Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This guide is part of the User Guides collection. It covers the two scored cards in a vendor’s Vendor Intelligence section. For the product-level explanation of where the data comes from, see Financial Health Score and Security Intelligence; for the corporate identity both are computed against, Vendor Intelligence.
These are optional features currently in beta. If you do not see the cards described here, ask your Coverbase representative to turn them on.
Two cards in Vendor Intelligence carry a score rather than a description: Coverbase Financial Health Score and External Security Intelligence. Both are assembled without contacting the vendor: one from regulatory filings and registries, the other from the vendor’s own public infrastructure. This guide is about reading them correctly. Both cards can be checked against their sources, and the most common mistake is treating a number as more certain than the card says it is.

Start with the qualifier, not the number

Every score on these cards comes with a qualifier that tells you how much to trust it. Read that first.

Financial health: the confidence tier

A means filed financial statements. B means estimates. C means no financials at all, so the score was inferred from funding, headcount, and corporate standing. The tier is derived from what resolved, never declared.

Security: what was measured

Factors that could not be measured are excluded from the rating rather than scored as failures. A card showing eight of eleven factors is rating what it could see, and says so.
Scores are held to a common scale across tiers, so ranking a portfolio on the number is reasonable. The tier still says how much evidence stands behind each one: a Tier C 72 and a Tier A 72 are different claims about different evidence. Before you act on a surprising score, check its tier.

Working the financial health card

1

Check the tier and the trend together

A Tier A score with 12-month movement is the strongest signal on the page. A Tier C score is a starting point for questions, not a conclusion. If a vendor you know to be public is sitting at Tier C, that usually means no filings resolved. Check the Corporate Registration card to see whether SEC EDGAR is listed as unavailable.
2

Open the rationale on the weakest pillar

The pillar breakdown shows five scores. Open the rationale on the lowest one and you will see the individual inputs, each with its measured value, its own score, and the weight it carried.Watch for inputs labeled as undeterminable rather than measured. A pillar dragged down by a value nobody could establish is a different finding from one dragged down by a bad ratio.
3

Check whether the inputs were peer-ranked

A ratio only means something against a comparable set: 4x debt/EBITDA reads very differently at a utility than at a software company. Inputs scored against the vendor’s own industry cohort are labeled as peer-ranked. Those scored against an absolute curve are not, and deserve more skepticism.When a cohort is too small to support a percentile, the score falls back to a wider group and the card says so.
4

Read the adverse events, including the dismissed ones

Events are weighted by severity and decay over time. Events awaiting confirmation are labeled Needs review and do not move the score until they are confirmed. An event that is about another company can be dismissed from the full Financial page with Revise from notes or evidence. Dismissed events stay on the record for audit but stop affecting the number.
5

Check the as-of dates before you quote a figure

Filed figures lag. Each input carries the date its value was true, which is not the date of the refresh. Quote the as-of date alongside any figure you pass on.

Working the security posture card

1

Read the grade, then the factor breakdown

The overall grade is a weighted mean across eleven factors. It is useful for triage and misleading on its own: a B can hide an F in email security under strong scores elsewhere. Scan the factor list for the outliers.
2

Open the rationale on any factor that grades poorly

Each finding names what was observed, where, and what it cost. These are concrete: p=none on the DMARC record, 1024-bit on DKIM selector selector1, a session cookie set without HttpOnly.Everything here is a public record you or the vendor can verify independently. That is what makes it usable in a conversation.
3

Check how long the finding has been open

A finding carries the date it was first seen. A weak key that appeared last week is an oversight. One that has stood open for eleven months has probably been seen by the vendor’s own team and left in place, which says something about how they run security.
4

Compare the rating against the predictive index

The rating asks how well the vendor is configured. The predictive index asks how likely something is to happen soon, based on known-exploited vulnerabilities, exploitation probability, and ransomware association.When they diverge, act on the index. A well-configured vendor running one product with an actively exploited CVE needs attention its letter grade will not prompt.
5

Turn a finding into a question, not an accusation

A useful question is specific and verifiable: “your DMARC record is p=none, so mail forged from your domain still gets delivered. Is enforcement on the roadmap?”That is a fact about a published record. The vendor can confirm it quickly, and it turns a generic security review into an answerable question.

What these cards will not tell you

A clean external security profile is not evidence of good internal security. Everything on the External Security Intelligence card is visible from outside the perimeter. It says nothing about access control, key management, secure development, incident response, or how the vendor handles your data once it is inside their systems.
The same applies to financial health in a different direction: the score describes the corporate entity Coverbase bound to the vendor. If a vendor is a subsidiary and the filings belong to the parent, the score describes the parent’s balance sheet, not the entity on your contract. Check the Corporate Registration card to see which legal entity was matched.

Opening the full page

Each card summarizes. Behind it sits a full page with the same data and far more of it, reached from View full analysis on the card or from the Security and Financial entries nested under Vendor Intelligence in the vendor’s left-hand navigation.

Security posture

The rating as a headline figure with its grade and band, plotted against the rating bands over time. Every scored factor is grouped and expandable down to the individual findings that cost it points, each with the record it read and how long it has been open.Then a section per class of evidence: known vulnerabilities ordered by whether attackers are exploiting them rather than by severity alone; the internet-facing attack surface; email authentication; web and transport hardening; credential exposure from third-party breaches; lookalike domains; web reputation; and which sources the scan used or skipped.

Financial health

The score with its confidence tier and peer standing, plotted against the risk bands over time with tier changes called out.All five pillars expand to the measured inputs behind them, alongside a chart ranking where the points are going, because a weak pillar carrying 5% of the weight matters far less than a middling one carrying 40%. Below that: the full vitals set grouped as a credit reviewer reads it, the debt maturity schedule, the peer benchmark, the event timeline, and every source with any cap or floor that was applied.
The full pages have their own URLs, so a specific vendor’s security posture or financial health can be linked directly into a ticket or an email.

Common questions

Tier C means no financial statements resolved. Open the Corporate Registration card and look at the sources: if SEC EDGAR is listed as unavailable, no CIK was matched. That usually means the vendor’s name on file differs from its registered legal name. Correcting the vendor’s name and refreshing Vendor Intelligence normally resolves it.
It could not be measured on the last run, so it was excluded from the rating rather than scored as a failure. A probe that timed out is not evidence about the vendor. It will reappear on a later refresh if the vendor’s infrastructure answers.
Two things can cause this. A factor that was previously unmeasurable may now be measurable (or the reverse), which changes what the weighted mean is averaging over. And when your organization first enables the feature, the rating switches from seven factors to eleven with new weights, so expect a one-time shift at that point.
Every finding names the record it read, so start by checking it yourself; a DNS record or a response header takes a moment to verify. If the record has changed since the last refresh, trigger a Vendor Intelligence refresh and the finding will clear on its own. If a finding or vulnerability is not about this vendor, open the full Security page, pick Revise from notes or evidence from the actions menu (…), and paste why. The change applies to your organization only. See the security intelligence guide.
Both refresh on the regular Vendor Intelligence cadence, and on any manual refresh you trigger from the vendor. Score history is kept as discrete points (one per day at most), so the trend line reflects separate computations rather than a smoothed curve.

Where else this data shows up

Once enabled, both feed the rest of the platform:
  • Assessments consult measured posture and registry facts as authoritative evidence, ranked ahead of any web result. A control asking about email authentication gets answered from the vendor’s DNS records rather than from a marketing page.
  • Intake and inherent risk score a new vendor request against its registered identity and measured posture before the web is consulted.
  • MCP exposes both conversationally: “what’s the financial health score for Acme?”, “which of my vendors have DMARC set to none?”
  • The API returns both on the vendor fact-sheet endpoint (the route name predates the Vendor Intelligence label). See the API reference.

Financial health guide

The full Financial health page, pillar by pillar.

Security intelligence guide

The full Security page, including the attributed estate.

Corporate registrations guide

The legal entity both scores are computed against.