All products

Technology & security risk report

SecureScope

A public-source technology and security risk baseline

Security questionnaires and vendor reviews ask what a counterparty's technology risk actually looks like — but the public evidence is scattered across filings, disclosures, and breach records, and nobody has time to assemble it.

$500one-time

Prefer an invoice? Request one below. Payment methods are listed with the price at the bottom of this page.

  1. Public-source scan

    Filings, disclosures, technical records, and enforcement history. Strictly passive — no testing or scanning.

  2. Framework benchmark

    Each observation maps to the control family it concerns.

  3. Report delivered

    Prioritized findings based on available public evidence, with severity, sources, and remediation paths. 5 business days.

Representative output

Illustrative
Medium severity

Third-party platform concentration — Galileo processing dependency

Evidence status
Confirmed — 10-K risk factors; disclosed ~23% platform-account decline
Affected obligation
NIST CSF 2.0 (ID.SC) · Operational resilience

Recommended action

Map fourth-party dependencies, require SOC 2 Type II, and document an exit / failover plan.

Select a framework to see what SecureScope examines against it from public evidence.

Restated from the public sample profile (SoFi Technologies — a public company, not a client). Your report reflects your own entity.

Who this is for

  • Security, risk, and vendor-management teams vetting a U.S. financial institution
  • Institutions that want an outside-in read of their own security posture before someone else takes one

When it lands on your desk

  • A vendor or counterparty review needs a defensible security baseline fast
  • A partner, client, or board asked for an independent read on technology risk
  • You want to see your own institution the way a diligence team would

The work

What SecureScope does

  • Scores technology and security risk from public evidence — availability, resilience, access, and breach exposure
  • Benchmarks observations against NIST CSF 2.0, ISO 27001, SOC 2, and DORA
  • Delivers prioritized risk findings with remediation paths and suggested owners
  • Records what public sources could not establish as explicit evidence gaps

What you provide

  • The institution's name and website
  • Nothing else — SecureScope is outside-in and uses no client documents

How the work is done

  • Entirely public-source: filings, disclosures, technical records, and enforcement history.
  • Framework-cited: each observation maps to the control family it concerns.
  • Every finding carries its evidence state; gaps are reported as gaps, not guesses.

Benchmarked against

  • NIST CSF 2.0
  • ISO 27001
  • SOC 2
  • DORA

Named standards and registers this product works from. Not a certification, attestation, or endorsement of any institution.

Deliverables

What you receive

  • Technology & security risk report with scored posture observations
  • Prioritized findings based on available public evidence, with severity, sources, and remediation paths
  • Framework benchmark against NIST CSF 2.0, ISO 27001, SOC 2, and DORA
  • Evidence-gap register for follow-up verification

Typical timing

Delivered in 5 business days. Flat fee, self-serve intake.

Benchmarked against

NIST CSF 2.0

  • Availability
  • Resilience
  • Access
  • Breach exposure

ISO 27001

  • Availability
  • Resilience
  • Access
  • Breach exposure

SOC 2

  • Availability
  • Resilience
  • Access
  • Breach exposure

DORA

  • Availability
  • Resilience
  • Access
  • Breach exposure

Every observation type is benchmarked against all four standards. A benchmark is a comparison, not a certification or attestation.

Start SecureScope

Name the institution and the decision this report supports — delivery is 5 business days from confirmed intake.

Company status

By submitting you consent to us contacting you about this request. Handled per our Privacy Policy and Trust Center.

Questions

SecureScope FAQ

Do you test or scan the target's systems?

No. SecureScope is strictly passive and public-source. It involves no penetration testing, scanning, or interaction with the subject's infrastructure.

Can we run it on an institution we don't control?

Yes — it uses only public information, so it works on any U.S. financial institution, including counterparties and vendors.

How is this different from a SOC 2 report?

A SOC 2 report is an auditor's attestation over an organization's own controls. SecureScope is an independent outside-in baseline built from public evidence — useful before, or in the absence of, an attestation. It does not replace one.

When is the fee final?

All sales are final once the report is generated. Payment methods are listed with the price at the bottom of this page.

What SecureScope is not

  • Not a penetration test, vulnerability scan, or any form of active technical testing.
  • Not a security certification, and not assurance over the subject's controls.
  • An outside-in baseline — internal controls may be stronger or weaker than public evidence shows.
  • Not legal, regulatory, audit, or compliance advice — your institution remains responsible for its own regulatory obligations.
  • Not an audit, audit opinion, control attestation, or certification of any kind.