Kenzer scores security posture from continuous, passive reconnaissance — not a self-reported questionnaire — built on ARPSyndicate's own subdomain and exploit intelligence databases, among the largest in the industry.
Kenzer's core is ARPSyndicate's own — Subdomain Center and Exploit Observer, the same shadow-IT discovery and exploit-maturity data (EPSS, VEDAS, CISA KEV) sold on their own as standalone APIs.
That core is complemented by specialized third-party intelligence — see Ecosystem below — rather than one team trying to build every signal in-house.
Deeper active verification runs only with an organization's explicit authorization.
The same reconnaissance pipeline and O-to-F risk grading, applied wherever “how risky is this externally-facing thing” is the question.
The core scanning engine underneath every other use case here — network scanning, SBOM analysis, exploit-aware prioritization.
Output integrations into the tools your team already runs.
Score vendors and suppliers from the outside in, continuously — not a point-in-time questionnaire.
Fourth-party breach cascade flags every vendor exposed the moment a shared provider is hit.
Discover what you didn't know you had — subdomains, hosts, exposed services, web apps.
The same shadow-IT discovery engine behind ARPSyndicate's own Subdomain Center.
Scheduled rescans and a triage queue prioritized by real exploit intelligence — EPSS, VEDAS, CISA KEV.
Not just CVSS — what's actually being exploited surfaces first.
An objective, externally-measured risk grade applied consistently across a whole book of policyholders.
For underwriting, renewal, and portfolio monitoring.
Whole-of-government attack surface visibility for CERTs and defense/cyber intelligence agencies.
Every ministry and agency rolled up into one sovereign posture score.
Not a mockup screenshot — these are the live figures from Kenzer's own running instance.
| Organization | Grade | Risk | Open findings | Assets |
|---|---|---|---|---|
| India | F | 98.3 | 121 | 2,597 |
| South Korea | D+ | 68.0 | 551 | 3,092 |
| Turkey | C- | 53.1 | 57 | 3,017 |
| Norway | A+ | 2.0 | 1 | 393 |
| Netherlands | A+ | 2.0 | 1 | 154 |
Discovery and scoring run continuously from passive, non-intrusive sources by default.
Deeper active verification is available too — but only against infrastructure an organization has explicitly authorized us to touch.
O, A+ through D-, F — fine-grained enough that two “pretty good” targets don't collapse into the same letter.
A diminishing-returns risk curve means one bad finding doesn't instantly cap the whole score.
Score a holding company, a conglomerate, or a national government as the average of its own sub-organizations.
Real-time, recursive, all the way up the chain.
See where an organization sits against its own tier and industry peers.
Track portfolio-wide trends — improving vs. worsening, at-risk counts, stale critical findings.
Log an incident at a shared provider (Cloudflare, AWS, Okta, ...) once.
Every organization with a detected dependency on that provider gets flagged automatically.
Hand a vendor's own team, or a business unit, a login restricted to exactly their own organizations.
They can triage and fix, and never see anyone else's.
Print or save a one-click PDF for a single organization, or a whole portfolio at once.
CSV export for findings and assets, for whatever you already do with the data downstream.
Kenzer draws on focused, industry-recognized intelligence sources rather than building every capability in isolation.
GoTrust, a privacy-first platform, integrated Kenzer's engine directly into their own product to meet the rising demand for offensive security.

Privacy-first platform, offensive security powered by Kenzer.
Kenzer already tracks 195 governments' external posture, live, in the National Threat Intelligence Database — built entirely from passive, non-intrusive reconnaissance.
No active scanning of any government is ever performed without that government's own authorization.
That's the same engine a national CERT or a defense & cyber intelligence agency can run privately — every ministry, every agency, every piece of critical infrastructure, rolled into one whole-of-government view.
Vendors, your own attack surface, a whole portfolio, or a nation's worth of infrastructure — one login away.