The problem

Security questionnaires and annual audits describe a single moment. Many recent breaches came through the connections between systems: OAuth apps, third-party tokens and integrations that no single scanner looks at together.

Built for software companies and platforms that sell to security-conscious buyers and need evidence, not another questionnaire.

What Wuramark does

  • Five layers, one grade

    Code, dependencies, third-party access, environment and rate of change combine into a single Trust Surface Risk Index, graded A to F.

  • Integrations come first

    Third-party and OAuth access carries the most weight. We compare the integrations you declare with the ones we find in your code.

  • Certificates that expire honestly

    Each certificate lasts 45 days and renews through continuous monitoring. If monitoring stops, the certificate is not renewed.

  • Verifiable by anyone

    A public verification page and badge show the grade, what was assessed and when it was last verified.

Five layers, one grade

Each layer is scored separately, then combined into the Trust Surface Risk Index and graded from A to F.

  1. L1

    Code

    Your application source, checked for insecure patterns and exposed secrets.

  2. L2

    Dependencies

    The open-source packages you ship, checked against known vulnerabilities.

  3. L3

    Third-party access30% of the score

    OAuth apps, connected services and the tokens you hold for others: how they are stored, scoped, rotated and revoked.

  4. L4

    Environment

    Configuration and deployment settings that decide how exposed the system is.

  5. L5

    Velocity

    How quickly the system changes, and whether security keeps pace.

How it works

  1. Connect

    Link a GitHub repository or upload a build. Every assessment is pinned to an exact commit or file hash.

  2. Assess

    Wuramark checks all five layers and calculates your grade.

  3. Certify

    A score of 75 or above earns a certificate that states exactly what was assessed and what it does not guarantee.

  4. Monitor

    Scheduled rescans keep watching. The certificate renews every 45 days while monitoring continues.

Pricing

$1,200 a year, or $120 a month

Founding pricing for our first ten customers, locked for two years. Certification and continuous monitoring are included.

A free scan and a one-off report are available if you want to see your results first.

Request early access

Questions

Can you certify a site from its URL alone?

No. A URL scan has no fixed artifact behind it, so it cannot support a certificate. Certificates are tied to a specific commit or uploaded build.

What does a certificate guarantee?

It records what was assessed, when, and the result. It is not a promise that a system cannot be breached, and the certificate says so itself.

What happens if we stop monitoring?

Your certificate stays valid until the end of its current period and is then not renewed. There is no certificate without monitoring.