Security Score

Reading the Security Score: how a 0–100 number becomes an A–F grade

A single number is only useful if you can explain what moved it. The Security Score aggregates passed and failed controls, weighted by severity, across Cloud, Identity and SaaS, and is recalculated on every new assessment.

Blog

August 29, 2026 · 12 min read

01

The score is a ratio of controls, not a guess

For every connected environment, the platform evaluates a defined set of controls and records a pass or fail per control, each carrying a severity weight. The Security Score aggregates that ratio across every environment the third party has connected, from 0 to 100.

The A–F grade is a fixed mapping of the 0–100 range, so the score and the grade never disagree — the grade is a readable label for the number, not a separate judgment.

Security Score: the memo view, with the composition explained across Overview, Cloud & IaaS, Identity and SaaS.
Security Score: the memo view, with the composition explained across Overview, Cloud & IaaS, Identity and SaaS.
02

Three environments, one number

The overview score is a roll-up of three environment scores: Cloud & IaaS (the connected cloud and Kubernetes accounts), Identity (permissions, entitlements and access hygiene) and SaaS (Microsoft 365 and Google Workspace configuration).

Each environment can be inspected on its own tab, which is what turns a single number into an explainable one: a reviewer can see exactly which environment is dragging the overall grade down.

  • Cloud & IaaS: posture of AWS, Azure, Google Cloud, OCI, Kubernetes and registries
  • Identity: access and entitlement hygiene across connected accounts
  • SaaS: Microsoft 365 and Google Workspace configuration
03

Cloud, identity and SaaS on their own tabs

Each environment tab shows the same pass/fail composition scoped to that domain, so a reviewer moving from the overview to the detail keeps the same mental model instead of switching frameworks.

Security Score — Cloud: control pass/fail composition scoped to the cloud environment.
Security Score — Cloud: control pass/fail composition scoped to the cloud environment.
04

The score moves when the assessment runs, not on a fixed schedule

The score is recalculated every time a new assessment completes on a scan target, not on a calendar. Fixing a failed control and re-running the assessment is what changes the number — there is no manual override that raises a score without evidence behind it.

Security Score — Identity: identity-scoped control composition feeding the overall score.
Security Score — Identity: identity-scoped control composition feeding the overall score.
1stone Research

Talk to the team about a third-party program

A working session against your actual third-party portfolio: how workspaces are created, which accounts get connected first, and what the Security Score looks like in week one.

Request a walkthrough