Skip to main content
Cyber Health Score
Get started

Security and trust

What Cyber Health Score does not do

Product boundaries and claims the platform does not make.

Audience
All users
Plan availability
All plans
Last reviewed

Clear product boundaries support trust. This page explains what Cyber Health Score should not be presented as doing.

Not a penetration-testing service

Cyber Health Score supports bounded External Attack Surface Management and safe external posture assessment. It is not a red-team platform, exploit framework, authenticated internal vulnerability scanner, or guarantee that every vulnerability will be found.

Cyber Health Score is not a penetration-testing service.

Not internet-wide scanning

Passive discovery starts from verified customer seeds and applies traversal bounds. It does not perform internet-wide scanning, full-ASN scanning, or unrestricted brute-force subdomain enumeration.

Not automatic active authority

Discovered hosts, IPs, services, CDN edges, SaaS providers, and ASN observations do not silently inherit active assessment authority. Continuous Assessment requires explicit consent and remains separately bounded.

Not compliance certification

Reports, Compliance Evidence, Evidence Vault and Configurable Reports support audit preparation and stakeholder review. They do not constitute ISO certification, PCI DSS approval, SOC 2 attestation, Cyber Essentials certification, or a guaranteed audit pass.

Not Supplier Assurance scanning authority

Recording a supplier in Supplier Assurance does not authorise Cyber Health Score to actively assess that supplier.

Not inferred Authorised Validation

Continuous Assessment consent never grants Authorised Validation authority. Authorised Validation remains explicit, time-bound and fail-closed.

Not unrestricted support access

Support access is tenant-consented, scoped, time-bound, revocable, and audited. It is not unlimited internal access without customer visibility.

Not proof of live payments in every environment

Billing uses Stripe. The current deployment may run with paid checkout held until commercial authorisation. Treat live commercial payment claims as environment-specific unless separately verified.

Not a promise of zero risk

No security product can promise zero false positives, zero false negatives, zero breaches, or zero downtime. Cyber Health Score improves visibility, prioritisation, and communication around external posture within declared boundaries.

Practical takeaway

The most credible description is a Production External Attack Surface Management platform for verified external posture visibility, confidence-aware vulnerability intelligence, prioritised remediation, and stakeholder-ready evidence within clear product boundaries.

Return to the documentation home to browse all topics.

Back to documentation