Best-in-class security posture.
No critical exposures, no exploitable CVEs, full TLS 1.3 / HSTS / DNSSEC, zero leaked credentials, and a complete history of remediated findings. Reserved for the top decile of scanned organisations.
One letter, seven tiers, and a verifiable badge system that turns continuous scanning into something a board, an underwriter, and a procurement team can all read at a glance.
No critical exposures, no exploitable CVEs, full TLS 1.3 / HSTS / DNSSEC, zero leaked credentials, and a complete history of remediated findings. Reserved for the top decile of scanned organisations.
Minor low-severity findings only. Patching cadence under 14 days, encryption everywhere, no known leaks. Trusted for enterprise procurement without further questionnaires.
Good coverage on encryption and headers with occasional medium issues. A few services exposed or TLS slightly behind best practice. Trusted for standard procurement with routine review.
Some medium-severity issues — outdated TLS suites, missing security headers, or one or two exposed services. Safe to do business with, but a remediation plan is expected.
Multiple medium issues or one high-severity exposure (e.g. expired certificates, weak SPF/DMARC, public admin panels). Engage only with compensating controls and a clear 30-day remediation SLA.
High-severity CVEs, leaked credentials in the wild, or unauthenticated services exposed to the internet. Active risk of compromise — treat as a security incident, not a procurement decision.
Critical vulnerabilities, breach indicators, or evidence of active exploitation. Insurance carriers will decline; enterprise buyers will exit. Immediate, hands-on remediation required.
Every signal carries a base weight, an exploitability multiplier, and a recency decay — so a fresh, KEV-listed CVE moves your score more than a stale informational header.
Badges are not marketing decorations — each one is cryptographically signed, time-stamped, and auto-revokes if your posture slips. Embed them or link to your trust page.
Domain ownership confirmed and signed by SecurityRating.com.
Complete domain verification (DNS TXT or HTTP file).
Daily external scans across 100+ signals; drift alerts within 15 minutes.
Active paid subscription with monitoring enabled.
Mapped controls satisfy at least one major framework (SOC 2, ISO 27001, NIS2, NESA, PDPL).
All control mappings for one framework pass for 30 consecutive days.
Sits in the top 10% of all rated organisations in its industry.
Score and posture stability in the 90th percentile for 90 days.
Score has risen by 10+ points in the last 90 days.
Continuous remediation with verified evidence of fixes.
Posture meets carrier underwriting criteria for preferred pricing.
Grade A or above plus no high/critical findings for 60 days.
No leaked credentials, secrets, or PII detected across the dark web in 12 months.
Clean dark-web intelligence sweep across all monitored identities.
Public posture page published with current grade and last-scanned timestamp.
Opt in to publish a securityrating.com/p/<your-domain> trust page.
Run a free, non-intrusive scan of any domain. We return a letter grade, the signals behind it, and a prioritised remediation list — no signup, no credit card.