All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
UpGuard sells security teams one place to rate their suppliers, watch their own internet-facing systems, and see which AI tools their staff are using. Its February 2026 funding announcement puts reach at 50k organizations and, in the same sentence, counts over 2,000 of them as customers. Trust Exchange, its questionnaire-automation product, is free to anyone with no credit card and no sales call. The customer count is the figure to compare against other vendors. Paid Vendor Risk plans start at $1,750 a month. The customers UpGuard names include Intercontinental Exchange, Morningstar and IAG. UpGuard is a mid-market buy, priced and pitched for teams that want vendor ratings, questionnaires and attack-surface monitoring from one supplier rather than several.
| Description | UpGuard gives security teams a single view of cyber risk across their vendors, their internet-facing attack surface and their workforce. | [f1] |
|---|---|---|
| Founded | 2012 | [f2] |
| HQ | Hobart, Tasmania, Australia, with US headquarters in Mountain View, California | [f2] |
| Latest funding | Series C, US$75 million, February 2026 | [f2] |
| Product | What it does |
|---|---|
| Vendor Risk | Third-party risk management with continuous vendor monitoring, security ratings, questionnaire automation and remediation workflows. |
| Breach Risk | Attack surface monitoring paired with open, deep and dark web threat monitoring and detection of lookalike domains and impersonation. |
| User Risk | Workforce risk management that finds unsanctioned SaaS and AI tools and blocks risky uploads and copy-pastes inside the browser. |
| Trust Exchange | Free questionnaire automation and a hosted trust page for sharing security documentation with prospects and customers. |
| Risk Automations | No-code automations that turn a risk signal into notification, ticketing and remediation actions across connected systems. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
UpGuard Vendor Risk rates a customer's supply chain, Breach Risk inventories the customer's own internet-facing attack surface and watches for leaked data, and User Risk finds unsanctioned workforce applications and blocks risky uploads. These products are mapped to the Cyber Defense Matrix. [f3]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | UpGuard aims the platform at the security team that answers for suppliers it does not run, and its compliance pages tie the work to named obligations, including APRA's Prudential Standard CPS 230 in force from July 2025. The figures that size the pain are UpGuard's own, so the buyer and the problem are clear while the magnitude is vendor-asserted. [s17, s3, s13, s1] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The security ratings page sets out the mechanism in specifics: daily collection across internet-facing properties, a subtractive score out of 950, a Gaussian weighted average that overweights the worst asset, and ten risk categories whose checks carry fixed weights. Forrester's 2024 cybersecurity risk ratings evaluation placed UpGuard as a Contender, reported by Information Security Media Group in May 2024, and that article names UpGuard once, in its tier list. [s7, s25, s3, s4, s2] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enablers are documented and the buyer-side evidence is thin. APRA's CPS 230 took effect in July 2025 and workforce AI adoption is the problem User Risk addresses, while the demand signals in the reviewed sources are UpGuard's own G2 category standing and a growth round rather than budget or procurement records. [s17, s5, s13, s18] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | UpGuard's breach research spans the reviewed record from 2017 to 2026: the research index carries dated, named-author posts through 2025 and 2026, CyberScoop covered the team's 198-million-voter finding in 2017, and SecurityBrief covered its streaming and betting research in 2026. The about page records the executive team by name and title, so the public signal is the research record rather than founder biographies. [s16, s19, s20, s9, s15] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | G2 hosts 735 reviews of Vendor Risk at 4.5 out of 5, which is buyer testimony UpGuard does not host, and UpGuard's own case studies name Morningstar, Colorado State University and Intercontinental Exchange with a New York Stock Exchange technology executive quoted by name. The reach figures of 50k organizations and over 2000 customers are UpGuard's own, and the review records G2 displays carry incentivized, seller-invited labels. [s24, s11, s3, s14, s13] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | UpGuard raised US$75 million from Springcoast in February 2026, after a 2021 offering the SEC Form D records as 19044613 dollars sold, and it ships five product lines against that capital. No revenue, margin or growth-efficiency figure appears in the reviewed sources, the one capital-efficiency characterization on record is Springcoast managing partner Holger Staude's, made in the announcement of his own firm's investment, so efficiency itself is unconfirmed. [s18, s22, s13, s1] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Buyers and analysts both do the placing: G2 files UpGuard Vendor Risk under Third Party & Supplier Risk Management with 600 reviews tagged to that category, and Forrester's 2024 cybersecurity risk ratings evaluation ranked UpGuard inside that named market as a Contender. The umbrella term UpGuard leads with, cyber risk posture management, is not the category either of them files it under. [s24, s25, s23, s14] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | What slows a bundling platform vendor here is accumulated program state rather than technology: vendor inventories, questionnaire history and remediation workflows build up inside the platform, wired outward through a catalog of more than 100 connectors. The reviewed sources describe collection methods and a scoring model a funded competitor could assemble, so the friction is real and not structural. [s3, s6, s14, s7, s2] |
UpGuard sells to the security function that has to answer for suppliers it does not control. Its vendor product runs onboarding, assessment, remediation and continuous monitoring in one place, and its compliance pages attach that work to named obligations. The APRA page states that the Prudential Standard CPS 230 takes effect from July 1st, 2025, and pages for DORA, NIST and the SIG questionnaires sit beside it.
The problem has widened rather than moved. User Risk addresses staff signing up for AI tools the security team never reviewed, and Breach Risk addresses the organization's own internet-facing exposure, so a buyer who arrived for third-party risk is offered two more problems from the same console.
The compliance surface is where a buyer's obligation set shows up. UpGuard publishes questionnaire and guidance pages for ISO 27001, NIST, SIG Lite, SIG Core, APRA CPS 230, DORA, DPDP and its own multi-framework questionnaire, which is the paperwork a regulated buyer arrives holding. [s17, s1, s3, s5, s4, s14]
The same scanning feeds two of the products a buyer evaluates separately. UpGuard describes proprietary scanning infrastructure that collects billions of data points daily through commercial, open-source and proprietary methods, with a stated focus on non-invasive passive collection, and the same collection feeds both the vendor ratings and the customer's own attack surface view.
The scoring model is documented in specifics. Checks feed a rating out of 950 for each internet-facing property, the algorithm subtracts points by severity and weight, an organization's overall score is a Gaussian weighted average that gives the worst asset the most weight, and the checks inside each of ten risk categories carry fixed weights. Vendor Risk states that ratings update multiple times per day.
AI appears as named tasks rather than as the product. UpGuard says its threat analyst triages breach signals, document analysis reads vendor evidence, and Questionnaire AI drafts answers from a customer's own library, and it publishes usage measurements for all of it, including 23 billion tokens processed in 100 days and 700k autofilled questionnaires to date. [s7, s3, s4, s13, s6]
Both sides of the ratings rivalry name each other in print. UpGuard publishes comparison pages against Bitsight, SecurityScorecard, CyberGRX and RiskRecon, and SecurityScorecard publishes a page on why customers choose it over UpGuard, which is as close to mutual acknowledgement as vendor material gets. G2 independently lists SecurityScorecard and Bitsight as the products buyers compare UpGuard Vendor Risk against. Forrester's 2024 evaluation of the same market ranked UpGuard a Contender, a tier below the Strong Performers and outside the leaders, and Forrester published a further edition of that evaluation in April 2026.
UpGuard's own argument on that page is about access. It says paid vendor risk plans start at USD 1,750 per month billed annually and that a free tier monitors up to five vendors, and it frames the product as fitting mid-market teams that deploy quickly.
The same page concedes a gap, which is unusual enough to note. UpGuard writes there that the product does not translate risk into dollar figures, so a buyer who needs financial risk quantification has to cover it outside the platform. [s14, s23, s24, s25, s26, s1, s8]
The funnel starts at zero cost. Trust Exchange is free to anyone, with UpGuard stating there is no credit card and no sales call to get started, and the Bitsight comparison page adds a free tier that monitors up to five vendors. Paid Vendor Risk plans open at $1,750 a month billed annually for 50 vendors, with extra vendors at $79 a month.
Named references are the strongest part of the traction record. UpGuard publishes case studies for Morningstar, Colorado State University, St John WA and Intercontinental Exchange, quotes a New York Stock Exchange technology executive by name on the Vendor Risk page, and lists TDK, PagerDuty, Hopin and IAG among customers on its Bitsight comparison page.
UpGuard announced on August 12, 2026 that the platform is available on Google Cloud Marketplace, where a Google Cloud marketplace director is quoted in the release, and says buyers can draw on committed Google Cloud spend to pay for it.
UpGuard supplies its own scale figures. Its February 2026 announcement counts 50k organizations in more than 90 countries and over 2000 customers, and the same paragraph claims a G2 category standing across 15 consecutive quarters. Startup Daily reported the US$75 million round, and the customer figures inside that article are quoted from the chief executive.
The independent volume is on G2. That site hosts 735 reviews of Vendor Risk at 4.5 out of 5 and counts 282 of the reviews at companies of 51 to 1,000 employees. The review records it displays carry incentivized, seller-invited labels. [s6, s14, s8, s11, s3, s13, s18, s24]
The company is older than its current name. Startup Daily reports that UpGuard was founded in 2012 as ScriptRock by Mike Baukes and Alan Sharp-Paul, and the SEC filing index records the same entity under the former name ScriptRock Inc. through August 2014.
Leadership is published as a roster rather than as biographies. The about page names Mike Baukes as co-founder and chief executive alongside a chief product officer, chief operating officer, chief financial officer, chief information security officer, chief marketing officer, chief revenue officer and chief of staff, without prior roles for any of them, so the team's public track record is the research the company publishes rather than the executives' histories.
The durable public signal is the research. UpGuard's breach research index carries dated posts with a named author through 2025 and 2026, its published research guidelines describe a disclosure process reviewed quarterly with outside counsel, CyberScoop credited an UpGuard analyst with the 198-million-voter exposure in 2017, and SecurityBrief covered its streaming and betting research in June 2026. [s18, s21, s9, s16, s15, s19, s20]
What UpGuard documents about itself is enterprise assurance plus one state certification. Its security page states the company is SOC 2 Type II compliant with annual attestation, that the security program is maintained in alignment with ISO/IEC 27001, and that a third party runs application penetration testing annually, and a separate August 2023 announcement records TX-RAMP certification under the Texas program for cloud services sold to state agencies and public colleges. Reports are available to current customers through a shared profile, and the page documents no other route to them.
Data location is sold as a paid control. Premium Assurance lets a customer store data in the US, Australia, the EU, India or Canada, which UpGuard positions against GDPR and APRA obligations, and the pricing page marks data residency as an additional cost.
The research team's data handling is written down in unusual detail. The guidelines state that analysts only research publicly accessible data, that no analysed data is uploaded to cloud services, and that on purge the decryption key is deleted and overwritten before the encrypted container is destroyed. [s10, s12, s8, s15]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Bitsight | competes with | UpGuard publishes a side-by-side comparison page against Bitsight, and both sell continuous security ratings into third-party risk programs. | |
| SecurityScorecard | competes with | Each vendor names the other in its own comparison material, with SecurityScorecard publishing a page on why customers choose it over UpGuard. | |
| CyberGRX | competes with | UpGuard lists CyberGRX among the four vendors it publishes comparison pages against. | |
| RiskRecon | competes with | UpGuard lists RiskRecon among the four vendors it publishes comparison pages against. |
Add analyzed competitors to compare them side by side with UpGuard.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
What UpGuard has accumulated is a record of how millions of companies looked from the outside, collected daily by its own scanners and scored out of 950. UpGuard describes its collection methods as commercial, open-source and proprietary rather than naming an exclusive input, so a funded rival would have to match the same reach. Its breach-research team deletes the exposed data it examines once no involved party still needs it, by its own published policy, so that work earns attention rather than a retained store. Most defensible for a mid-market team that wants vendor ratings, questionnaires and attack-surface data from one supplier, weakest where procurement wants assurance beyond SOC 2 Type II and a Texas state certification.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | UpGuard delivers software its customers configure and run, with the platform returning ratings, assessments and alerts the customer's own team acts on. A designated-analyst assessment service is sold beside the product rather than inside it. UpGuard's own comparison page states that operating the platform does not require a professional services engagement, which puts the delivered artifact at the software-product level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | A customer builds up a vendor inventory, questionnaire history and remediation workflows inside the platform, and wires it to ticketing, chat and identity systems drawn from a catalog of more than 100 connectors, which is the data history, integrations and learned workflows this level names. The cited record documents no state that cannot be exported and does not size a migration, so the switching mechanism is documented and the exit is not sized. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | UpGuard documents SOC 2 Type II with annual attestation, a security program it states is maintained in alignment with ISO/IEC 27001, and TX-RAMP certification announced in August 2023 under the Texas program that certifies and continuously monitors cloud services for state agencies and public colleges. The cited record names no Texas public-sector customer whose replacement that certification would block, so what it evidences is enterprise entry cost rather than a barrier. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | UpGuard runs its own scanning infrastructure across the internet-facing properties of millions of companies, refreshes vendor ratings multiple times a day, and folds the results into a weighted scoring model whose ten categories carry fixed-weight checks, alongside open, deep and dark web collection. That is internet-scale scanning infrastructure and algorithmic scoring work rather than integration effort. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The evidenced buyers include regulated enterprises: UpGuard names Intercontinental Exchange, Morningstar and IAG as customers, and G2 counts 64 financial services reviews among the 735, ahead of every other named industry. UpGuard also aims at the mid-market and opens paid plans at $1,750 a month, so regulated accounts are part of a broad mid-market base rather than the whole of it. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | UpGuard is an application its customers log into, extended by a REST API, webhooks and more than 100 connectors that push risk data into ticketing, chat and identity systems. Other tools consume its findings, and the cited record shows no system that depends on it to run, which is the platform level rather than infrastructure. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | The evidenced asset is rating history: UpGuard says it monitors billions of data points across millions of companies and that the product shows changes in ratings between any given time periods, which is accumulation the vendor holds rather than tenant data it holds for a customer. Its own pages describe the inputs as commercial, open-source and proprietary methods rather than naming an exclusive one, so a funded rival could accumulate comparable history with time and reach, and UpGuard's own August 2026 announcement sizes the corpus at more than 14 million pre-scored organizations. |
UpGuard's declared target and its named customers pull in different directions. Its chief executive told Startup Daily the Series C accelerates enterprise-grade solutions for the mid-market, and the Bitsight comparison page says UpGuard fits mid-market teams that deploy quickly. The same page names Intercontinental Exchange, Morningstar, TDK, PagerDuty, Hopin and IAG as customers.
Industry pages carry the vertical story. UpGuard publishes industry pages for education, financial services and technology, and its compliance pages address ISO 27001, NIST, DORA, the SIG questionnaires and APRA CPS 230, which is the obligation set a regulated buyer arrives with.
Geography is split between two homes. Startup Daily reports the company is headquartered in Hobart, Tasmania with US headquarters in Mountain View, California, and the chief executive is quoted saying the business has customers in 90 countries and staff in 14.
G2's reviewer profile is the one segmentation record UpGuard does not write. It counts 282 reviews from companies of 51 to 1,000 employees and 77 from companies below 50, spreads them across Asia, North America, ANZ and Europe, and names financial services 64 times against 63 for information technology services.
The scanning and scoring engine is the capability the ratings run on. UpGuard describes proprietary scanning infrastructure collecting billions of data points daily through commercial, open-source and proprietary methods, focused on non-invasive passive collection, and says it monitors billions of data points across millions of companies.
The score is specified rather than asserted. Checks feed a rating out of 950 per internet-facing property, points are subtracted by severity and weight, the organization-level score is a Gaussian weighted average that gives the lowest asset score the most weight, and the checks inside each of ten categories carry fixed weights. UpGuard says its in-house research team adds new checks over time and changes the algorithm with them.
AI is scoped to named jobs. Threat triage, document analysis behind the security profile, and questionnaire autofill are each described as specific tasks, and UpGuard publishes its own usage measurements, including more than 100 billion risk signals a day and 23 billion tokens processed in 100 days.
In the reviewed sources, one third-party evaluation of this market ranks the product and one analyst market guide lists it. Forrester's 2024 cybersecurity risk ratings evaluation ranked UpGuard a Contender, a tier below the Strong Performers and outside the leaders, and the Information Security Media Group report on it names UpGuard once, in that tier list. Forrester published a further edition of the evaluation in April 2026, and UpGuard separately announced a Representative Vendor listing in a 2022 Gartner market guide for IT vendor risk management.
The motion starts with free software and published prices. Trust Exchange is free with no credit card and no sales call, a free tier monitors up to five vendors, and paid plans are listed rather than quoted, which UpGuard contrasts with rivals on its own comparison pages.
Research is the attention engine. The breach research index publishes dated investigations under a named author through 2025 and 2026, and the guidelines state that UpGuard works with media under embargo and never approaches a breached entity in a sales capacity, which separates the research brand from the sales motion in writing.
Proof for buyers is a library of named references. Case studies name Morningstar, Colorado State University, St John WA and Intercontinental Exchange, and G2 carries 735 reviews of Vendor Risk at 4.5 out of 5.
Vendor Risk is the priced anchor. The Standard plan is $1,750 a month billed annually and monitors 50 vendors, additional vendors cost $79 a month, and the Professional, Corporate, Enterprise and Enterprise+ tiers move to contact-sales pricing while adding vendor slots, fourth-party visibility, audit logging and multi-org accounts.
Packaging separates the products a buyer can start with. Trust Exchange is free, with premium features such as custom domains and white labeling behind a paid plan, and the Bitsight comparison page says one license covers both monitoring and assessments.
Enterprise controls are a paid tier of their own. Premium Assurance carries data residency, a designated customer success manager and priority support, and the pricing page marks data residency as an additional cost on top of it.
The platform is software the customer's team operates. UpGuard runs it on Google Cloud Platform, ships from Kubernetes containers on a fortnightly release cycle, and states that operating the platform does not require a professional services engagement.
A human assessment service exists beside the product rather than inside it. UpGuard allocates a designated analyst who collects documentation, liaises with vendors and performs an in-depth risk assessment, and markets it for assessment backlogs, program launches and audit preparation.
Support is tiered with the plan. Standard support carries defined response times on the lower plans, and Premium Assurance adds accelerated service levels, a designated customer success manager and extended weekday technical support.
What UpGuard documents about itself is enterprise assurance plus one state certification. The security page states SOC 2 Type II compliance with annual attestation, a security program maintained in alignment with ISO/IEC 27001, encryption at rest and in transit, and annual third-party application penetration testing. A separate announcement records TX-RAMP certification in August 2023, under the Texas program for cloud services sold to state agencies and public colleges.
The attestation goes to customers rather than to the public. UpGuard says a current customer can access its reports through a shared profile, and its security page documents no other route to them. The same page states that the company runs no bug bounty program and pays no monetary rewards for findings.
The research team's handling of other people's data is the most specific commitment on the site. The guidelines state analysts only research publicly accessible data, never crack third-party encryption, keep downloads on physical media, and delete the decryption key and overwrite the container once no involved party still needs the data.
The platform is built to push its findings outward. UpGuard documents a REST API and webhooks, and says Risk Automations adds more than 100 native integrations including Jira, ServiceNow, Microsoft Entra, Slack and Cloudflare.
Automation is positioned as the difference between reporting and resolving. UpGuard describes turning a risk signal into vendor onboarding, score-drop triage, ticket creation, alerting and system-level actions such as blocking an address or forcing a credential reset.
Trust Exchange extends the platform to the other side of the transaction. A supplier answers questionnaires and publishes a trust page at no cost, which puts UpGuard in front of organizations that are not its customers.
The founding pair and the current roster are separate records. Startup Daily reports UpGuard was founded in 2012 as ScriptRock by Mike Baukes and Alan Sharp-Paul, the 2021 SEC Form D lists both as executive officers, and the about page today names Mike Baukes as co-founder and chief executive, with no role recorded there for Sharp-Paul.
The executive team is published as names and titles. Chief product, operating, financial, information security, marketing and revenue officers each appear on the about page, along with a chief of staff, and no prior role is recorded for any of them there, so their track records are not part of what that page offers a reader.
The research team is the part of the organization with a public output record. Its guidelines describe a documented breach research process reviewed quarterly with outside counsel, and its index carries dated investigations under a named author.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | UpGuard: about page | official | 2026-08-20 |
| f2 | Startup Daily: Tassie cybersecurity scaleup Upguard pockets $105 million Series C | press | 2026-08-20 |
| f3 | UpGuard: homepage | official | 2026-08-20 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | UpGuard: homepage “Cut cyber risk with the only platform that spans your supply chain, attack surface, workforce, and trust relationships.” | official | 2026-08-20 |
| s2 | UpGuard: platform page “Transform how you manage cyber risk with the CRPM platform that unifies risk detection, inference, orchestration & scoring across your entire organization.” | official | 2026-08-20 |
| s3 | UpGuard: Vendor Risk product page “Instantly understand vendor security posture with industry-leading ratings updated multiple times per day.” | official | 2026-08-20 |
| s4 | UpGuard: Breach Risk product page “Monitor the dark, deep, and open web for emerging threats, compromised credentials, and other cybercriminal activity.” | official | 2026-08-20 |
| s5 | UpGuard: User Risk product page “User Risk maps hidden applications, blocks risky file uploads, intercepts sensitive copy-pastes in mid-air, and redirects users to approved corporate AI alternatives.” | official | 2026-08-20 |
| s6 | UpGuard: Trust Exchange product page “Yes, it’s really free! Anyone can use Trust Exchange to answer questionnaires and create a Trust Page. No credit card or sales call to get up and running.” | official | 2026-08-20 |
| s7 | UpGuard: security ratings methodology page “UpGuard’s proprietary scanning infrastructure monitors & collects billions of data points daily through trusted commercial, open-source, and proprietary methods.” | official | 2026-08-20 |
| s8 | UpGuard: pricing page “Standard $1,750 /mo, billed annually” | official | 2026-08-20 |
| s9 | UpGuard: about page “Founded in 2012, UpGuard is a leader in cybersecurity and risk management.” | official | 2026-08-20 |
| s10 | UpGuard: security page “UpGuard is committed to securely managing your data. UpGuard is SOC 2, Type II compliant, and undergoes attestation on an annual basis.” | official | 2026-08-20 |
| s11 | UpGuard: customers page “Thousands of global companies trust UpGuard to reduce their cyber risk” | official | 2026-08-20 |
| s12 | UpGuard: TPRM services page “A designated analyst is allocated to your security team to manage vendor assessments.” | official | 2026-08-20 |
| s13 | UpGuard: Series C announcement “Hobart, Tasmania and Mountain View, California - February 26, 2026 - UpGuard , a leader in cybersecurity and risk management, today announced it has raised a Series C funding round of $75M from Springcoast Partners.” | official | 2026-08-20 |
| s14 | UpGuard: Bitsight comparison page “UpGuard customers include Intercontinental Exchange (NYSE: ICE), Morningstar, TDK, PagerDuty, Hopin, and IAG.” | official | 2026-08-20 |
| s15 | UpGuard: cyber risk research guidelines “The UpGuard Cyber Risk Research team finds publicly exposed data, helps the owners secure it, and shares information on how these exposures can be avoided.” | official | 2026-08-20 |
| s16 | UpGuard: breach research index “Own Goal: Inside the Cyber Risks of the 2026 World Cup” | official | 2026-08-20 |
| s17 | UpGuard: APRA CPS 230 compliance page “APRA's Prudential Standard CPS 230 is a regulatory requirement that aims to improve the resilience of financial institutions against disruptions. The new standard takes effect from July 1st, 2025 .” | official | 2026-08-20 |
| s18 | Startup Daily: Tassie cybersecurity scaleup Upguard pockets $105 million Series C “Tassie cybersecurity scaleup Upguard pockets $105 million Series C - Startup Daily” | press | 2026-08-20 |
| s19 | CyberScoop: 200 million registered voters exposed due to open AWS repository “A misconfigured database containing sensitive personal information of 198 million American voters was left exposed to the internet for 12 days by a Republican data analysis firm, the largest known data exposure of its kind.” | press | 2026-08-20 |
| s20 | SecurityBrief: UpGuard links pirate football streams to offshore betting “UpGuard has published research linking exposed customer data to illegal streaming and offshore gambling operations tied to football viewing.” | press | 2026-08-20 |
| s21 | SEC EDGAR: UpGuard, Inc. company filing index “UpGuard, Inc. CIK #: 0001615311 (see all company filings)” | regulatory | 2026-08-20 |
| s22 | SEC EDGAR: UpGuard, Inc. Form D primary document “entityName: UpGuard, Inc.” | regulatory | 2026-08-20 |
| s23 | SecurityScorecard: SecurityScorecard vs UpGuard comparison page “Why customers choose SecurityScorecard over UpGuard” | official | 2026-08-20 |
| s24 | G2: UpGuard Vendor Risk product and reviews page “UpGuard Vendor Risk Reviews (735)” | research | 2026-08-20 |
| s25 | Information Security Media Group: Bitsight, SecurityScorecard, Panorays Lead Risk Ratings Tech “Strong Performers: Black Kite, RiskRecon, BlueVoyant, Recorded Future Contenders: UpGuard, Prevalent Challengers: ISS Corporate Solutions” | press | 2026-08-20 |
| s26 | Forrester: Cyber Risk Ratings Fade Out, Actionable Intelligence Takes The Spotlight “Cyber Risk Ratings Fade Out; Actionable Intelligence Takes The Spotlight Paul McKay , VP, Principal Analyst Apr 14 2026” | research | 2026-08-20 |
| s27 | UpGuard: TX-RAMP certification announcement “UpGuard’s TX-RAMP certification comes in addition to its alignment with ISO/IEC 27001 and annual SOC 2, Type II certification.” | official | 2026-08-20 |
| s28 | UpGuard: Google Cloud Marketplace availability announcement “Mountain View, California - August 12, 2026 - UpGuard , a leader in cybersecurity and risk management, today announced that UpGuard is now available on Google Cloud Marketplace .” | official | 2026-08-20 |
| s29 | UpGuard: 2022 Gartner Market Guide listing announcement “UpGuard, the third-party risk and attack surface management platform, has been recognized as a Representative Vendor in the 2022 Gartner Market Guide for IT Vendor Risk Management Solutions report.” | official | 2026-08-20 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | UpGuard: homepage “Cut cyber risk with the only platform that spans your supply chain, attack surface, workforce, and trust relationships.” | official | 2026-08-20 |
| s2 | UpGuard: platform page “Transform how you manage cyber risk with the CRPM platform that unifies risk detection, inference, orchestration & scoring across your entire organization.” | official | 2026-08-20 |
| s3 | UpGuard: Vendor Risk product page “Instantly understand vendor security posture with industry-leading ratings updated multiple times per day.” | official | 2026-08-20 |
| s4 | UpGuard: Breach Risk product page “Monitor the dark, deep, and open web for emerging threats, compromised credentials, and other cybercriminal activity.” | official | 2026-08-20 |
| s5 | UpGuard: User Risk product page “User Risk maps hidden applications, blocks risky file uploads, intercepts sensitive copy-pastes in mid-air, and redirects users to approved corporate AI alternatives.” | official | 2026-08-20 |
| s6 | UpGuard: Trust Exchange product page “Yes, it’s really free! Anyone can use Trust Exchange to answer questionnaires and create a Trust Page. No credit card or sales call to get up and running.” | official | 2026-08-20 |
| s7 | UpGuard: security ratings methodology page “UpGuard’s proprietary scanning infrastructure monitors & collects billions of data points daily through trusted commercial, open-source, and proprietary methods.” | official | 2026-08-20 |
| s8 | UpGuard: pricing page “Standard $1,750 /mo, billed annually” | official | 2026-08-20 |
| s9 | UpGuard: about page “Founded in 2012, UpGuard is a leader in cybersecurity and risk management.” | official | 2026-08-20 |
| s10 | UpGuard: security page “UpGuard is committed to securely managing your data. UpGuard is SOC 2, Type II compliant, and undergoes attestation on an annual basis.” | official | 2026-08-20 |
| s11 | UpGuard: customers page “Thousands of global companies trust UpGuard to reduce their cyber risk” | official | 2026-08-20 |
| s12 | UpGuard: TPRM services page “A designated analyst is allocated to your security team to manage vendor assessments.” | official | 2026-08-20 |
| s13 | UpGuard: Series C announcement “Hobart, Tasmania and Mountain View, California - February 26, 2026 - UpGuard , a leader in cybersecurity and risk management, today announced it has raised a Series C funding round of $75M from Springcoast Partners.” | official | 2026-08-20 |
| s14 | UpGuard: Bitsight comparison page “UpGuard customers include Intercontinental Exchange (NYSE: ICE), Morningstar, TDK, PagerDuty, Hopin, and IAG.” | official | 2026-08-20 |
| s15 | UpGuard: cyber risk research guidelines “The UpGuard Cyber Risk Research team finds publicly exposed data, helps the owners secure it, and shares information on how these exposures can be avoided.” | official | 2026-08-20 |
| s16 | UpGuard: breach research index “Own Goal: Inside the Cyber Risks of the 2026 World Cup” | official | 2026-08-20 |
| s17 | UpGuard: APRA CPS 230 compliance page “APRA's Prudential Standard CPS 230 is a regulatory requirement that aims to improve the resilience of financial institutions against disruptions. The new standard takes effect from July 1st, 2025 .” | official | 2026-08-20 |
| s18 | Startup Daily: Tassie cybersecurity scaleup Upguard pockets $105 million Series C “Tassie cybersecurity scaleup Upguard pockets $105 million Series C - Startup Daily” | press | 2026-08-20 |
| s19 | CyberScoop: 200 million registered voters exposed due to open AWS repository “A misconfigured database containing sensitive personal information of 198 million American voters was left exposed to the internet for 12 days by a Republican data analysis firm, the largest known data exposure of its kind.” | press | 2026-08-20 |
| s20 | SecurityBrief: UpGuard links pirate football streams to offshore betting “UpGuard has published research linking exposed customer data to illegal streaming and offshore gambling operations tied to football viewing.” | press | 2026-08-20 |
| s21 | SEC EDGAR: UpGuard, Inc. company filing index “UpGuard, Inc. CIK #: 0001615311 (see all company filings)” | regulatory | 2026-08-20 |
| s22 | SEC EDGAR: UpGuard, Inc. Form D primary document “entityName: UpGuard, Inc.” | regulatory | 2026-08-20 |
| s23 | SecurityScorecard: SecurityScorecard vs UpGuard comparison page “Why customers choose SecurityScorecard over UpGuard” | official | 2026-08-20 |
| s24 | G2: UpGuard Vendor Risk product and reviews page “UpGuard Vendor Risk Reviews (735)” | research | 2026-08-20 |
| s25 | Information Security Media Group: Bitsight, SecurityScorecard, Panorays Lead Risk Ratings Tech “Strong Performers: Black Kite, RiskRecon, BlueVoyant, Recorded Future Contenders: UpGuard, Prevalent Challengers: ISS Corporate Solutions” | press | 2026-08-20 |
| s26 | Forrester: Cyber Risk Ratings Fade Out, Actionable Intelligence Takes The Spotlight “Cyber Risk Ratings Fade Out; Actionable Intelligence Takes The Spotlight Paul McKay , VP, Principal Analyst Apr 14 2026” | research | 2026-08-20 |
| s27 | UpGuard: TX-RAMP certification announcement “UpGuard’s TX-RAMP certification comes in addition to its alignment with ISO/IEC 27001 and annual SOC 2, Type II certification.” | official | 2026-08-20 |
| s28 | UpGuard: Google Cloud Marketplace availability announcement “Mountain View, California - August 12, 2026 - UpGuard , a leader in cybersecurity and risk management, today announced that UpGuard is now available on Google Cloud Marketplace .” | official | 2026-08-20 |
| s29 | UpGuard: 2022 Gartner Market Guide listing announcement “UpGuard, the third-party risk and attack surface management platform, has been recognized as a Representative Vendor in the 2022 Gartner Market Guide for IT Vendor Risk Management Solutions report.” | official | 2026-08-20 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.