Public product example

See the evidence before the decision.

This fictional report demonstrates how Aegisnode organizes externally observable vendor risk, confidence, and remediation priorities. It is not a scan of a real organization.

Read methodology
aegisnode
Fictional sample

External vendor evidence report

Northstar Cloud Services

A point-in-time view of internet-facing exposure associated with a fictional vendor domain. Findings support review decisions; they do not replace vendor due diligence.

Primary targetnorthstar-cloud.example
Assessment date2026-07-24 14:30 UTC
Report IDSAMPLE-AN-260724
Review stateDemonstration only
01

Decision summary

What a reviewer should understand first.

68
Grade B- / Elevated observations

Illustrative score on a 0-100 scale. Higher is better. See methodology for category weights and grade boundaries.

Conditional review recommended

The fictional target presents one high-priority encryption finding and two configuration weaknesses. The evidence is sufficient to request remediation, but it does not establish the vendor's internal control effectiveness or contractual compliance.

1High
2Medium
1Low
4Total

Fictional weighted category breakdown

CategoryScoreWeightWeighted value
TLS4520%9.00
DNS8510%8.50
Email6515%9.75
Ports8220%16.40
Headers6210%6.20
Technology7815%11.70
Breach6410%6.40
Total-100%67.95, rounded to 68
02

Vendor record

Context supplied for this fictional review.

Business owner
Fictional: Maya Chen
Criticality
High
Data access
Customer contact data
Renewal date
2026-11-30
Inherent risk
High
Review status
Remediation requested
03

Findings

Illustrative observations ranked by potential decision impact.

IDFindingSeverityConfidenceEvidence
F-001Legacy TLS protocol acceptedA fictional endpoint accepted TLS 1.0 during the sample observation.HighConfirmed
Direct handshake
EV-001
F-002DMARC policy not enforcedThe fictional DNS response used a monitoring-only policy.MediumConfirmed
Direct DNS record
EV-002
F-003Security headers incompleteTwo recommended browser response headers were absent from the fictional response.MediumObserved
Single-path response
EV-003
F-004Certificate renewal windowA fictional certificate was within 28 days of expiry.LowConfirmed
Presented certificate
EV-004
04

Evidence register

Every sample finding points to a specific fictional observation.

EV-001

TLS handshake transcript

edge.northstar-cloud.example:443 / protocol offered: TLS 1.0 / observed 2026-07-24 14:31 UTC.

Direct observation
EV-002

DNS TXT response

_dmarc.northstar-cloud.example / fictional policy value p=none / observed 14:32 UTC.

Direct observation
EV-003

HTTPS response headers

Fictional root-path response did not include CSP or Permissions-Policy. Other routes were not tested in this sample.

Scoped observation
EV-004

Presented certificate metadata

Fictional leaf certificate expiry: 2026-08-21 23:59 UTC / 28 days from assessment.

Direct observation
05

Remediation plan

Suggested next actions for the fictional review owner.

  1. Disable legacy TLS versions

    Require TLS 1.2 or newer across the affected edge configuration, then provide a retest window.

    Due: 14 days
  2. Move DMARC toward enforcement

    Validate mail sources, document exceptions, and progress from monitoring to quarantine or reject based on business impact.

    Due: 30 days
  3. Confirm response-header coverage

    Apply the required browser controls consistently and retest representative application routes.

    Due: 30 days
  4. Confirm certificate renewal automation

    Verify ownership and renewal monitoring before the fictional expiry date.

    Due: 7 days
06

Review record and limitations

Decision ownership remains with the organization using the report.

Scope boundary: This fictional example represents external, point-in-time observations. It does not test internal systems, people, contracts, data flows, control operation, penetration resistance, or compliance with any law, regulation, certification, or framework.
Reviewed by: Fictional sample / no professional review performed
Risk acceptance: Not applicable / demonstration only
Exception: None recorded
Reassessment date: Fictional 2026-08-24