# SecurityScorecard

**Canonical:** https://apis.io/providers/security-scorecard/  
**Website:** https://securityscorecard.com  
**APIs profiled:** 1

SecurityScorecard is a cybersecurity ratings and third-party risk management platform that continuously rates the security posture of any company from the outside in, producing an A-F security score across ten risk factors. Its REST API (base https://api.securityscorecard.io) lets customers manage portfolios of monitored companies, pull scorecards, factor scores, historical trends, issues/findings, industry benchmarks, and generate reports, and react to changes through webhook-driven Rules. Authentication is a static API token ("Authorization: Token <key>"), and first-party npm SDK and CLI packages are published under the @securityscorecard organization. Originally surfaced as a GV (Google Ventures) portfolio company, this profile has been enriched from SecurityScorecard's public developer documentation.

## Kin Score — 51.3 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 51.3).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 51.6 |
| Governance | 0.0 |
| Operational Transparency | 36.8 |
| Developer Ergonomics | 69.6 |
| Commercial Clarity | 60.5 |

## Agent readiness — 45.0 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| MCP Server | yes |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **SecurityScorecard API** — REST API for security ratings, portfolios, scorecards, factor and issue data, historical scores, industry benchmarks, reporting, and webhook Rules.

## MCP servers (1)

- **security-scorecard-mcp.yml**

## Security (3)

- **Security Scorecard Authentication** — apiKey · 1 scheme
- **Security Scorecard Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Security Scorecard Trust Center** — ISO 27001, PCI DSS, HIPAA, GDPR

## Tags

Company, Enterprise, Cybersecurity, Security Ratings, Third-Party Risk, Risk Management, Attack Surface, Compliance

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/security-scorecard/). Scores are computed from the provider's own public artifacts under a published rubric.
