Back to the registry
Agent passport

Attack Surface Intelligence

SecurityScorecard · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

SecurityScorecard has established itself as the cybersecurity ratings leader. On our path to attaining this industry trust, we have collected security-relevant data over the past 10 years. And we continue to expand and refine processes for gathering, enriching, and normalizing nearly 10 petabytes of raw data.

Significantly, 99 percent of the data on which our ratings and services are based is sourced from in-house collection and analysis operations:

Show the rest of the publisher’s description (6 more lines)

SecurityScorecard's DNS sinkhole collects information about infections from more than 150 malware families without requiring an inside sensor on infected systems or networks. Additionally, our malware attribution system provides automated malware analysis, classification, and tracking at scale. This includes rich information about malware families, threat groups, and campaigns, enabling us to generate issue types and track threat groups.

The platform also contains leaked breach records, consisting of 68 terabytes of processed data, including user names, passwords, social media URLs, Social Security numbers, credit card numbers, addresses, IPs, and more. This data set is comprised of more than 10 billion records.

Our ransomware leak site crawler provides findings specific to ransomware attacks, breaches, and credential leaks. It also provides insight into how the ransomware groups operate, what industries they target, who the victims are, and what data is stolen. Information on more than 40 active ransomware groups is actively tracked and updated daily.

SecurityScorecard operates an extensive honeypot system that provides information about the structure and intentions of advanced persistent threats (APTs) and ransomware groups that actively exploit a particular vulnerability.

We use a Chrome-based web crawler to gather information on all major sites' infrastructure, vulnerabilities, vendor dependencies, screenshots, and more. It detects supply chain dependencies in software and provides data for more than 50 types of issues in Ratings platform's Application Security factor.

For inquiries about a Private Offer (PO) or a Channel Partner Private Offer (CPPO), please contact aws-sales@securityscorecard.io.

Highlights

Highlighted by the publisher on AWS Marketplace.

7B+ Normalized leaked databases records from across the dark web and forums

100B+ Vulnerabilities and attributions published weekly

36M+ Threat actor associations made and growing daily tied to exposed assets, malicious IPs, file hashes, and more.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMP ReadyConfirmedin process90%, registry-checkedSecurityScorecard Security Ratings is FedRAMP Ready at Moderate impact (domain match)FedRAMP Marketplaceregistry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment

CompanySecurityScorecardAutomated

Plans and pricing as listed

5 listed
One request to the Attack Surface Intelligence search endpoint / month
  • Units
$1.667
ASI Free Tier
  • Units
$0.00
P1M
ASI Free Tier
  • Units
$0.00
P12M
ASI Free Tier
  • Units
$0.00
P24M
ASI Free Tier
  • Units
$0.00
P36M

Refund terms

As stated by the publisher on AWS Marketplace.

All fees are non-cancellable and non-refundable except as required by law or as provided in our MSA.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
CustomEulaCustomEulaSource

Publisher resources

2 links
Publisher linkaws.amazon.comSource
Learn about our Customer Success Teamsecurityscorecard.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
5 plans listed
Delivery
SaaS
Learn about our Customer Success Team: https://securityscorecard.com/customers/customer-success Our Customer Success team is a team of advisors, partners and experts that are here to help you maximize your experience with SecurityScorecard. They help you unleash the full potential of SecurityScorecard, provide guidance on use cases, as well as keep you apprised of new product features. From onboarding and adoption through operationalization and scaling, the Customer Success team will be your partner to ensure you meet your goals as an additional layer to our technical support resources. To reach the Customer Success team contact us at csm@securityscorecard.io. For technical support please contact us at support@securityscorecard.io.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.