What an outside-in rating can and cannot see
A rating built from internet-facing signals — exposed services, certificate hygiene, mail authentication records, breach chatter — is genuinely useful for a first pass across a large portfolio. It is also structurally limited to whatever a third party exposes to the public internet.
Most of a modern third party's risk surface is not internet-facing at all: internal identity permissions, storage bucket policies, Kubernetes namespace configuration, SaaS admin settings. None of that is visible from outside, no matter how sophisticated the scanning.

A questionnaire records an answer, not a configuration
A self-assessment questionnaire is a snapshot of what someone was willing to attest to on a given day, reviewed by no one but the person filling it in. It is slow to collect, quickly stale, and gives a contracting organization no way to verify a single answer.
The two approaches are not competitors to inside-out measurement; they simply answer a different question. Inside-out measurement answers: what is actually configured in the third party's own environment, right now.
- Outside-in rating: what is visible from the public internet
- Questionnaire: what the third party attests to, unverified
- Inside-out: what is actually configured, evidenced control by control
The inside-out model, in one sentence
The contracting party creates an isolated workspace for the third party, invites the responsible contact by email, and the third party connects its own cloud, container and SaaS accounts using a read-only credential. From that point, the platform evaluates real configuration continuously and produces a Security Score with evidence behind every control.
- One isolated workspace per third party
- Invitation-based onboarding; the third party connects its own accounts
- Read-only credential only — no standing write access is requested
- Continuous re-evaluation, not a point-in-time snapshot