Methodology
HOW WE CALCULATE RISK
Every threat gets a score built in four layers. Here's the shape of it — not the exact constants, since those are the calibration work that makes the engine worth anything.
Step 1: TECHNICAL SEVERITY
CVSS v3.1, the open industry standard. Not a private scale we invented.
Step 2: LIKELIHOOD, ADJUSTED FOR EVIDENCE
a category baseline updated by what's actually true in your environment: exposure, asset criticality, what's already in place. Evidence moves the number. It isn't fixed.
Step 3: CONTROL EFFECTIVENESS
every control tied to a threat reduces its residual score, but controls don't stack linearly. Each additional one closes a smaller gap than the last — the way defense-in-depth actually behaves, not the way a checklist pretends it does.
Step 4: PROJECT-LEVEL SCORE
individual scores roll up into one weighted number per project, so exposure is something you can trend over time, not just read one threat at a time.
Every constant behind these four layers is documented internally and calibrated against real assessments. That calibration is hard-won — it's the one part of the engine we keep to ourselves.
HOW CONTROL EFFECTIVENESS WORKS
Controls don't just exist — they measurably reduce risk, or they don't count. Here's the shape of how that's decided.
- TYPE
- what a control actually does: prevent it, detect it after the fact, recover from it, or discourage it from being tried. Each type pulls a different lever in the score.
- STATE
- a control only reduces your score once it's actually deployed and verified. Planned controls show up in your inventory as intent, not as protection — the score won't lie to you about something that isn't running yet.
- STACKING
- add a second control to the same threat and it helps, but less than the first did. A third helps less still. That's not a limitation of the model — it's how real defense-in-depth behaves: diminishing returns, not addition.
- ORPHANS
- a control that isn't tied to any threat contributes exactly nothing to your score, no matter how good it is on paper. The platform flags these so nothing sits in your inventory doing no work.
The exact weighting between prevention, detection, and response speed — and the calibration values behind each control type — are documented internally and used live in your workspace. Same reason as the risk engine: that calibration is hard-won, and it's the one part we keep to ourselves.