Compare

Certisyn, Bitsight and SecurityScorecard: a rating of the outside and a determination of a claim.

Bitsight and SecurityScorecard produce security ratings from externally observable signals, which suits broad supplier monitoring. Certisyn determines whether a specific claim a supplier makes is true, from the evidence behind it, and issues the result as a sealed record with its gaps named. A rating helps a buyer decide where to look. A determination settles what the buyer found.

At a glance

PropertySecurity ratingsCertisyn determination
BasisExternally observable signals about an organisation's internet-facing footprintEvidence supplied for a specific claim: policy, telemetry, configuration, logs, registry records
UnitAn organisation, scoredA claim, determined
OutputA score and a rating over timeA sealed, policy-versioned determination with a public anchor
GapsVisibility depends on what is observable from outsideEvery unexamined unit enumerated with a reason; every undetermined claim stated
BreadthWide: many suppliers monitored continuouslyDeep: the claims that carry the decision
Reader checkPer the provider's platformPublic registry and recomputable derivation root, no account

How buyers combine them

Ratings give a procurement or risk team a wide first view across a supplier base. A Certisyn determination follows for the suppliers and claims that carry weight: a certification a contract depends on, a control an insurer prices, a jurisdiction a regulator asks about.

Frequently asked

How is Certisyn different from a security rating?

A security rating summarises how an organisation looks from outside, using externally observable signals. A Certisyn determination addresses a specific claim, examines the evidence behind it and names the gaps. The 2 answer different questions.

Can a buyer use both?

Yes. A rating can prioritise which suppliers to examine first. A determination settles the claims that matter for the decision.

Related