GRC & third-party risk · Data security & backup

BigID

United States · bigid.com
Official address, recorded by DBSE. Everything on this page that talks about domains uses these.

Data discovery, classification and privacy.

Community rating

0 ratings
5 ★
0
4 ★
0
3 ★
0
2 ★
0
1 ★
0

Sign in to rate.

Scorecard from 0 structured reviews

Deployment effort
Support quality
Features vs promises
Pricing transparency
Return on investment

All reviews and filters → · Compare

Exposure signal

Low

An objective, third-party reading of this vendor's own credential hygiene. It is not part of the community scorecard and does not affect any rating on DBSE.

Staff credentials in infostealer logs
0
Third-party services their staff use
5

Credentials belonging to 0 of this vendor's own staff appear in infostealer logs, and no date is recorded for the most recent staff credential. Their staff hold credentials for 5 distinct external services, which is the surface a successful attack on this vendor could reach. This says nothing about how well the product works.

Customer-side infections: 8 (not counted in the band)

These are infections on the machines of people who log in to this vendor's service. They reflect those users' own endpoint hygiene, and a vendor with a large consumer or partner login footprint will always show more of them. Counting that against the vendor would penalise popularity, so this platform does not.

Context that is recorded but never scored

Stealer families seen against this domain: Lumma, RedLine, Azorult, Generic Stealer. Which malware took a credential says more about what is circulating than about the vendor, so it is not scored.

Which third-party services appear
ServiceIn our directoryCommunity ratingOccurrences
hubspot.com Not listed 1
intercom.io Not listed 1
hibob.com Not listed 1
carta.com Not listed 1
slack.com Not listed 1

If your own organisation depends on any of these, a successful attack on this vendor and an attack on you share a blast radius. That is worth a question in the security review, not a reason to walk away. Where a service is itself a vendor in our directory it is named and linked, with whatever the community has scored it, so you can read both sides of the dependency in one place. The rating shown is the community's own; it is not derived from this exposure data.

Two independent sources agree on 0 exposed staff credentials.

Source: FireIntel (xti.fireintel.net), public domain summary. Source: Hudson Rock (hudsonrock.com), free infostealer intelligence API. About this data. Read 18 hours ago. DBSE does not collect, hold, or sell this data.

Discussions about BigID