Example Output

Sample VERA Assessment

Explore a representative VERA assessment and see how externally verified findings are translated into actionable vendor risk intelligence. Organization details have been anonymized, but the scoring methodology, evidence citations, and report structure reflect actual assessment output.

Acme Co.

redacted-vendor.example

High Risk

Criticality: High (x1.2)

Scanned: [Anonymized date/time]

D

1critical 2high

Profile based on 8 domains with 43 total findings.

Alert Domains

1/8

Total Findings

43

High+Critical

3

Composite

67/100

Domain Risk Profile

This chart compares relative risk across all scoring domains. Larger outward shape indicates stronger security posture in that area.

Domain risk radar chart

Risk Summary

Generated [Anonymized date/time]

Acme Co. is assessed with an overall score of 67/100 and classified as High Risk, with high vendor criticality. The Compliance domain score is notably low at 48/100, indicating significant exposure in regulatory and governance areas. Evidence shows the absence of a privacy policy, and no trust center or responsible-disclosure program is publicly discoverable.

Critical and High Findings

The live result lists findings by domain and severity. This sample uses expandable blocks to show representative drill-down detail without requiring JavaScript.

Critical F-001: No DMARC record is published for primary domain (DNS and Email) E-001

Without DMARC enforcement, spoofed email can pass recipient checks and increase phishing exposure for customer and partner inboxes.

Status: Unresolved  |  Affected Scope: Primary domain mail flow  |  Source: DNS TXT inspection (May 2026)

High F-002: SPF record missing for sending domain (DNS and Email) E-002

SPF absence prevents receiving systems from validating authorised outbound infrastructure, weakening impersonation controls.

Status: Unresolved  |  Affected Scope: Root and transactional sender domains  |  Source: DNS SPF query

High F-003: DKIM selectors not discoverable for assessed namespace (DNS and Email) E-003

Missing DKIM selectors reduce message integrity verification and increase downstream deliverability and trust concerns.

Status: Unresolved  |  Affected Scope: 12 tested selector conventions  |  Source: Selector probe set

Elevated F-004: No public privacy policy detected in compliance surface (Compliance and Governance) E-004

For a high-criticality vendor, missing privacy disclosures create legal and procurement friction, especially for regulated buyers.

Status: Requires vendor confirmation  |  Source: Public website policy crawl

Elevated F-005: Trust center and security governance pages not publicly discoverable (Security Maturity) E-005

Absence of baseline trust artifacts reduces transparency for third-party assurance and may extend procurement review cycles.

Status: Open  |  Source: Public site and indexed page discovery

Evidence References

IDSourceTypeConfidenceRetrievedRelated Findings
E-001DMARC TXT lookupDNSHigh[Anonymized]F-001
E-002SPF TXT lookupDNSHigh[Anonymized]F-002
E-003DKIM selector probe (12)DNSMedium[Anonymized]F-003
E-004Policy and legal page crawlOSINTMedium[Anonymized]F-004
E-005Trust artifact discovery setOSINTMedium[Anonymized]F-005

Score Computation

AreaScoreWeightContribution
Attack Surface8118%14.58
Breach and Dark Web10015%15.00
Code and OSINT Leaks1008%8.00
Compliance and Governance4810%4.80
DNS and Email3612%4.32
Financial and Reputation6912%8.28
Security Maturity2910%2.90
Vulnerability Exposure10015%15.00
Weighted Average72.9Criticality adj.67 / 100 (High Risk)

Disclaimer: This sample is illustrative and based on publicly observable signals, third-party intelligence, and automated analysis. It does not replace legal, technical, or contractual due diligence.

Commission a VERA assessment for your next vendor

Turnaround from 3 business days. No vendor cooperation required.

Scroll to Top