External vendor evidence report
Northstar Cloud Services
A point-in-time view of internet-facing exposure associated with a fictional vendor domain. Findings support review decisions; they do not replace vendor due diligence.
Decision summary
What a reviewer should understand first.
Illustrative score on a 0-100 scale. Higher is better. See methodology for category weights and grade boundaries.
Conditional review recommended
The fictional target presents one high-priority encryption finding and two configuration weaknesses. The evidence is sufficient to request remediation, but it does not establish the vendor's internal control effectiveness or contractual compliance.
Fictional weighted category breakdown
| Category | Score | Weight | Weighted value |
|---|---|---|---|
| TLS | 45 | 20% | 9.00 |
| DNS | 85 | 10% | 8.50 |
| 65 | 15% | 9.75 | |
| Ports | 82 | 20% | 16.40 |
| Headers | 62 | 10% | 6.20 |
| Technology | 78 | 15% | 11.70 |
| Breach | 64 | 10% | 6.40 |
| Total | - | 100% | 67.95, rounded to 68 |
Vendor record
Context supplied for this fictional review.
- Business owner
- Fictional: Maya Chen
- Criticality
- High
- Data access
- Customer contact data
- Renewal date
- 2026-11-30
- Inherent risk
- High
- Review status
- Remediation requested
Findings
Illustrative observations ranked by potential decision impact.
| ID | Finding | Severity | Confidence | Evidence |
|---|---|---|---|---|
F-001 | Legacy TLS protocol acceptedA fictional endpoint accepted TLS 1.0 during the sample observation. | High | Confirmed Direct handshake | EV-001 |
F-002 | DMARC policy not enforcedThe fictional DNS response used a monitoring-only policy. | Medium | Confirmed Direct DNS record | EV-002 |
F-003 | Security headers incompleteTwo recommended browser response headers were absent from the fictional response. | Medium | Observed Single-path response | EV-003 |
F-004 | Certificate renewal windowA fictional certificate was within 28 days of expiry. | Low | Confirmed Presented certificate | EV-004 |
Evidence register
Every sample finding points to a specific fictional observation.
TLS handshake transcript
edge.northstar-cloud.example:443 / protocol offered: TLS 1.0 / observed 2026-07-24 14:31 UTC.
DNS TXT response
_dmarc.northstar-cloud.example / fictional policy value p=none / observed 14:32 UTC.
HTTPS response headers
Fictional root-path response did not include CSP or Permissions-Policy. Other routes were not tested in this sample.
Presented certificate metadata
Fictional leaf certificate expiry: 2026-08-21 23:59 UTC / 28 days from assessment.
Remediation plan
Suggested next actions for the fictional review owner.
- Due: 14 days
Disable legacy TLS versions
Require TLS 1.2 or newer across the affected edge configuration, then provide a retest window.
- Due: 30 days
Move DMARC toward enforcement
Validate mail sources, document exceptions, and progress from monitoring to quarantine or reject based on business impact.
- Due: 30 days
Confirm response-header coverage
Apply the required browser controls consistently and retest representative application routes.
- Due: 7 days
Confirm certificate renewal automation
Verify ownership and renewal monitoring before the fictional expiry date.
Review record and limitations
Decision ownership remains with the organization using the report.