Security tool servers are assessed with elevated scrutiny on Dimension 4 (security posture) — a server providing security capabilities must itself demonstrate secure practices. The specific concern: security tools often require elevated permissions to do their job, and those permissions must be scoped minimally. A vulnerability scanner that requests filesystem read access to scan a single directory is over-permissioned. Assessment notes for this category document the permission model explicitly.
No assessed servers in this category yet.
Submit a server for assessment.
Missing a server? Submit it for assessment.
How scores are calculated →