For anyone who gets asked security questions by buyers
A client asked for a security rating. This is what they will see.
Buyers increasingly run an external check before they send the questionnaire, and use it to decide what to probe. The findings become questions, and the questions arrive mid-sale.
When a prospective customer runs security due diligence on you, they use external checks — because that is all they have. This page shows what that view contains, so you can see your own organisation the way a buyer's procurement or security team will before they raise it in a questionnaire.
Why buyers check before they ask
Security questionnaires are slow and self-reported, so buyers increasingly run an external check first and use it to decide what to probe. That means the external view often shapes the conversation before you know it has started — and anything that looks wrong from outside becomes a question you have to answer under time pressure during a sale.
- The external check usually happens before the questionnaire, not after
- Findings become questions, and questions become delay
- You cannot correct an impression you never saw
What they can see without asking
Everything in this view is public. No access, no credentials and no permission are required, which is precisely why buyers rely on it.
- Transport security and certificate health, including certificates about to expire
- Email authentication, which tells them how easily someone could impersonate your staff
- Internet-exposed services and known vulnerabilities affecting them
- Whether credentials associated with your domain appear in public breach and infostealer data
- Domain registration details and how the domain is administered
What to fix before the next tender
Buyers rarely reject a supplier over a single finding. What damages you is a cluster of small, cheap, visible items, because together they read as a lack of routine care — and routine care is what the exercise is trying to assess.
- Certificates with short remaining life look like nobody is watching
- A weak or absent email policy is easy to spot and easy to fix
- Exposed services on forgotten hosts are the most damaging category, because they suggest nobody knows what is running
Common questions
›Is this the same check a buyer would run?
It reads the same class of public signals: transport security, email authentication, exposed services, breach exposure and domain administration. Buyers use various tools and weight them differently, but the underlying evidence is public and largely the same.
›Can we see what a supplier of ours looks like?
Yes, and that is a separate flow — this page is about your own outward view. The supplier-checking route is built for assessing someone else's domain before you sign with them.
›How often should we look at this?
Before any tender or renewal, and on a schedule otherwise. Certificates expire, new services appear, and breach data is published continuously, so a clean result has a shelf life.
Advisory only. This shows externally observable signals about a domain. It is not a security audit, not a certification, and it cannot see internal controls, contracts or processes.
Also useful: checking a supplier of your own.