stackoverflow.com
Ready for an outside-in assessment
New domain added to your portfolio
Run an assessment when you are ready
Add any domain
Paste your domain or a vendor’s URL. No agent, questionnaire, or access to their network required.
Paste any vendor domain and get a 0–100 rating, an A–F grade, and the evidence behind every deduction. Nothing to send, nobody to chase — the assessment reads what is already public, so you are not waiting on a vendor's security team to answer a spreadsheet. Your organization and every supplier in one portfolio. Data stored in the EU.


How it works
Everything an insurer, a customer, or an attacker can already observe about a domain — collected, scored, and written up so the rest of your team can act on it.
stackoverflow.com
Ready for an outside-in assessment
New domain added to your portfolio
Run an assessment when you are ready
Paste your domain or a vendor’s URL. No agent, questionnaire, or access to their network required.
DNS posture
Records and email controls
Reputation
Public threat signals
Signal mapping
Evidence grouped into one rating.
Four collectors read DNS and email records, TLS and certificates, HTTP security headers, and exposed infrastructure. Every finding carries the evidence it came from.
Your action plan is ready.
Start with the biggest rating impact:
HIGH PRIORITY
Tighten your DMARC policy
Evidence, impact, and a remediation checklist
↳ Re-assess to confirm the fix
See what pulled the rating down, work through the remediation checklist, then re-assess to show the deduction is gone.
From signal to decision
A rating nobody can trace back to evidence is a number in a slide deck. Every deduction here opens onto the record it came from.

01 / 04
Assess any domain from the outside in, see what changed since the last run, and hand your team the evidence behind it. Nothing to install, nobody to ask for access.
Record where you stand against the frameworks your buyers ask about, and move each one along as controls get done. These are your attestations — SolidLayer keeps the record, it does not audit, verify, or certify them.

The same category breakdown your team uses in the dashboard.

Your organization and every vendor, rated on the same scale.

Every deduction includes proof, severity, and a concrete fix.

Every run, with the score it produced, how long it took, and whether it completed.

Built for vendor onboarding, cyber insurance renewals, and MSP client reviews. One number for the people who ask for one. Findings your engineers can act on.
VAT calculated at checkout.
For focused teams
One organization and enough evidence to start acting on it.
Get startedFor growing portfolios
More than three times the assessment capacity, plus priority support.
Choose ProFor complex organizations
Custom volume and controls shaped around your organization.
Contact us about EnterpriseEvery plan includes passive assessments, evidence behind every finding, and the full 0–100 rating.
Compare all featuresHave more questions? Reach out to our support team.
Email support