External attack surface
Inventory, passive discovery with provenance, change detection and graph context. Discoveries beneath verified roots do not consume root allowance, and supplier domains do not grant active authority.
In page detailCyber Health Score platform
Cyber Health Score is an integrated External Trust Platform, not two standalone products. Start with verified external posture and authorised simulations, then keep the same signal connected through findings, remediation, evidence, supplier assurance and reporting within declared authority boundaries.
Auctoritas programme
The Auctoritas programme ships as one candidate from Continuum through Satya: continuous exposure operations, relationship intelligence, adaptive trajectory, approval gated operator actions, trust and assurance, brand intelligence, workflow fabric, portfolio command and hardening. No single surface defines the platform by itself. A clean assessment means no supported issue was detected at the time of assessment, not guaranteed security.
Discover and understand
Establish what is externally visible and how assets relate, within verified scope and without implying active authority.
Inventory, passive discovery with provenance, change detection and graph context. Discoveries beneath verified roots do not consume root allowance, and supplier domains do not grant active authority.
In page detailCyber Digital Twin temporal reads that explain how assets relate without inventing attack path certainty. Advisory only.
In page detailLookalike observation, potential impersonation and requires review states for third party domains. A lookalike is not automatically phishing or confirmed impersonation.
In page detailAssess and prioritise
Translate external signals into ordered, owned work while keeping observation, inference and recommendation separate.
Assessment Operations, Change Intelligence and curated exposure events within authorised scope. Reconciliation checks for due work are not a full tenant scan on that interval.
How CHS worksSeverity ordered findings, ownership, exposure context and an evidence backed remediation workflow. Workflow resolution remains distinct from technical verification.
Review findingsObservation, inference and recommendation stay separate. Cadence hints suggest earlier review where warranted but never create new assessment authority.
How CHS worksAct and validate
Run authorised activity with explicit, bounded and revocable authority. Guidance never executes remediation for you.
Explicit, target bounded, method bounded and time bounded validation authority that is revocable, auditable and fail closed. Off by default with platform and tenant emergency stop.
Security boundariesTenant scoped, read only workspace assistant for posture, findings and evidence. Guidance is bounded and never executes remediation or changes workflow state.
In page detailAlerts, email and webhook destinations, signed delivery, durable export and scoped API access under fail closed defaults. Secrets are never exposed in the view.
Platform showcaseAssure and demonstrate
Keep evidence, readiness and reporting connected to the same source of truth. Assurance readiness is not certification.
Evidence Vault, compliance evidence and configurable reports with freshness, review and restricted handling made explicit. Assurance readiness is not certification.
Evidence Vault overviewControls, ownership and readiness self assessment mapped to findings and evidence. Governance does not automatically certify controls.
Platform showcaseBuild tailored reports from approved workspace data with versioned publish workflow. Reporting is a point in time view, not a live guarantee.
Configurable reports overviewCommand and connect
Operate across teams and, where granted, across an explicit portfolio without inferred cross organisation access.
Enterprise portfolio view with explicit authorised grants. Cross organisation access is never inferred from email domain, shared asset or billing convenience.
In page detailSupplier register, assurance workflow, questionnaires and concentration insight. Commercial relationships do not authorise active supplier scanning, and declarations remain declared until corroborated.
Supplier assuranceThe platform does not offer penetration test services, unrestricted exploitation, complete vulnerability detection, certification or unrestricted ASM, and it does not guarantee complete detection. Supplier Assurance and Portfolio Command operate within explicit authority boundaries and declared states where applicable.
Entry points
External posture assessment for verified domains
Authorised email-based phishing simulations
Next steps
Compare Free, Plus, Pro, and Business plans for your organisation.
View pricingTalk to us about Business rollout or a wider platform footprint.
Contact salesSee your external posture clearly.
Create a workspace with your organisation email and begin with verified scope.