For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
The SecurityScorecard connector is a licensed rating connector: you bring your own SecurityScorecard subscription, and Coverbase reads your portfolio with your credentials. It works like the Black Kite integration. Ratings land on the vendor’s Certificates tab under Licensed Ratings, and changes become Radar signals.
What it does
- Provisions monitoring once. The first time you save credentials, Coverbase adds one SecurityScorecard source to Radar and one detector on it, named for a security score drop. Both are created once. Archiving the source stops monitoring, and saving new credentials later does not bring it back.
- Matches companies to vendors. Each company in your portfolio is matched to a vendor by a match recorded on an earlier pull, then by its domain (walking up to the parent domain, never down), then by its exact legal name. A company that matches no vendor is skipped.
- Records the rating. Each pull records the matched vendor’s Security Score (0 to 100).
- Signals only on change. A Radar item is raised only when a stored rating moved. The first pull is a baseline, so connecting a provider does not flood Radar.
The detector
The detector starts enabled, alerting on a drop of 5 points or more between pulls. Edit it like any other Radar detector. It has three gates, and at least one must be set. A rating change alerts only when it passes every gate that is set. Minimum drop and Alert below take zero or more, in the provider’s own units.
Alerts go through the ordinary Radar path, so reassessment triggers and monitoring plan signal rules see them like any other signal.
Authentication
SecurityScorecard issues an API key. Coverbase sends it asAuthorization: Token <key> to https://api.securityscorecard.io, lists your portfolios from /portfolios, and reads each portfolio’s companies.
- In SecurityScorecard, create an API key for a user who can read your portfolios.
- Note the ID of the portfolio to read, if you want only one.
Set up in Coverbase
- Open Configuration → External Integrations and click SecurityScorecard.
- Enter API Token, and optionally Account ID (a portfolio ID; leave it blank to read every portfolio the key can see). The panel notes: “Saving the key adds a SecurityScorecard source to Radar. Leave the account ID blank to read every portfolio.”
- Click Save, then Test connection.
- Open Radar to find the new source and its detector.
Related
Certificate Vault guide
Where licensed ratings show on a vendor.
Working Radar signals
Triaging the signals a rating change raises.
Monitoring plans
Letting a rating drop pull monitoring forward.
Security intelligence guide
Coverbase’s own outside-in rating, which needs no subscription.