SOC 2 Type II reportIndependent report · Aug 12, 2026
Request required⌄CURRENTVendor risk assessment software
Assess vendor risk.
Prove it with evidence.
Monitor public cyber exposure, publish a free trust center, and answer unlimited security questionnaires from one evidence-backed workspace.
Free · No credit card · Your first assessment takes about a minute
EXAMPLE COMPANY PROFILE
Northstar Systems
One profile. Every security review.
Built for the people who ask, answer, and stand behind security questions.
01 / LIVE PRODUCT TOUR
Watch trust move
from proof to answer.
Scroll through the workflows your team and your buyers actually use. Every scene mirrors the current RiskAssure app.
PRODUCT WORKFLOWTRUST PROFILE
TRUST PROFILE
Establish trust before the first question.
EXAMPLE COMPANY PROFILENorthstar Systems
LOW RISKRiskAssure IndexIllustrative · 5 of 8 shown
DOMAIN VERIFIEDnorthstar.systems
TRUST PROFILE
Establish trust before the first question.
EVIDENCE LIBRARY
Put every claim on approved evidence.
CITED Q&A
Give buyers answers they can verify.
QUESTIONNAIRE REVIEW
Move from upload to reviewed response.
FREE Unlimited questionnaires Human approval before sharing
02 / FREE TRUST CENTER
FREE FOR EVERY VENDORKnow your exposure.
Prove your security.
RiskAssure combines outside-in breach-risk visibility with a controlled security trust center—so your team can fix what buyers see, share approved evidence, and move every questionnaire forward.
Northstar SystemsSecurity Trust Center
✓Access grantedVerified buyer session
Review current security posture, company-approved evidence, and cited answers in one buyer-ready workspace.
✓ Domain ownership verified · 12 approved sourcesPublic files open immediately. Sensitive reports remain controlled.
Outside-in breach visibility
- External asset and domain visibility
- Vulnerability and patch signals
- Dark web and leak monitoring
- Risk ratings and remediation context
Buyer-ready security assurance
- Controlled security trust center
- Approved evidence content library
- Access and NDA protection
- Unlimited questionnaire imports and responses
03 / HOW IT WORKS
See the whole workflow.
Get the hours back.
Watch RiskAssure turn approved security evidence into cited answers, reviewed questionnaires, an explainable score, and a buyer-ready trust center.
RiskAssure launch filmOne governed evidence trail, from first question to shared proof.
FOR VENDORS
Answer once.
Prove it everywhere.
Turn approved security work into a free, buyer-ready source of truth built for unlimited questionnaires.
- 01 Correct and control your company profile
- 02 Keep public signals separate from verified evidence
- 03 Share documents with scoped access
- 04 Complete unlimited questionnaires at no cost
FOR BUYERS
See the evidence.
Own the decision.
Move from a generic outside-in score to a review shaped by your relationship and risk appetite.
- 01 Compare observable posture and approved proof
- 02 Ask questions with source-backed context
- 03 Track findings, conditions, and review dates
- 04 Build a defensible review record
04 / THE RISKASSURE INDEX
A rating should
show its work.
The RiskAssure Index brings eight component scores into one view. Each covers a different dimension of observable cyber risk—from exposed technology and control hygiene to breach signals, third-party dependence, and company context.
Read common questionsEight component scores
Observed signals · Context · Coverage
Vulnerability
Observable technical exposureFinds known vulnerabilities and exposed services on public-facing assets that can be confidently tied to the company.
Looks at CVEs · exposed services · software versions · asset attribution
Context: No observed finding does not prove an asset is vulnerability-free.
Security Posture
External control hygieneAssesses how securely the public-facing stack is configured across transport, domain, email, and browser protections.
Looks at TLS · DNS · SPF / DKIM / DMARC · HTTP security headers
Context: Observable configuration does not verify how internal controls operate.
Dark Web
Breach and credential exposureChecks monitored breach and leak sources for company-linked credentials, records, and incident evidence.
Looks at breach datasets · credential leaks · domain matches · recency
Context: No match reflects available sources and coverage—not proof of no exposure.
Third-Party
Connected ecosystem riskIdentifies observable vendors and service providers, then considers the risk they introduce to the company’s external footprint.
Looks at identified vendors · assessment coverage · provider posture · relationship confidence
Context: Inferred relationships should be verified before they drive action.
Breach Prediction
Forward-looking risk signalEstimates future breach likelihood from current observable posture, exposure patterns, and available incident history.
Looks at current factors · incident history · exposure trends · risk indicators
Context: This is a forecast, not a guarantee; confidence falls when data is limited.
Reputation
Public security contextAnalyzes credible security-related reporting and incident coverage associated with the company.
Looks at article volume · source credibility · recency · coverage tone
Context: Public reporting adds context; it is not technical proof of a control or breach.
Firmographic
Business risk contextUses company characteristics to place observed risk in context, including size, age, industry, and security resources.
Looks at employee count · company age · industry · security staffing
Context: Firmographics provide context and do not measure security performance directly.
IP Reputation
Attributable network behaviorChecks company-controlled public IP addresses against public threat blocklists and abuse intelligence.
Looks at domain resolution · IP attribution · blocklist matches · abuse history
Context: Shared CDN or cloud addresses are excluded; this component may be not measured.
Coverage is part of the result. Limited data, no finding, and not measured are three different states—and RiskAssure labels them that way.
05 / WHITE-LABEL PARTNERS
Your brand. Every client's trust center.
Launch a buyer-ready trust center with your logo, colors, custom domain, and a clear “Secured by Your Company” endorsement. Your brand secures the experience while every client keeps its name, evidence, access, and account.
See the partner experience
Your CompanySecurity evidence, ready when buyers ask.
Northstar Systems keeps its verified evidence, access controls, and ownership inside an experience secured by Your Company.
06 / TRUST BY DESIGN
Clear signals.
Clear boundaries.
Cyber risk intelligence is useful only when people can understand its scope, challenge its findings, and see where the evidence came from.
Passive by default
No active vulnerability testing without explicit authorization.
Claim status shown
Unclaimed profiles are clearly separated from domain-verified company information.
Every score explained
Material findings include context, freshness, and a path to correction or dispute.
Evidence stays distinct
Company-approved proof builds assurance without silently rewriting the public Index.
07 / COMMON QUESTIONS
Understand the signal before you use it.
Plain-language answers about company risk ratings, profile claiming, and third-party risk reviews.
01What is a cyber risk rating?+
A cyber risk rating is a point-in-time view of a company’s observable security posture. The RiskAssure Index organizes public signals into eight component dimensions and pairs the score with source context, freshness, and a plain-language risk tier.
02Does a high RiskAssure Index mean a vendor is approved?+
No. The public Index is an outside-in signal, not a certification or purchasing decision. Buyers should evaluate it alongside approved first-party evidence, inherent risk, contracts, compensating controls, and their own risk appetite.
03What changes when a company claims its profile?+
A domain-verified company can review its profile, request corrections, add approved security evidence, publish its free trust center, and complete unlimited security questionnaires. Claimed status identifies an owner; it does not erase the distinction between public signals and first-party evidence.
04Is the RiskAssure Trust Center really free?+
Yes. The RiskAssure Trust Center is free and includes unlimited security questionnaires, an approved content library, controlled evidence sharing, and access and NDA protection. Buyer-side assessments and other managed risk services are separate from the vendor’s free trust center.
05Does RiskAssure actively test a company’s systems?+
The public rating is designed around passive, outside-in signals. Active security testing should only occur with explicit authorization. Every material finding should be presented with its source date, scope, and limitations.
06How can advisers use RiskAssure with clients?+
Auditors, vCISOs, MSPs, MSSPs, security firms, and privacy advisers can help clients organize approved evidence and launch buyer-ready trust centers while the client retains ownership of its account, data, and access decisions.
START WITH A SIGNAL
