- Application
- Attack
- Certificates
- Certifications
- Compliance
- Configuration Management
- Cyber Risk
- Cybersecurity
Show all 28 topics
- Domain Name System
- Enterprise
- Evidence Collection
- Governance, Risk, and Compliance
- Identity Access Management
- Internet Protocol
- IT Governance
- Monitoring
- on-premises
- Public Sector
- Remediation
- Risk Management
- Security Operations
- Security Posture
- Services
- Software-as-a-Service
- Standards
- Third-Party Risk Management
- Vendor Risk Management
- Visibility
No article in the knowledge graph for UpGuard yet.
Who is UpGuard?
UpGuard is a cybersecurity platform focused on Third-Party Risk Management (TPRM) and attack surface management for enterprise and institutional environments.
- Third-party and Vendor Risk Management (VRM) with security questionnaires, evidence collection, and risk assessments (third-party risk management).
- External attack surface management for discovering, monitoring, and assessing exposed internet-facing assets (attack surface management).
- Security ratings and continuous monitoring of vendors and subsidiaries for cyber risk visibility (security ratings).
- Workflows for remediation, issue tracking, and collaboration between security teams and vendors (governance, risk, and compliance).
- Reporting and analytics for compliance stakeholders, boards, and auditors on vendor and external security posture (security analytics).
Show more
More About UpGuard
UpGuard provides Software-as-a-Service (SaaS) platforms used by enterprises, public sector organizations, and other institutions to manage cyber risk associated with third parties and external attack surfaces. Its offerings focus on two primary domains: TPRM and attack surface management. Security, risk, and compliance teams use UpGuard to gain structured visibility into vendors’ security practices and external exposures and to coordinate remediation activities with internal and external stakeholders.
In TPRM (third-party risk management), UpGuard enables organizations to assess vendors using standardized security questionnaires, custom questionnaires, and supporting evidence such as policies, certifications, and audit reports. The platform centralizes vendor risk data, allowing users to categorize vendors, track questionnaire status, store documentation, and record risk findings. Security ratings (security ratings) and continuous monitoring features provide an additional external signal on vendor posture by scanning internet-facing assets for issues such as misconfigurations, expired certificates, exposed services, or compromised credentials.
For attack surface management (attack surface management), UpGuard discovers and inventories externally reachable assets associated with an organization and its subsidiaries, often using Domain Name System (DNS) records, IP ranges, and other attribution techniques. The platform then evaluates these assets for security issues including open ports, outdated services, misconfigured security controls, and data exposure risks. This supports Security Operations (SecOps) and infrastructure teams that need to reduce their external attack surface and validate that internet-facing systems conform to internal standards and policies.
UpGuard’s architecture is delivered as a cloud-based platform, accessed via web interfaces and programmatic APIs. It relies on network scanning, DNS enumeration, certificate analysis, web application checks, and related techniques to build security ratings and external asset inventories. Integration points typically include ticketing and collaboration tools for remediation workflows, identity and access management for user control, and export capabilities for reports and dashboards consumed by Governance, Risk, and Compliance (GRC) stakeholders.
Compared to generic IT asset management products, UpGuard’s focus is on externally observable security posture and vendor ecosystems rather than deep endpoint or on-premises (on-prem) configuration management. Within enterprise security taxonomies, its offerings align with TPRM, attack surface management, security ratings services, and elements of GRC tooling. Organizations use the platform to support risk assessments during vendor onboarding, periodic vendor reviews, regulatory and contractual compliance checks, and continuous monitoring of both suppliers and their own internet-facing infrastructure.
Our description of UpGuard. Updated December 2025.