Senserity Help
Changelog

Seven new data sources and 59 new tests

Regulated care inspection, patents, trade marks, operator licensing and Certificate Transparency have all gone live since July, taking Senserity to 34 data sources.

Since the evidence tabs shipped in July, seven new data sources have gone live and 59 new tests have been built on them. This entry collects them in one place.

Regulated care inspection

Senserity now reads all three UK care regulators: the Care Quality Commission in England, Care Inspectorate Wales, and the Care Inspectorate in Scotland. Between them they cover care homes, domiciliary care, supported living, children's services and the rest of the regulated estate.

Twenty-six tests were built on this data. They report registration status, the rating of the weakest location in an estate rather than an average that hides it, how much of an estate sits in the lowest grade bands, leadership and safeguarding assessments, whether ratings are moving up or down, and whether an estate is contracting. Two of them cover situations that should not occur and matter when they do: a care registration still active against a company that has been dissolved, and a registration ended by regulator enforcement rather than by the provider closing it.

Scotland's register does not carry company numbers, so Scottish services are matched on name. That is a weaker link than the English and Welsh matches and is reported as such.

Patents and trade marks

Two sources: the European Patent Office's published patent data, and the UK, EU and international trade mark registers. Eighteen tests report what a company has invented and what it has branded, including how widely each is protected and whether trade marks are still in force.

All eighteen are informational and carry no weight in the risk grade. Most UK companies hold no registered intellectual property and there is nothing wrong with that, so absence is never reported as a finding.

Operator licensing

The Traffic Commissioners' register of goods and public service vehicle operator licences, covering the eight Great Britain traffic areas. Eight tests report whether a licence is held, whether it has been curtailed or suspended, whether a standard licence is running without a transport manager, whether a continuation date has passed, and the authorised fleet size.

Two of them cross-reference against other Senserity data: a licence held by a dissolved company, and a licence held by a company already showing financial distress. Operator licences are granted partly on proof of financial standing, so the second combination is worth knowing about.

Certificate Transparency

The newest source, and the 34th overall. Every certificate authority is required to publish a log entry for each TLS certificate it issues, naming the hostnames that certificate covers. Senserity reads that public record for a company's domain to find its internet-facing estate: mail servers, VPN gateways, customer portals, staging copies of the site, and occasionally the web interface of a firewall or a NAS.

Seven tests report where each name leads, whether its certificate is valid, expired, self-signed or unverifiable, whether it looks like a development environment, a remote access gateway or an equipment management interface, and whether the estate has grown in the last ninety days. Internal hostnames leaked into the public log are reported for information only.

Estate size is deliberately not scored. A managed service provider hosting systems for its customers will have far more hostnames than a professional services firm of the same size, without being any less secure. What is scored is the proportion of certificates that are sound, which compares fairly across estates of any size.

This is not crawling. Senserity reads a published log and then connects to the names it finds in the way a browser would. It does not scan ports, probe for weaknesses, or guess at names that were never published.

Certificate Transparency results appear in a Public hostnames panel on the Cyber tab, and in a Public Hostnames section in the Cyber report. A large estate can run to several hundred names, so the report listing is capped at roughly a page, ordered so that any address with a finding appears before any clean one. The footer states how many addresses were held back and whether any of those had findings, because a capped list that quietly dropped failures would read as a clean bill of health.

One test retired

CYB-031, Subdomain Discovery, has been retired. It was built on a wordlist that guessed at common subdomain names, which Certificate Transparency supersedes entirely: the log lists names that actually exist rather than names that might. Its findings now come through CYB-061 instead.

Where to read more

The test catalogue lists every test with its severity and minimum tier, and the data sources page covers all 34 sources. How Senserity checks cyber risk has been rewritten to cover the hostname estate in full.

On this page