> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Vendor Summary

> AI-powered overview of a vendor's security posture, certifications, and risk score.

The Vendor Summary provides a comprehensive, AI-generated analysis of any vendor's security posture. This page helps both technical and non-technical stakeholders understand vendor risk at a glance.

## Vendor profile

At the top, you will see the vendor's **logo**, **domain**, **overall security score** (0–1000), **tier**, **portfolio**, and **business label**. You can edit any of these classifications directly.

## Score trend

A month-over-month chart shows how the vendor's security score has changed over time. Automated vendors are re-queued for a fresh scan once their last scan is more than a month old, so expect the trend line to move about monthly.

## Compliance certifications

The summary displays which certifications the vendor holds — such as ISO 27001, SOC 2, or GDPR compliance — so you can quickly assess regulatory alignment.

## 10 security assessment categories

DSALTA evaluates every vendor by scanning their domains and IP addresses across **10 categories**:

<CardGroup cols={2}>
  <Card title="Application Security" icon="code">
    Web application protections, secure headers, and app-level vulnerabilities.
  </Card>

  <Card title="Network Security" icon="network-wired">
    Open ports, firewall configuration, and network exposure.
  </Card>

  <Card title="Endpoint & OS Security" icon="laptop">
    OS patching, endpoint protection, and device security.
  </Card>

  <Card title="IP Reputation" icon="globe">
    Blocklist presence and IP address reputation.
  </Card>

  <Card title="DNS & Email Security" icon="envelope">
    SPF, DKIM, DMARC configuration strength.
  </Card>

  <Card title="Information Leakage" icon="eye-slash">
    Exposed credentials, misconfigured storage, data leaks.
  </Card>

  <Card title="Vulnerability Exploitation" icon="bug">
    Known exploited vulnerabilities and unpatched systems.
  </Card>

  <Card title="Dark Web & Chatter" icon="mask">
    Mentions on dark web forums, breach databases, paste sites.
  </Card>

  <Card title="Security Best Practices" icon="check-double">
    HTTPS enforcement, certificate validity, security hygiene.
  </Card>

  <Card title="Social Engineering" icon="user-secret">
    Susceptibility to phishing and impersonation attacks.
  </Card>
</CardGroup>

Each category receives a weighted score that contributes to the overall 0–1000 rating.

<Tip>
  Share the vendor summary with procurement or leadership teams — the AI-generated narrative makes vendor risk understandable without requiring security expertise.
</Tip>

## Related pages

* [Risk History](/guides/vendors/risk-history)
* [Risk Assessment](/guides/vendors/risk-assessment)
