LocateRisk

LocateRisk scores a target's cyber risk from the outside, passively and without the target's involvement, across sourcing, diligence and integration.

LocateRisk, based in Darmstadt, provides automated, non-invasive external attack surface analysis and security ratings. Any target can be scored passively from its domain alone, without agents, credentials or the target's involvement, so cyber risk becomes measurable before first contact and before data room access. Deal teams use it to pre-screen targets in sourcing, to quantify and price cyber exposure in due diligence, to map third-party dependencies, and to monitor portfolio companies after closing.

Key Features

  • Passive outside-in scoring from a domain alone

  • Attack surface discovery incl. shadow IT of previously acquired units

  • KPI-based security rating with peer benchmark

  • Longlist screening before the LOI

  • Third-party and supply chain dependency mapping

  • CVE-based vulnerability detection with remediation priorities

  • Scan-to-scan diff for integration and portfolio monitoring

AI Capabilities

AI helper functions interpret vulnerability data in plain language for non-technical deal teams, generate remediation recommendations and connect findings to external LLMs via MCP interface.

Integrations

REST API for exporting reports and findings; PDF/CSV export for data rooms; MCP interface for external LLMs; connectors to SIEM platforms such as Sekoia.io; SSO via Entra ID / SAML

More Information

Sourcing: screen a longlist passively, only the domain is needed, so targets are assessed before any approach. Diligence: security score, category KPIs, peer benchmark and a prioritised finding list; typical deal red flags are end-of-life systems, unpatched vulnerabilities, exposed admin interfaces, weak email authentication (payment-fraud risk during a live deal) and shadow IT from earlier acquisitions. Integration: scan-to-scan diff evidences which findings were actually closed and how the combined attack surface develops. Hold period: continuous monitoring and alerts across all holdings with group reporting. Only publicly reachable information is evaluated and no exploitation is attempted, so no scanning agreement, no system access and no involvement of the target's IT are required.

What sets it apart

  1. Passive scoring before the LOI, no contact or data room needed

  2. KPI-based score with peer benchmark for IC and pricing

  3. German provider; GDPR-compliant; KRITIS and public sector

Key Facts

Category
Cybersecurity / IT Diligence
Founded
2018
Pricing
SaaS subscriptions priced by number of monitored entities and scan frequency; single-target assessments for one-off deal work, portfolio packages for recurring monitoring of holdings.
Target Market
Corporate M&A, Private Equity, M&A Advisory