Security and trust
What Cyber Health Score does not do
Product boundaries and claims the platform does not make.
- Audience
- All users
- Plan availability
- All plans
- Last reviewed
Clear product boundaries support trust. This page explains what Cyber Health Score should not be presented as doing.
Not a penetration-testing service
Cyber Health Score supports bounded External Attack Surface Management and safe external posture assessment. It is not a red-team platform, exploit framework, authenticated internal vulnerability scanner, or guarantee that every vulnerability will be found.
Cyber Health Score is not a penetration-testing service.
Not internet-wide scanning
Passive discovery starts from verified customer seeds and applies traversal bounds. It does not perform internet-wide scanning, full-ASN scanning, or unrestricted brute-force subdomain enumeration.
Not automatic active authority
Discovered hosts, IPs, services, CDN edges, SaaS providers, and ASN observations do not silently inherit active assessment authority. Continuous Assessment requires explicit consent and remains separately bounded.
Not compliance certification
Reports, Compliance Evidence, Evidence Vault and Configurable Reports support audit preparation and stakeholder review. They do not constitute ISO certification, PCI DSS approval, SOC 2 attestation, Cyber Essentials certification, or a guaranteed audit pass.
Not Supplier Assurance scanning authority
Recording a supplier in Supplier Assurance does not authorise Cyber Health Score to actively assess that supplier.
Not inferred Authorised Validation
Continuous Assessment consent never grants Authorised Validation authority. Authorised Validation remains explicit, time-bound and fail-closed.
Not unrestricted support access
Support access is tenant-consented, scoped, time-bound, revocable, and audited. It is not unlimited internal access without customer visibility.
Not proof of live payments in every environment
Billing uses Stripe. The current deployment may run with paid checkout held until commercial authorisation. Treat live commercial payment claims as environment-specific unless separately verified.
Not a promise of zero risk
No security product can promise zero false positives, zero false negatives, zero breaches, or zero downtime. Cyber Health Score improves visibility, prioritisation, and communication around external posture within declared boundaries.
Practical takeaway
The most credible description is a Production External Attack Surface Management platform for verified external posture visibility, confidence-aware vulnerability intelligence, prioritised remediation, and stakeholder-ready evidence within clear product boundaries.
Related documentation
Related documentation
Return to the documentation home to browse all topics.
Back to documentation