Remote third-party cyber due diligence

Third-Party Exposure Snapshot

A rapid external intelligence review of a vendor, partner, acquisition target, law firm, service provider, or other company before risk becomes your problem.

Single-company and portfolio scopes available

Review areas

What can be learned without accessing the third party’s systems.

  • Company identity, primary domains, subsidiaries, and relevant brand references
  • Historical ransomware, extortion, and public breach references
  • Credential and information-stealer exposure signals where lawfully available
  • Publicly observable internet-facing assets and indicators requiring validation
  • Exposed repositories, documents, filenames, and metadata references
  • Executive or brand impersonation indicators where relevant
  • Potential fourth-party or extended supply-chain leads

Standard scope

  • Target1 company
  • Primary domain1
  • Related domainsUp to 2
  • Target turnaround5 business days
  • DeliverableExecutive summary + action questions
  • Client interactionEmail-only available

Best use cases

Fast external context before a decision or after a warning sign.

Pre-contract review

Identify questions the business should raise before giving a vendor access to data or systems.

Renewal or acquisition

Reassess a critical relationship when the business, ownership, or risk profile changes.

Ransomware claim

Understand whether a public criminal claim or leaked-file publication appears relevant.

Vendor incident

Organize external signals and next questions while the vendor’s own investigation continues.

One company. One report.

Request a third-party snapshot with a public company name and domain.

Start Request