External vendor risk intelligence

Verify vendor exposure from the outside.

Aegisnode gives security and TPRM teams a fast way to scan vendor-facing domains, validate security claims, and turn external evidence into remediation-ready reports.

External exposure Domains, services, TLS, DNS, CVEs, and risky configuration drift.
Vendor claims Compare questionnaire or website claims against observable scan evidence.
Continuous review Track changes, export evidence, and route findings into risk workflows.
Vendor exposure report
acme-supplier.example
72
Finding Exposed admin service
High
Evidence TLS certificate, open port, service banner
Verified
Vendor claim "No public administrative interfaces"
Contradicted

Evidence is organized for vendor follow-up, internal review, and audit trails.

Scan

Vendor risk workflow

From domain to defensible evidence.

Use Aegisnode when a vendor assessment needs more than a questionnaire answer. Scan what is exposed, verify what is claimed, and keep a record of what changed.

01

Add a vendor

Start with a domain, IP, or vendor-facing asset set. No agent install required.

02

Scan exposure

Map open services, certificates, DNS posture, security headers, and correlated CVEs.

03

Verify claims

Compare vendor statements against external evidence and flag what is confirmed or contradicted.

04

Track remediation

Export findings, monitor drift, and keep risk decisions tied to observable proof.

What gets checked

External signals that matter to TPRM teams.

Aegisnode focuses on evidence a security reviewer can validate, explain, and send back to a vendor.

Attack surface discovery

Find internet-facing services and unexpected exposure across vendor domains and IPs.

TLS and DNS posture

Review certificates, record hygiene, takeover risk, mail security, and trust configuration.

Vulnerability context

Correlate observed services with known CVEs and prioritize findings by severity.

Evidence-backed reports

Export readable summaries with raw technical evidence preserved for review and audit.

Claims verification

Paste vendor claims from security pages, RFPs, or questionnaires and test them against scan data.

Change monitoring

Detect new exposures over time and keep vendor risk reviews from going stale.

Claims verification

Turn vendor promises into testable controls.

Questionnaires are useful, but external evidence tells you whether the vendor-facing surface matches the story. Aegisnode helps separate verified claims from gaps that need follow-up.

Verified

Evidence supports the claim

Example: security headers, TLS posture, or DNS controls match the vendor statement.

Contradicted

Evidence conflicts with the claim

Example: an exposed service or stale certificate contradicts a published control.

Unverified

More context is required

Example: a claim needs documentation, private evidence, or vendor confirmation.

Changed

Exposure drifted since review

Example: a new host, port, or certificate appeared after the last assessment.

Threat telemetry adds context.

Live sensor data helps explain what attackers are probing, but vendor exposure remains the core product.

0
Events
0
Attacker IPs
0
Sensors
0
Countries
View telemetry

Start with one vendor domain.

Run a scan, review the evidence, and decide whether the vendor risk story matches the exposed surface.

Scan a vendor