Measuring how safe companies actually are -- not how safe they say they are.
Our mission: Every company deploying AI or handling digital infrastructure should have a measurable, independently verified security posture. The Benware Standard makes that measurement possible -- using the same data an attacker would use, scored by a methodology anyone can inspect.
One framework. External attack surface. AI governance. Data protection. Infrastructure. One score.
Compliance frameworks measure documentation. Attackers do not read documentation.
Seven domains. Every test vector is observable from outside the organization, without credentials or prior access.
The Benware Standard runs 75 test vectors across all seven domains. Each test is observable from the public internet, without credentials or prior knowledge of the organization's internal environment.
Results produce a 0-100 score and an A-F grade based on weighted domain performance. Scores are calculated using a proprietary exploitability formula that weights findings by severity, detectability, and remediation complexity.
Nine organizations assessed across financial services and insurance. All findings anonymized. Dataset published April 2026.
| Sector | Grade | Highest Finding | Annual Risk Range |
|---|---|---|---|
| US-based growth equity fund | D | Server control panel exposed | $35K -- $286K |
| London angel syndicate, FCA-regulated | C | Zero email authentication | $6K -- $35K |
| US venture fund, Series A | B | Weak email authentication | $5K -- $33K |
| European PE firm | A | No verified findings | $6K -- $63K |
| Mid-market investment firm | A | No verified findings | $6K -- $63K |
| Global specialty insurance | A | No verified findings | $13K -- $125K |
| Cyber insurance provider | A | No verified findings | $6K -- $63K |
| European PE firm | A | No verified findings | $3K -- $33K |
| Global insurance and reinsurance | A | No verified findings | $13K -- $125K |
Five levels of certification, from basic tooling to government-grade continuous monitoring. Each tier builds on the previous.
The complete test vector library, scoring rubrics, domain weighting rationale, and benchmark dataset methodology are available in the published standard.
View Full Methodology