One number, built from six categories of check. How it is put together is set out below. What each individual signal is worth is not, because publishing that would let someone tune their score without fixing anything.
Signals are collected from search indexes, service fingerprinting, threat classification and breach-pattern matching, then verified by language models before a person reviews anything serious. Scoring runs continuously against every enrolled subject, categorized, and alertable in a live dashboard. Nothing surfaces to your counter-parties that we haven't already flagged to you.
Risk bands are calibrated against a representative North American small and medium business baseline. A score of 0 indicates no detectable external exposure across monitored sources. Scores are point-in-time assessments and will change as new breaches are disclosed, infrastructure is modified, or intelligence feeds are updated.
A single check turns up dozens of separate observations. Each is sorted, weighted by how much damage that kind of thing has actually caused, and folded into one number between 0 and 100. Categories below are listed in order of typical contribution. Credential and infrastructure findings carry the most weight because they represent the most direct paths to compromise.
Confirmed presence of domain-linked credentials in breach databases, paste sites, and dark web monitoring. Higher weight reflects that exposed credentials translate to direct account compromise.
Misconfigurations, missing security controls, and exploitable weaknesses on externally visible infrastructure. Findings are weighted by severity, with criticals carrying substantially higher impact than informational notes.
Domain or IP correlation with malware activity, phishing campaigns, abuse reports, and known exploitable vulnerabilities. Each correlation indicates active or recent threat activity rather than theoretical risk.
Shadow IT, leaked credentials in public code, lookalike domains, and unmonitored assets that extend the attack surface beyond what an organization typically tracks.
Government breach notification filings, fraud alert correlations, and consumer protection records that indicate prior incidents or active enforcement attention.
A baseline contribution applied to entities verified in public business registries, ensuring confirmed organizations register a non-zero score that reflects discoverability by threat actors.
The weight of each individual signal stays private. If those numbers were public, anyone wanting a better-looking score could work to the numbers instead of fixing what is exposed. The framework above is sufficient to interpret any score we publish.
Monitors breach databases, dark web repositories, and paste sites for exposed credentials linked to the assessed domain.
Evaluates externally visible infrastructure for misconfigurations, missing security controls, and exploitable weaknesses.
Cross-references domain and IP data against threat intelligence feeds, malware engines, and reputation databases.
Searches federal and state databases for breach notifications, fraud alerts, and corporate registration data.
Analyses historical records to identify changes in infrastructure, ownership, and security position over time.
Identifies shadow IT, code leaks, and exposure vectors that extend beyond the primary domain.
Asks live AI assistants and search panels the questions a client asks, and checks each answer against what your own site publishes.
Protector Class Intelligence