Quiet Forensics / サービスServices / 取引先セキュリティ審査Supplier security review

取引先管理・委託先管理にFor vendor and supplier management

取引先 20 社の外部公開状況を、
取引先に何も送らずに審査。
Review 20 suppliers' external exposure.
Without contacting any of them.

取引先のドメインを入力して決済すると、証明書透明性ログと公開 DNS だけを読んで審査し、取引先ごとの評価と、供給網全体のリスクをまとめたレポートをお届けします。取引先のサーバにはパケットを一切送らないため、取引先の承諾は不要で、取引先に気づかれることもありません。

Enter your suppliers' domains and pay. We read Certificate Transparency logs and public DNS only, and deliver a report with a per-supplier assessment and the risks that sit across your supply chain. Not a single packet reaches a supplier, so no consent is needed and no supplier is alerted.

価格(税込)Price (tax incl.)
¥150,000 / 20 社まで¥150,000 for up to 20
納期Delivery
通常 10 分以内(最大 24 時間)Usually under 10 min (max 24 h)
方法Method
公開記録のみ(非侵入)Public records only (non-intrusive)

内容Scope

提供するもの・しないものWhat you get, and what you don't

提供するものWhat you get

  • 取引先ごとのスコア・評価(A〜F)・指摘と、それぞれの修正手順
  • 供給網全体の集中リスク: 複数の取引先が同じサーバ・同じネームサーバ・同じメール事業者に依存している箇所。個社ごとの採点では見えない、「一度の障害で複数社が同時に止まる」リスクです
  • なりすましメール対策(SPF・DMARC)、証明書、DNSSEC、名前解決しないホストなど 20 項目
  • 各指摘の根拠にした公開記録(事実)と、そこからの推論(推定)の区別
  • 印刷・PDF 保存できる提出用レポート(日本語)。稟議や監査資料にそのまま添付できます
  • Per-supplier score, grade (A–F), findings and the fix for each
  • Supply-chain concentration: where several suppliers depend on the same server, nameserver or mail operator - the 'one outage stops several suppliers at once' risk that per-vendor scores never show
  • 20 checks: spoofing protection (SPF, DMARC), certificates, DNSSEC, hosts that no longer resolve and more
  • The public records each finding rests on (facts), kept apart from inferences (estimates)
  • A report you can print or save as PDF (in Japanese), ready to attach to an approval or audit file

提供しないものWhat we don't do

  • ペネトレーションテストや脆弱性診断。取引先のサーバには一切アクセスしません
  • 漏えいしたアカウント情報の調査。取引先の従業員の情報を、その会社の同意なく第三者に渡すことはできないためです
  • 取引先への連絡や是正の依頼。レポートをもとに、お客様から取引先へお伝えください
  • 脆弱性の有無の断定。「推定」と記した項目は、取引先への確認を経てからご利用ください
  • Penetration testing or vulnerability scanning. We never access a supplier's servers
  • Leaked-credential lookups. A company's employees' data cannot be handed to a third party without that company's consent
  • Contacting suppliers or asking them to fix anything. Use the report to raise it with them yourself
  • Declaring that a supplier is vulnerable. Confirm items marked as estimates with the supplier before relying on them

流れHow it works

注文からレポート受け取りまでFrom order to report

すべて自動で進みます。

Everything runs automatically.

01

ドメインを入力Enter domains

取引先のドメインを 1 行に 1 社、最大 20 社まで入力します。URL をそのまま貼り付けても構いません。

One supplier per line, up to 20. Pasting URLs is fine.

02

決済Pay

Stripe でクレジットカード決済します。カード番号は当社のサーバを通りません。

Pay by card through Stripe; card details never touch our servers.

03

自動審査Automated review

公開記録だけを読み、取引先ごとの評価と供給網全体の集中リスクを算出します。

We read public records only and compute per-supplier results and concentration risk.

04

レポートを受け取るReceive the report

レポートのリンク(30 日間有効)をメールでお送りします。印刷・PDF 保存ができます。

A report link (valid 30 days) is e-mailed. Print or save it as PDF.

よくある質問Questions

FAQ

取引先に知られますか?Will suppliers notice?

いいえ。公開されている記録(証明書透明性ログと公開 DNS)を読むだけで、取引先のサーバには何も送りません。

No. We only read public records (Certificate Transparency logs and public DNS); nothing is sent to a supplier's servers.

取引先の同意は必要ですか?Do we need suppliers' consent?

公開記録の閲覧のみのため、同意は不要です。一方で、同意が必要になる調査(能動的な検査や漏えい情報の照会)は、この審査には含めていません。

No: it reads public records only. Checks that would need consent - active probing or leaked-credential lookups - are deliberately not part of this review.

20 社を超える場合は?More than 20 suppliers?

20 社ずつに分けてご注文ください。供給網全体の集中リスクは、1 回の注文に含まれる取引先の範囲で算出します。

Place one order per 20 suppliers. Concentration risk is computed across the suppliers in each order.

自社も同じ基準で見たいCan we check ourselves the same way?

自社のドメインは、無料の攻撃面診断で同じ項目を確認できます。

Yes - the free attack surface check runs the same checks on your own domain.

まずは取引先 20 社を 1 回でStart with 20 suppliers in one order

¥150,000(税込)・通常 10 分以内に納品。見積もりや打ち合わせは不要です。

¥150,000 (tax incl.), usually delivered within 10 minutes. No quotes, no calls.