Vulnerability Scanning (external)
Use Trust Chain to run external security checks against your vendors' public domains and review detailed findings by check category
Written By Micah
Trust Chain builds your picture of vendor risk from the evidence your vendors submit, which Verify AI reviews on your behalf. External vulnerability scanning adds a second, independent signal: Strike Graph runs security checks against a vendor's public-facing domains and reports what it finds.
The scanner automatically discovers subdomains through certificate transparency logs, so it covers more of a vendor's actual public footprint rather than checking only the apex domain. You get a read on a vendor's external security posture without waiting for that vendor to upload a single document, and the result comes from Strike Graph's direct observation rather than the vendor's self-attestation.
What the external scan checks
An external scan runs unauthenticated checks against a vendor's public domains (including auto-discovered subdomains), in the same way a browser or a mail server would interact with them. Five categories of checks make up a scan:
TLS configuration: whether the domain still accepts insecure protocols (SSLv2, SSLv3) or deprecated ones (TLS 1.0, TLS 1.1), whether weak ciphers are enabled, and whether it supports modern TLS (1.2 or 1.3).
Certificate validity: whether the domain's TLS certificate is trusted, correctly matched to the domain, not expired or expiring soon, and not signed with a weak algorithm.
HTTP security headers: whether the standard browser-facing security headers are in place, and whether responses reveal software version details.
DNS and email hygiene: whether SPF and DMARC records exist and actively enforce anti-spoofing rather than only monitoring it. SPF and DMARC are checked on the vendor's primary domain only, because email configuration almost always lives at the main domain and checking subdomains would mostly surface false positives.
Certificate transparency: a lookup against public certificate transparency logs to surface how many certificates have been issued for the domain and by which issuers. This check is informational and is not counted toward the coverage score.
The first four checks are required and contribute to the vendor's coverage score. Certificate transparency is reported for context only.
What the external scan does not do
External scans are limited to standard DNS, HTTP, and TLS interactions with a vendor's public domains. Specifically, we do not:
Scan ports or probe non-standard ports
Send exploit or injection payloads
Attempt to authenticate to, or log into, any vendor system
Reach internal or private network addresses
Ingest data from third-party ratings or exposed-surface providers
Because the checks are unauthenticated and non-exploitative, direct authorization from the vendor is not required before running them.
Who can run an external vulnerability scan
External vulnerability scanning is part of the paid Trust Chain and is not included with the free Trust Chain vendor allowance. Managers can trigger scans and view results from the vendor detail page.
If you do not see scan functionality on your vendors, it may not be enabled for your organization yet. Reach out to support or your Customer Success Manager to request access.
Running an external scan on a vendor
Open Trust Chain and select the vendor you want to scan.
Locate the External Vulnerability Scan panel on the vendor detail page.
Select a domain from the Domain to scan dropdown. If the vendor has more than one domain on file, choose the one you want scanned.
Click Run scan.
Scans run in the background. Most complete within seconds to a couple of minutes, and the panel shows a "Scan in progress" status while the checks run. Results appear when the run finishes.
Each vendor can be scanned once within a cooldown window. If a scan has already run for a vendor recently, the Run scan button will be disabled and a tooltip shows when the next scan is available.
About the scanned domain
The primary scan target comes from the vendor's contact email address, so it may be a corporate or marketing domain rather than the one hosting the vendor's product. From that starting point, the scanner uses certificate transparency logs to discover additional subdomains. Each scan covers up to three domains: the primary domain and up to two discovered subdomains.
When the scan covers discovered domains beyond the one you selected, an info icon appears next to the scanned domain in the results. Hover over it to see which additional domains were reviewed.
Reading external scan results
Scan results are organized into two layers: a high-level rollup at the top of the panel and a detailed checks section below it.
The scan rollup
The rollup provides an at-a-glance summary with five data points:
Status: the overall state of the scan (Not yet scanned, Scan in progress, Scan complete, Complete with errors, or Scan failed). This describes how much of the vendor was measured, not the vendor's security posture. Hover over the info icon for an explanation of each status.
Coverage: a percentage representing how many of the required checks reported a definitive result. Below the bar, the count shows how many required checks reported out of the total.
Findings: the total number of issues found, displayed as a severity-weighted color bar spanning critical, high, medium, low, and info levels.
Scanned domain: the primary domain that was scanned, with a tooltip for any additional discovered domains.
Last scan: the date the most recent scan completed.
The checks section
Below the rollup, each check is listed as an expandable row. The row header shows the check name and a badge indicating its outcome:
Passed (green): the check ran and found no issues.
Issues found (severity badges): the check surfaced one or more findings, shown as severity counts (e.g., "1 High, 2 Medium").
Could not check: the scanner could not get a representative response from the host (for example, a WAF block or an error page).
Not run: the check was not executed.
Not applicable: the check does not apply to this domain.
Not reported: the check did not report in the latest scan.
Expand a check to see what the scanner observed. For checks that passed, the detail shows a summary of what was found (for example, "TLS 1.2 and TLS 1.3 accepted" or "Certificate valid for another 88 days"). For checks with findings, the detail shows the individual finding cards.
When the scan covered multiple hosts, each check displays per-host observations so you can see exactly what was found on each domain.
Finding cards and finding detail
Each finding appears as a card showing its severity, title, the affected domain, and the affected endpoint. Click a finding to open its full detail, which includes:
Severity level: Critical, High, Medium, Low, or Info
Affected domain: the specific host this finding was observed on
Affected endpoint: the URL or resource where the issue was found
Description: what the scanner observed
Remediation guidance: steps the vendor can take to resolve the issue
First seen / Last seen dates: when the finding was first detected and when it was most recently confirmed
Finding severity levels
Findings are ranked by severity from highest to lowest: Critical, High, Medium, Low, and Info. The severity strip in the rollup uses color to show the distribution across these levels, and findings within each check are ordered highest-severity first.
Why findings change between scans
Findings persist across scans. When a vendor fixes an issue, that finding drops out of the results on the next scan. If a finding was raised in an earlier scan but is not raised in the latest run, it remains listed under its check with a note: "Still open from an earlier scan — the latest scan did not raise it."
The vendor's view of their scan results
Vendors can see their own scan results in Strike Graph on a dedicated Vulnerability Scan page. The same rollup, checks, and findings are shown, with two differences:
Vendor-only findings: some findings may be marked as not shared with customers. Vendors see all findings — both shared and vendor-only — while customers see only the shared ones. Each finding card displays a visibility badge so the vendor knows which results their customers can see.
Re-scanning: after the first scan (triggered by a customer), the vendor can re-run the scan on their own using the Re-run scan button. The vendor cannot trigger the initial scan, and they cannot see which customer initiated it.
Remediation statuses
Vendors can track the status of each finding using remediation statuses visible on the finding cards: Open, Acknowledged, In progress, Resolved, or Won't fix. These statuses are managed by the vendor and persist across rescans.
How external scan results are shared
Strike Graph scans each vendor once and shows the same results to every customer of that vendor who has scanning enabled. If a peer also manages this vendor in Trust Chain, they see the same shared findings you see.
Troubleshooting external scans
No scan target available
If no domain is available in the dropdown, there is nothing for the scan to check. Confirm that the vendor record includes a contact email at the vendor's own domain rather than at a public email provider
A check errored or could not complete
Errored checks are usually environmental: a firewall blocking automated requests, a DNS resolver timing out, or an endpoint that is temporarily unreachable will produce a "Could not check" result rather than a finding. Running the scan again later often resolves it.
"Complete with errors" status
This status means the scan finished but some checks could not run on some hosts, usually because a host did not respond. It describes how much of the vendor was measured, not the vendor's security. The findings below the rollup show what was actually found.
Results seem out of date
Scans reflect the point in time when they ran. Check the "Last scan" date in the rollup, and run a new scan if you need a current read.
Scan cooldown
If the Run scan button is disabled and the tooltip says a scan was run recently, wait for the cooldown period to pass before running another.
Need More Help?
If you encounter any issues with external vulnerability scanning or have questions about scan results, reach out through our in-app messenger. We're here to help.
Was this helpful?
More in Trust Chain
Trust Chain: A Guide for VendorsTrust ChainTry Trust Chain Free: Assess Up to 5 VendorsTrust Chain PricingStill need help? Share an idea