand and improve.

Understand your exposure. Prioritise what matters. Demonstrate progress.

Based on completed assessments of verified assets. Not real-time monitoring or penetration testing.

  • No intrusive testing
  • Verified assets only
  • Your data stays in your workspace