Third-Party Exposure Intelligence

Independent exposure intelligence before a vendor becomes your incident.

A human-led assessment of a prospective or existing third party using publicly observable and lawfully accessed intelligence to identify issues that deserve validation, contractual attention, or deeper technical review.

Pre-engagement premium report

Go beyond questionnaires and point-in-time claims.

Vendor questionnaires describe what a company says about itself. DarkWater’s assessment looks outward for evidence that may support, contradict, or add context to those claims. The result is an intelligence report—not a certification, penetration test, or guarantee of security.

Assessment depth can be tailored to business criticality, data access, operational dependency, geography, known concerns, and the client’s due-diligence process.

Assessment areas

Exposure signals reviewed in context—not dumped into a spreadsheet.

01

Corporate & Domain Mapping

Legal entity, public domains, subsidiaries, brands, acquisitions, leadership references, and relevant connected organizations.

02

External Exposure Indicators

Publicly observable internet-facing services, certificates, technology clues, and indicators of potential exposure or misconfiguration that warrant validation.

03

Credential Exposure

Company-domain credentials and related exposure signals available through sources lawfully accessed by DarkWater, with context and limitations.

04

Ransomware & Extortion History

Historical claims, leak-site references, publication status, known incident reporting, and evidence that may indicate data exposure.

05

Leaked Files & Metadata

Where lawfully available and approved, review filenames, file indexes, metadata, and selected content indicators for client-relevant exposure.

06

Extended Supply Chain

Third-party-of-third-party or fourth-party leads that may create inherited exposure, concentration, or operational risk.

Critical language

“Potentially exposed” is not the same as “confirmed vulnerable.”

DarkWater distinguishes passive and public intelligence from active technical validation. Findings involving internet-facing systems are reported as externally observable indicators that may warrant validation. No scanning, authentication, exploitation, or active testing is performed without explicit written authorization and a separately defined scope.

Report structure

  • Executive summary and overall exposure rating
  • Corporate and digital footprint map
  • Material findings with confidence and source context
  • Ransomware, credential, file, and supply-chain observations
  • Questions for the vendor and recommended next actions
  • Limitations, unresolved items, and monitoring recommendation

Initial client inputs

Enough information to identify the right company—not sensitive internal data.

  • Third-party legal or commonly used company name
  • Primary public website/domain
  • Country or operating geography
  • Nature and criticality of the proposed relationship
  • Known aliases, subsidiaries, or acquired brands, if available
  • Specific concerns, deadline, and intended audience

The public website may be used to submit the company name and public domain. Non-public architecture, vulnerability details, contracts, credentials, and confidential documents should not be submitted through the web form.

Optional recurring service

Third-Party Continuous Monitoring

After the baseline report, DarkWater can monitor defined domains, company names, ransomware and extortion references, credential exposure, material leaked-file indicators, and selected threat-source mentions.

Monitoring cadence, escalation, source categories, and report format are set in the engagement.

Third-party assessment

Submit a public company name and domain for high-level scoping.

DarkWater will confirm identity, objectives, legal fit, expected depth, delivery timing, and any continuous-monitoring needs before work begins.