CertIQ
Cyber risk for technology companies

Your customers inherit your security posture whether they audit it or not.

If you build software, your weaknesses become your customers' weaknesses. That is why enterprise procurement now asks for evidence before signing, and why a single compromised release pipeline can reach further than any direct attack on you.

Takes 45 seconds · No sales call · Australian businesses

What actually goes wrong

Three ways technology companies get hit.

01
You are the supply chain
A compromise in your build or release process propagates to every customer running your software, at their next update.
02
Sprawling internet-facing surface
Staging environments, preview deployments and internal tools reachable from the internet, usually with weaker controls than production and often forgotten entirely.
03
Credentials in the open
API keys and tokens exposed through repositories, exposed environments, or staff addresses appearing in unrelated breaches.
What we check first

The three that matter most for technology companies.

Your score covers all six checks. These are the ones that most often explain a low score in your industry.

Forgotten systems
Subdomains and old hosts still attached to your domain.
Exposed services
Open ports and remote access visible from the internet.
Leaked passwords
Staff addresses appearing in public breach databases.
Where you stand

The obligations that apply to you.

Privacy Act obligations apply above $3m turnover, but SOC 2 and ISO 27001 expectations arrive from customers well before that, and contractually rather than by statute.

General information only, not legal advice. CertIQ scores your operational posture — it does not assess your compliance.

Every customer
Who inherits a compromise in your release pipeline

See where you actually stand.

Enter your website and CertIQ scores your cyber health out of 100 in about 45 seconds. Free, no account needed.