the average security-ratings subscription. Point-in-time, passively IP-attributed, and routinely disputed. A score you cannot show your work on when the auditor asks how you know.
For Third-Party Risk · The ROI of Defensible Monitoring
$147,000 a year.
Undefendable.
The average security-ratings contract pays for scores vendors dispute and auditors reject. Defensible monitoring starts at $10 a month, every finding a dated reading the vendor’s own team can check.
One working artifact: the signed evidence report.
Every reading DomainDrift takes is signed the moment it is observed and travels as a dated evidence report you can hand over: state, providers, registrar, expiry, email authentication, DNSSEC and subdomains, per domain, on one page. The recipient re-checks every reading themselves in the public verifier, with no account, years later. That artifact is the same on every page here. The persona only changes which part of it you foreground, on the same $10 / $29 / $99 ladder.
The math, before the feature.
The average security-ratings contract runs about $147,000 a year for point-in-time scores your vendors dispute and an auditor will not accept. DomainDrift is continuous, defensible monitoring on a $10 / $29 / $99 ladder. Business is $1,188 a year, under one percent of that contract, and every finding is a dated reading a regulator accepts.
priced by the portfolio you watch, never per lookup. The working program is $29 a month; a full vendor estate is $99. Look up any vendor free.
Business is $1,188 a year, less than one percent of a $147k ratings contract, and every finding traces to a dated reading the vendor’s own team can check. Avoided audit failure, at a fraction of the cost.
“If a regulator or auditor asks you to explain a scoring discrepancy, ‘we filed a dispute’ is not a defensible answer.”
A public statement, quoted verbatim. Not a customer, not affiliated with DomainDrift, and not an endorsement.
Your vendor desk, real captures
The product, pointed at your desk.
Type a vendor, see its exact posture
The reading shows a vendor from the outside the way the internet sees it: who runs its infrastructure, who carries its mail, whether its certificates are healthy. Every line is a reading the vendor’s own team can check, so a disputed finding ends at the reading, not at a black-box score.
A vendor swears the finding is not their asset; the infrastructure map settles it, on the record.
Ten vendors, one dated report
Group your vendors and DomainDrift watches them together, every day. The live view is your desk; the daily report is the deliverable you hand a reviewer, an auditor, or the vendor. Email authentication, upcoming expiries, subdomain coverage, every line drawn from that vendor’s latest signed reading. A quiet portfolio is itself a dated, signed result.
Hear about a change where you work
Watch one vendor, a portfolio group, a cohort, or your whole list. The moment a nameserver shifts, a certificate is about to expire, or a mail record changes, the alert lands in Slack or a webhook, between reassessments, not a quarter later. Approve a vendor’s current state as its baseline, and the alert reads not “something changed” but “changed from what you signed off on.”
A control lapses the week after the quarterly review; you hear about it that day, not next quarter.
Read any vendor from the outside with no account. A straight answer in a few seconds.
A free account watches one; paid plans raise the count so a whole vendor estate is one watch.
Every group produces a dated report grounded in checkable readings, the evidence a reviewer accepts.
The exact DNS, mail, and certificate reading behind every finding, checkable by the vendor’s own team against published keys. The dispute ends at the reading, and your monitoring record is one an auditor accepts.
An independent, signed record, now anchored to Base
Every reading is signed the moment it is taken and chained to the one before, against published keys, and each day's most-recent readings are rolled into a single root and anchored to Base, a public chain, so the date is confirmed by the chain and not only by us. That proves who took each reading, that nobody has altered it since, and when it was taken. It is attribution, integrity, and an independent timestamp, never a claim the reading is correct: a signature can sit on a wrong observation. Anyone re-checks a reading's signature themselves at the verifier, no account, years later. The signature is the first-mover trust layer; the lasting advantage is the dated record itself, which compounds and cannot be recreated after a domain changes, or rewritten once it is anchored.
Start free
A free account puts one of your own domains under watch, keeps its history, and sends a signed alert the moment we see it change. Paid plans raise the dials; pricing is on its own page.
Free to start. No credit card. Your signed record is yours to keep and verify anywhere.