How does SecurityScorecard collect data?

SecurityScorecard uses both active and passive data collection to gather proprietary and third-party data.

Active data collection involves initiating a connection towards remote hosts and participating in some initial part of their protocol. Think about this as data that needs to be requested.

Passive data collection can be done in two ways:

  • A remote host connects to us.

  • We obtain copies or summaries of some protocol transaction from a network sensor or intermediary device.

Think about this as data that’s collected without asking.

SecurityScorecard’s proprietary data collection relies on a global network of sensors. They examine the entire internet and identify services, vulnerabilities, and adherence to best practices, which can indicate a company’s current cybersecurity posture. These signals are the backbone of SecurityScorecard’s security ratings. They also operate one of the world’s largest networks of sinkholes and honeypots to find indications of malware infection from outside a company's network.

SecurityScorecard further enriches their data set by leveraging commercial and open-source intelligence feeds. This allows SecurityScorecard to improve the cadence of observation, build fidelity in the signals, and confirm accuracy in observations.

All of SecurityScorecard’s data collection methods are legal. They collect externally accessible and publicly available data. No intrusive techniques are used to gather information.