Skip to main content
Cyber Health Score
Get started

Cyber Health Score platform

One platform. One evidence trail.

Cyber Health Score is an integrated External Trust Platform, not two standalone products. Start with verified external posture and authorised simulations, then keep the same signal connected through findings, remediation, evidence, supplier assurance and reporting within declared authority boundaries.

Auctoritas programme

Discover, understand, assess, prioritise, act, verify, assure.

The Auctoritas programme ships as one candidate from Continuum through Satya: continuous exposure operations, relationship intelligence, adaptive trajectory, approval gated operator actions, trust and assurance, brand intelligence, workflow fabric, portfolio command and hardening. No single surface defines the platform by itself. A clean assessment means no supported issue was detected at the time of assessment, not guaranteed security.

Discover and understand

Discover and understand

Establish what is externally visible and how assets relate, within verified scope and without implying active authority.

External attack surface

Inventory, passive discovery with provenance, change detection and graph context. Discoveries beneath verified roots do not consume root allowance, and supplier domains do not grant active authority.

In page detail

Relationship intelligence

Cyber Digital Twin temporal reads that explain how assets relate without inventing attack path certainty. Advisory only.

In page detail

Brand and impersonation intelligence

Lookalike observation, potential impersonation and requires review states for third party domains. A lookalike is not automatically phishing or confirmed impersonation.

In page detail

Assess and prioritise

Assess and prioritise

Translate external signals into ordered, owned work while keeping observation, inference and recommendation separate.

Continuous exposure operations

Assessment Operations, Change Intelligence and curated exposure events within authorised scope. Reconciliation checks for due work are not a full tenant scan on that interval.

How CHS works

Findings and remediation

Severity ordered findings, ownership, exposure context and an evidence backed remediation workflow. Workflow resolution remains distinct from technical verification.

Review findings

Adaptive assessment and trajectory

Observation, inference and recommendation stay separate. Cadence hints suggest earlier review where warranted but never create new assessment authority.

How CHS works

Act and validate

Act and validate

Run authorised activity with explicit, bounded and revocable authority. Guidance never executes remediation for you.

Authorised validation

Explicit, target bounded, method bounded and time bounded validation authority that is revocable, auditable and fail closed. Off by default with platform and tenant emergency stop.

Security boundaries

CHS Agent

Tenant scoped, read only workspace assistant for posture, findings and evidence. Guidance is bounded and never executes remediation or changes workflow state.

In page detail

Workflows and integrations

Alerts, email and webhook destinations, signed delivery, durable export and scoped API access under fail closed defaults. Secrets are never exposed in the view.

Platform showcase

Assure and demonstrate

Assure and demonstrate

Keep evidence, readiness and reporting connected to the same source of truth. Assurance readiness is not certification.

Evidence and assurance fabric

Evidence Vault, compliance evidence and configurable reports with freshness, review and restricted handling made explicit. Assurance readiness is not certification.

Evidence Vault overview

Governance

Controls, ownership and readiness self assessment mapped to findings and evidence. Governance does not automatically certify controls.

Platform showcase

Configurable reports

Build tailored reports from approved workspace data with versioned publish workflow. Reporting is a point in time view, not a live guarantee.

Configurable reports overview

Command and connect

Command and connect

Operate across teams and, where granted, across an explicit portfolio without inferred cross organisation access.

Portfolio Command

Enterprise portfolio view with explicit authorised grants. Cross organisation access is never inferred from email domain, shared asset or billing convenience.

In page detail

Supplier assurance

Supplier register, assurance workflow, questionnaires and concentration insight. Commercial relationships do not authorise active supplier scanning, and declarations remain declared until corroborated.

Supplier assurance

The platform does not offer penetration test services, unrestricted exploitation, complete vulnerability detection, certification or unrestricted ASM, and it does not guarantee complete detection. Supplier Assurance and Portfolio Command operate within explicit authority boundaries and declared states where applicable.

Entry points

Start with what is observable and authorised.

Purpose built entry points for the external signals your team needs to understand first. Scope and authority stay explicit throughout. These feed the broader platform above.

Next steps

Plans and next steps

See your external posture clearly.

Create a workspace with your organisation email and begin with verified scope.

Start free