Cyber due diligence for private equity
RiskPoint reads a portfolio company the way an attacker would — its perimeter, its code, its cloud, its suppliers and the breach news about it — and returns a posture score and a £ figure, not a PDF of findings nobody prices.
Built for the people who own the asset: Operating Partners, COOs and CFOs running diligence on a target or monitoring the companies they already hold.
0–850
Deterministic posture score
6
NIST CSF domains scored
Cyber £
Enterprise value at risk
Daily
Breach desk on every target
What it runs
Every pipeline emits the same issue contract, so a semgrep hit, a confirmed pentest finding and a ransomware listing are ranked on one scale instead of three reports.
Passive
OSINT with no packets sent in anger: attack surface, email security, breach exposure, threat intel, compliance filings, corporate structure and hiring signals.
Active
An autonomous agentic pentest against the live perimeter — confirmed, reproducible findings with the evidence attached, not a vulnerability guess.
GitHub
Static analysis across every repository the company owns, so the code the value sits on is read, not assumed.
Cloud
The Azure/AWS tenancy assessed against its own configuration — identity, exposure and the controls that were meant to be on.
Breaches
A daily desk watching public incident reporting, ransomware leak sites and breach catalogues for the companies and suppliers you actually hold.
Manual
The controls no scanner can see, captured as an analyst assessment with its evidence and folded into the same score.
How it works
01
A name, a domain and a valuation. Add its suppliers and the scans start themselves — no questionnaire round trip, no diligence window to wait for.
02
Six very different scans, one contract: each finding carries its severity, its NIST function and the evidence behind it, so they can be ranked against each other.
03
That list scores a 0–850 posture deterministically — code, not a language model — and the same findings drive Valuation at Risk: the equity value exposed if this company is breached.
The £ figure is conditional and shown as a range, with every input labelled by where it came from — read the methodology.
Third parties
Suppliers are scanned in their own right — passively, never intrusively, because nobody authorised a pentest of someone else's vendor — and their posture rolls up into the company that depends on them.
Monitoring
Every day it sweeps public incident reporting, extortion leak sites and breach catalogues and asks one question: is this about a company or supplier on file? What it finds scores the target the morning it appears — usually before the victim confirms anything.
Speak to an analyst, hand over one domain, and get the posture, the findings and the £ back.