Remote third-party cyber due diligence
Third-Party Exposure Snapshot
A rapid external intelligence review of a vendor, partner, acquisition target, law firm, service provider, or other company before risk becomes your problem.
Single-company and portfolio scopes available
Review areas
What can be learned without accessing the third party’s systems.
- Company identity, primary domains, subsidiaries, and relevant brand references
- Historical ransomware, extortion, and public breach references
- Credential and information-stealer exposure signals where lawfully available
- Publicly observable internet-facing assets and indicators requiring validation
- Exposed repositories, documents, filenames, and metadata references
- Executive or brand impersonation indicators where relevant
- Potential fourth-party or extended supply-chain leads
Standard scope
- Target1 company
- Primary domain1
- Related domainsUp to 2
- Target turnaround5 business days
- DeliverableExecutive summary + action questions
- Client interactionEmail-only available
Best use cases
Fast external context before a decision or after a warning sign.
Pre-contract review
Identify questions the business should raise before giving a vendor access to data or systems.
Renewal or acquisition
Reassess a critical relationship when the business, ownership, or risk profile changes.
Ransomware claim
Understand whether a public criminal claim or leaked-file publication appears relevant.
Vendor incident
Organize external signals and next questions while the vendor’s own investigation continues.
One company. One report.
