Security reports policy

About our security reports

UpGuard publishes free security reports for organizations around the world. These reports provide an independent, third-party assessment of an organization’s externally observable security posture, helping businesses, researchers, and the public understand cybersecurity risk.

Each report includes:

  • A security rating: Based on continuous monitoring of the organization’s public-facing infrastructure.
  • Risk findings: Across categories such as website security, email security, network security, DNS, encryption, and more.
  • Basic company information: To identify the organization being assessed.

The nature of our ratings and findings

UpGuard’s security ratings and risk findings represent our independent assessment, based on our own methodology and analysis of publicly observable information. They are statements of UpGuard’s opinion, provided “as is.”

A security rating does not equate to a certification or cybersecurity audit, so it does not substitute for a penetration test, formal security assessment, or professional advice.

An organization’s real-world security posture may differ from what is externally observable, and ratings may change as our methodology evolves or as new information becomes available.

Where our data comes from

Security ratings and risk findings are derived from UpGuard’s analysis of publicly observable, externally verifiable information including DNS records, SSL/TLS certificates, email authentication configurations, open ports, and other data accessible without authentication, supplemented by data from established open-source and commercial threat intelligence providers. The externally observable information we analyze is the same type of information available to any security researcher examining an organization’s public attack surface.

Company profile information (such as organization name, industry, and description) is sourced from publicly available data. We make reasonable efforts to ensure this information is accurate, but recognize that organizational details change over time.

Company logos are displayed for identification purposes only and do not imply any endorsement, affiliation, or sponsorship by the organization featured in the report. All trademarks, logos, and brand names remain the property of their respective owners.

What we don’t do

Our analysis relies only on information that is publicly accessible without authentication. In producing our security reports, UpGuard does not attempt to gain unauthorized access to any system, does not exploit vulnerabilities, and does not perform intrusive or disruptive testing against the organizations we assess. Our findings reflect the same externally observable information available to any member of the public or security researcher.

Requesting a correction

We are committed to the accuracy of our reports. If you believe any information in a security report is factually incorrect, please contact us at support@upguard.com with:

  • The URL of the report in question
  • The specific information you believe is incorrect
  • The correct information, with a source or reference if available

We will acknowledge correction requests within 2 business days and aim to review and update reports, where appropriate, within 5–7 business days.

Our right to publish

UpGuard’s security reports are based on publicly available information and our own independent analysis. Publishing factual, independently gathered information and our own assessment of an organization’s public security posture does not require that organization’s authorization.

This is consistent with the practices of security rating services, business intelligence platforms, and cybersecurity research organizations worldwide.

We do not remove security reports on request. If you believe specific information is inaccurate, please use the correction process described above.

Questions

For questions about our security reports or this policy, contact support@upguard.com.

Last reviewed and updated: July 15, 2026

Experience superior visibility and a simpler approach to cyber risk management