Capabilities
Primarily focuses on first-party risk rather than taking a holistic view of cybersecurity.
2,000,000+ organizations scanned daily.
170,000 supported organizations
1,000,000+ companies rated.
100,000+ companies on the exchange.
Usability and the learning curve
Its threat intelligence tool maps internet-facing assets and provides insights and prioritized remediation recommendations based on asset criticality, context, and threat severity.
High-level summation of risk with the ability to drill down into precise technical details.
Provides high-level summation of vendor risk allowing easy comparison of vendors.
Simple interface for quick grade reports and charts.
Risks detailed on point-in-time vendor assessment coupled with continuous monitoring of inherent risk, threat intelligence, and risk scoring. The exchange model forces more frequent point in time assessments, as many as 2-3 times each year.
Community support
Company and product blog.
UpGuard Summit brings together a community of security leaders from leading companies, explores the future of security and helps businesses stay secure. The UpGuard cybersecurity and risk management blog is updated four times a week and our breach research blog has uncovered and secured some of the largest data breaches.
Company and product blog.
Company and product blog.
Company and product blog.
Release rate
UpGuard has adopted DevOps principles internally to develop, test, and release software continuously, ensuring fast, consistent, and safe releases.
Agile release methodology for both the SaaS platform and content.
Pricing and support
Rumored to start at $35 per 1,000 analyzed pages per year or $150,000 per analyzed brand plus cumulative consumer downloads per year for mobile products.
UpGuard has a transparent pricing model which you can view here. UpGuard pricing starts at $5k/year and scales with your company.
Public pricing information is not available. Pricing is reported to start at $20,000 plus $2,000-$2,500 per vendor per year.
Public pricing information is not available. Reports say pricing starts at $16,500 for self-assessment plus five vendors, and additional vendors cost $1,500-$2,000 per vendor per year.
There is no public pricing available for CyberGRX, making it hard to know how much you would pay without talking to them.
API and extensibility
UpGuard offers a standard API to pull data into other enterprise applications.
Fully functional bidirectional API.
Third-party integrations
Integrates with Cloudflare, Splunk, Crowdstrike, Qualys, Rapid7, ServiceNow, and more.
Integrates with GRC platforms, ticketing systems like ServiceNow, and more.
Offers integrations with RSA Archer GRC, CyberGRX, OneTrust Vendorpedia, ProcessUnity, MetricStream, and more.
Offers integrations with GRC platforms such as RSA Archer.
Integrates with multiple GRC platforms (using connectors), visualization tools, ticketing systems, and SOC tools.
Customers
Customers include Amazon, Disney, Box, Facebook, McKesson, Toyota, United, Pepsi, Rackspace, DocuSign, and American Express.
NASA, the New York Stock Exchange (ICE), Morningstar, Akamai, Bill.com, IAG, and ADP. Read our customer stories.
Customers include The University of North Florida, Snam, EPAM, and PROSA.
Customers include Symantec, Pepsico, Two Sigma, and Stony Brook University.
Fortune 500 companies across several sectors (including Financial Services, Healthcare, Retail, and Technology), and across geographies including North America, Europe, and APAC markets.
Predictive capabilities
Relies on first-party attack surface management by monitoring your digital footprint (websites, domains, public-facing assets, as well as javascript resources, and typosquatted domains), as well as external threats like phishing, deep and dark web discussions, email spoofing, and other cyber threats.
As UpGuard checks for misconfigurations across your Internet footprint, many important breach vectors are covered, including phishing, ransomware susceptibility (like WannaCry), man-in-the-middle attacks, DNSSEC, vulnerabilities, email spoofing, domain hijacking, and DNS issues. Data leaks are automatically surfaced by the platform for your team to assess and close before they become breaches.
The IP reputation methodology helps catch active malware installations, but that’s only one possible way a data breach can occur.
The IP reputation methodology helps catch active malware installations, but that's only one possible way a data breach can occur. Yes, they use additional data but lack the transparency to prove the efficacy of their scores
Checks for misconfigurations across Internet footprint and covers breach vectors such as phishing, ransomware susceptibility (like WannaCry), man-in-the-middle attacks, DNSSEC, vulnerabilities, email spoofing, domain hijacking, and DNS issues. Data breach incidents are captured, and notice is provided.
Security rating
Capabilities
Primarily focuses on first-party risk rather than taking a holistic view of cybersecurity.
Usability and the learning curve
Its threat intelligence tool maps internet-facing assets and provides insights and prioritized remediation recommendations based on asset criticality, context, and threat severity.
Community support
Company and product blog.
Release rate
Pricing and support
Rumored to start at $35 per 1,000 analyzed pages per year or $150,000 per analyzed brand plus cumulative consumer downloads per year for mobile products.
API and extensibility
Third-party integrations
Integrates with Cloudflare, Splunk, Crowdstrike, Qualys, Rapid7, ServiceNow, and more.
Customers
Customers include Amazon, Disney, Box, Facebook, McKesson, Toyota, United, Pepsi, Rackspace, DocuSign, and American Express.
Predictive capabilities
Relies on first-party attack surface management by monitoring your digital footprint (websites, domains, public-facing assets, as well as javascript resources, and typosquatted domains), as well as external threats like phishing, deep and dark web discussions, email spoofing, and other cyber threats.
Security rating
Capabilities
2,000,000+ organizations scanned daily.
Usability and the learning curve
High-level summation of risk with the ability to drill down into precise technical details.
Community support
UpGuard Summit brings together a community of security leaders from leading companies, explores the future of security and helps businesses stay secure. The UpGuard cybersecurity and risk management blog is updated four times a week and our breach research blog has uncovered and secured some of the largest data breaches.
Release rate
UpGuard has adopted DevOps principles internally to develop, test, and release software continuously, ensuring fast, consistent, and safe releases.
Pricing and support
UpGuard has a transparent pricing model which you can view here. UpGuard pricing starts at $5k/year and scales with your company.
API and extensibility
UpGuard offers a standard API to pull data into other enterprise applications.
Third-party integrations
Integrates with GRC platforms, ticketing systems like ServiceNow, and more.
Customers
NASA, the New York Stock Exchange (ICE), Morningstar, Akamai, Bill.com, IAG, and ADP. Read our customer stories.
Predictive capabilities
As UpGuard checks for misconfigurations across your Internet footprint, many important breach vectors are covered, including phishing, ransomware susceptibility (like WannaCry), man-in-the-middle attacks, DNSSEC, vulnerabilities, email spoofing, domain hijacking, and DNS issues. Data leaks are automatically surfaced by the platform for your team to assess and close before they become breaches.
Capabilities
170,000 supported organizations
Usability and the learning curve
Provides high-level summation of vendor risk allowing easy comparison of vendors.
Community support
Company and product blog.
Release rate
Pricing and support
Public pricing information is not available. Pricing is reported to start at $20,000 plus $2,000-$2,500 per vendor per year.
API and extensibility
Third-party integrations
Offers integrations with RSA Archer GRC, CyberGRX, OneTrust Vendorpedia, ProcessUnity, MetricStream, and more.
Customers
Customers include The University of North Florida, Snam, EPAM, and PROSA.
Predictive capabilities
The IP reputation methodology helps catch active malware installations, but that’s only one possible way a data breach can occur.
Security rating
Capabilities
1,000,000+ companies rated.
Usability and the learning curve
Simple interface for quick grade reports and charts.
Community support
Company and product blog.
Release rate
Pricing and support
Public pricing information is not available. Reports say pricing starts at $16,500 for self-assessment plus five vendors, and additional vendors cost $1,500-$2,000 per vendor per year.
API and extensibility
Third-party integrations
Offers integrations with GRC platforms such as RSA Archer.
Customers
Customers include Symantec, Pepsico, Two Sigma, and Stony Brook University.
Predictive capabilities
The IP reputation methodology helps catch active malware installations, but that's only one possible way a data breach can occur. Yes, they use additional data but lack the transparency to prove the efficacy of their scores
Security rating
Capabilities
100,000+ companies on the exchange.
Usability and the learning curve
Risks detailed on point-in-time vendor assessment coupled with continuous monitoring of inherent risk, threat intelligence, and risk scoring. The exchange model forces more frequent point in time assessments, as many as 2-3 times each year.
Community support
Company and product blog.
Release rate
Agile release methodology for both the SaaS platform and content.
Pricing and support
There is no public pricing available for CyberGRX, making it hard to know how much you would pay without talking to them.
API and extensibility
Fully functional bidirectional API.
Third-party integrations
Integrates with multiple GRC platforms (using connectors), visualization tools, ticketing systems, and SOC tools.
Customers
Fortune 500 companies across several sectors (including Financial Services, Healthcare, Retail, and Technology), and across geographies including North America, Europe, and APAC markets.
Predictive capabilities
Checks for misconfigurations across Internet footprint and covers breach vectors such as phishing, ransomware susceptibility (like WannaCry), man-in-the-middle attacks, DNSSEC, vulnerabilities, email spoofing, domain hijacking, and DNS issues. Data breach incidents are captured, and notice is provided.
Security rating
All comparisons
We want you to choose the best platform for you, even if it’s not us.
Sign up to our newsletter
Get the latest curated cybersecurity news, breaches, events and updates in your inbox every week.


Free instant security score
How secure is your organization?
Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
- Instant insights you can act on immediately
- 13 risk factors, including email security, SSL, DNS health, open ports and common vulnerabilities

Book a free demo
Book a free, personalized onboarding call with one of our cybersecurity experts.