Finding it
Open a vendor, go to Vendor Intelligence, and pick the Security tab.
1 Overall rating and grade. 2 Rating over time. 3 Per-factor breakdown, with the findings behind each score.
The rating is a floor, not a verdict
Everything measured here is visible from the public internet. That is its strength and its limit in one. A strong rating means the things an attacker can see from outside are in order. It says nothing about what happens inside the vendor’s network, how they manage access, or whether they have a working incident process. Those questions need an assessment. A weak rating is more actionable in the other direction. A monitor-only DMARC policy or an expired certificate is a fact, not an inference, and you can raise it with the vendor immediately.Read the factors, then the number
The overall rating is a weighted roll-up. The factor breakdown underneath it is where the decisions live. Each factor expands to show the specific observations behind its score, so a low number always resolves to something concrete: a hostname, a header, a certificate, a CVE. That distinction matters when you are writing up an assessment. “Not measured” belongs in the questions you ask the vendor, not in the findings you record against them.Open a finding to get the fix
Click any finding in a factor to open it.
A finding opened from the Email authentication factor, showing what was observed and the step that resolves it.
- Impacts rating tells you whether this finding actually cost points, and how many. A finding recorded for completeness that moved nothing says No, which saves you chasing a number that never changed.
- First seen and Last seen tell you how long it has been open. A finding that has survived months has been seen by the vendor’s own team too.
- Observed is the raw value the scan read, such as
p=noneorTLSv1.0. - Remediation is the step that resolves it, written for whoever operates the asset rather than for you.
Raise findings from what the scan found
Raise finding on an open finding creates a tracked finding against the vendor, pre-filled with the asset, the observed value and the scan date, so it stands on its own once it leaves Coverbase. When a sweep turns up the same problem across a dozen hosts, use Generate findings at the top of the page instead.
Every scored issue, ticked by default, ordered by severity.
Rating over time
Each point is a restatement of the whole rating. A step change usually means a scan found something new rather than the vendor changing overnight, so read the factors before drawing a trend.Attack surface
What is reachable from the internet under the vendor’s domains: hosts, exposed services and open ports. A large surface is not automatically a finding; it is context for the rest of the page. Transport checks run per host rather than only against the vendor’s main domain, so one neglected server does not hide behind a well-configured front door.
Each attributed host handshaken separately, with its own chain, protocol and expiry.
Attributed estate
The scan works out which domains and addresses belong to the vendor from certificate transparency logs and public scan data, then measures each one. Attributed Estate is that list, and it is where you correct what the scan got wrong.
Every asset the scan attributes to this vendor, filtered by what still needs a decision.
Something is listed that is not theirs
Shared hosting, a reseller, or a product the vendor buys rather than runs. Open the row’s actions menu and choose Dispute. The next scan skips that asset entirely, and its findings leave the rating. Choose Confirm when you have checked an asset and it is theirs. That records the decision so nobody re-reviews it, and it does not change the rating.Something they run is missing
The scan only finds hosts that appear in a public certificate, so an internal host, or one the vendor never published a certificate for, never shows up on its own.
Adding the hosts the scan cannot discover on its own, in one go.
999.1.1.1 is rejected rather than accepted as a hostname, which would otherwise put an asset in the estate that can never resolve.
Email authentication
SPF, DKIM and DMARC as actually published. What matters is the policy, not merely the presence of a record: a DMARC record set tonone monitors and enforces nothing, and an SPF record ending in +all authorizes the entire internet to send as that domain.