> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coverbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Financial health and security intelligence guide

> How to read the Financial Health Score and Security Posture cards in a vendor's Vendor Intelligence section, what each number is actually claiming, and what to do about what you find.

<Info>
  This guide is part of the [User Guides](/user-guides/overview) collection. It covers the two scored cards in a vendor's Vendor Intelligence section. For the product-level explanation of where the data comes from, see [Financial Health Score](/products/financial-health-score) and [Security Intelligence](/products/security-intelligence); for the corporate identity both are computed against, [Vendor Intelligence](/products/vendor-intelligence).
</Info>

<Note>
  These are optional features currently in beta. If you don't see the cards described here, let your Coverbase representative know you'd like them turned on.
</Note>

Two cards in Vendor Intelligence carry a score rather than a description: **Coverbase Financial Health Score** and **Security Posture**. Both are assembled without contacting the vendor: one from regulatory filings and registries, the other from the vendor's own public infrastructure.

This guide is about reading them correctly. Both cards are designed to be checkable, and the most common mistake with either is treating a number as more certain than the card says it is.

## Start with the qualifier, not the number

Every score on these cards ships with something that tells you how much weight it can bear. Read that first, every time.

<CardGroup cols={2}>
  <Card title="Financial health: the confidence tier" icon="layer-group">
    **A** means filed financial statements. **B** means estimates. **C** means no financials at all, so the score was inferred from funding, headcount, and corporate standing. The tier is derived from what actually resolved, never declared.
  </Card>

  <Card title="Security: what was measured" icon="circle-question">
    Factors that could not be measured are excluded from the rating rather than scored as failures. A card showing eight of eleven factors is rating what it could see, and says so.
  </Card>
</CardGroup>

<Warning>
  Financial health scores are only comparable **within** a tier. A Tier C 72 and a Tier A 72 are different claims about different evidence. Never rank a Tier A vendor against a Tier C vendor on the score alone. Build your vendor list, filter to one tier, then compare.
</Warning>

## Working the financial health card

<Steps>
  <Step title="Check the tier and the trend together">
    A Tier A score with 12-month movement is the strongest signal on the page. A Tier C score is a starting point for questions, not a conclusion. If a vendor you know to be public is sitting at Tier C, that usually means no filings resolved. Check the Corporate Registration card to see whether SEC EDGAR is listed as unavailable.
  </Step>

  <Step title="Open the rationale on the weakest pillar">
    The pillar breakdown shows five scores. Open the rationale on the lowest one and you'll see the individual inputs, each with its measured value, its own score, and the weight it carried.

    Watch for inputs labelled as undeterminable rather than measured. A pillar dragged down by a value nobody could establish is a very different finding from one dragged down by a ratio that is genuinely bad.
  </Step>

  <Step title="Check whether the inputs were peer-ranked">
    A ratio only means something against a comparable set: 4x debt/EBITDA reads very differently at a utility than at a software company. Inputs scored against the vendor's own industry cohort are labelled as peer-ranked. Those scored against an absolute curve are not, and deserve more scepticism.

    When a cohort is too small to support a percentile, the score falls back to a wider group and the card says so.
  </Step>

  <Step title="Read the adverse events, including the dismissed ones">
    Events are weighted by severity and decay over time. Events awaiting confirmation are labelled **Needs review**. Confirm or dismiss them, because an unconfirmed event is still counting against the score. Dismissed events stay on the record for audit but stop affecting the number.
  </Step>

  <Step title="Check the as-of dates before you quote a figure">
    Filed figures lag. Each input carries the date its value was true, which is not the date of the refresh. Quoting a revenue figure to a stakeholder without its as-of date is the fastest way to lose the room.
  </Step>
</Steps>

## Working the security posture card

<Steps>
  <Step title="Read the grade, then the factor breakdown">
    The overall grade is a weighted mean across eleven factors. It is useful for triage and misleading on its own: a B can hide an F in email security under strong scores elsewhere. Scan the factor list for the outliers.
  </Step>

  <Step title="Open the rationale on any factor that grades poorly">
    Each finding names what was observed, where, and what it cost. These are concrete: `p=none` on the DMARC record, `1024-bit` on DKIM selector `selector1`, a session cookie set without `HttpOnly`.

    Everything here is a public record you or the vendor can verify independently. That is what makes it usable in a conversation.
  </Step>

  <Step title="Check how long the finding has been open">
    A finding carries the date it was first seen. This is the field that changes the conversation. A weak key that appeared last week is an oversight. One that has stood open for eleven months has been seen by the vendor's own team and left in place. That is a decision, and it tells you something about how they run security that no questionnaire answer will.
  </Step>

  <Step title="Compare the rating against the predictive index">
    The rating asks how well the vendor is configured. The predictive index asks how likely something is to happen soon, based on known-exploited vulnerabilities, exploitation probability, and ransomware association.

    When they diverge, believe the divergence. A well-configured vendor running one product with an actively exploited CVE needs attention its letter grade won't prompt.
  </Step>

  <Step title="Turn a finding into a question, not an accusation">
    The useful move is specific and verifiable: "your DMARC record is `p=none`, so mail forged from your domain still gets delivered. Is enforcement on the roadmap?"

    That is a fact about a published record, it takes the vendor thirty seconds to confirm, and it converts a generic security review into an answerable question.
  </Step>
</Steps>

## What these cards will not tell you

<Warning>
  A clean external security profile is **not** evidence of good internal security. Everything on the Security Posture card is visible from outside the perimeter. It says nothing about access control, key management, secure development, incident response, or how the vendor handles your data once it is inside their systems.
</Warning>

The same applies to financial health in a different direction: the score describes the corporate entity Coverbase bound to the vendor. If a vendor is a subsidiary and the filings belong to the parent, the score describes the parent's balance sheet, not the entity on your contract. Check the Corporate Registration card to see which legal entity was matched.

## Opening the full page

Each card summarises. Behind it sits a full page with the same data and far more of it, reached from **View full analysis** on the card or from the two entries nested under **Vendor Intelligence** in the vendor's left-hand navigation.

<CardGroup cols={2}>
  <Card title="Security posture" icon="shield-halved">
    The rating as a headline figure with its grade and band, plotted against the rating bands over time. Every scored factor is grouped and expandable down to the individual findings that cost it points, each with the record it read and how long it has been open.

    Then a section per class of evidence: known vulnerabilities ordered by whether attackers are actually exploiting them rather than by severity alone; the internet-facing attack surface; email authentication; web and transport hardening; credential exposure from third-party breaches; lookalike domains; web reputation; and which sources the scan used or skipped.
  </Card>

  <Card title="Financial health" icon="chart-line">
    The score with its confidence tier and peer standing, plotted against the risk bands over time with tier changes called out.

    All five pillars expand to the measured inputs behind them, alongside a chart ranking where the points are actually going, because a weak pillar carrying 5% of the weight matters far less than a middling one carrying 40%. Below that: the full vitals set grouped as a credit reviewer reads it, the debt maturity schedule, the peer benchmark, the event timeline, and every source with any cap or floor that was applied.
  </Card>
</CardGroup>

<Tip>
  The full pages have their own URLs, so a specific vendor's security posture or financial health can be linked directly into a ticket or an email.
</Tip>

## Common questions

<AccordionGroup>
  <Accordion title="The vendor is public but shows Tier C. Why?" icon="circle-question">
    Tier C means no financial statements resolved. Open the Corporate Registration card and look at the sources: if SEC EDGAR is listed as unavailable, no CIK was matched. That usually means the vendor's name on file differs from its registered legal name. Correcting the vendor's name and refreshing Vendor Intelligence normally resolves it.
  </Accordion>

  <Accordion title="A security factor is missing from the breakdown." icon="circle-minus">
    It could not be measured on the last run, so it was excluded from the rating rather than scored as a failure. This is deliberate: a probe that timed out is not evidence about the vendor. It will reappear on a later refresh if the vendor's infrastructure answers.
  </Accordion>

  <Accordion title="The security score moved and nothing changed at the vendor." icon="arrows-up-down">
    Two things can cause this. A factor that was previously unmeasurable may now be measurable (or the reverse), which changes what the weighted mean is averaging over. And when your organization first enables the feature, the rating switches from seven factors to eleven with new weights, so expect a one-time shift at that point.
  </Accordion>

  <Accordion title="Can I dispute a finding?" icon="flag">
    Every finding names the record it read, so start by checking it yourself; a DNS record or a response header takes a moment to verify. If the record has changed since the last refresh, trigger a Vendor Intelligence refresh and the finding will clear on its own. If you believe the reading itself is wrong, raise it with your Coverbase representative with the vendor domain and the finding.
  </Accordion>

  <Accordion title="How often do these refresh?" icon="rotate">
    Both refresh on the regular Vendor Intelligence cadence, and on any manual refresh you trigger from the vendor. Score history is kept as discrete points (one per day at most), so the trend line reflects separate computations rather than a smoothed curve.
  </Accordion>
</AccordionGroup>

## Where else this data shows up

Neither card is an island. Once enabled, both feed the rest of the platform:

* **Assessments** consult measured posture and registry facts as authoritative evidence, ranked ahead of any web result. A control asking about email authentication gets answered from the vendor's actual DNS records rather than from a marketing page.
* **Intake and inherent risk** score a new vendor request against its registered identity and measured posture before the web is consulted.
* **MCP** exposes both conversationally: "what's the financial health score for Acme?", "which of my vendors have DMARC set to none?"
* **The API** returns both on the vendor fact-sheet endpoint (the route name predates the Vendor Intelligence label). See the [API reference](/api-reference/vendors#vendor-intelligence-sections).
