How the ShipReady Score works
The ShipReady Score is a single 0–100 composite, graded A–F, that rolls up nine domain scores. Every number is computed from data you connect — the platform never shows sample data, and a domain with no connected source is left out of the composite rather than given a placeholder grade.
The composite
Each domain carries a relative weight; the composite normalizes by the sum of the weights of the domains that are actually measured. Security Readiness and AI Readiness carry the most weight; the Technical Debt and Lifecycle Risk scores are inverted, so lower real risk raises the score rather than lowering it.
The nine domains
Weights shown are each domain’s base weight share of the composite when all nine are measured. These are the base weights only: in a live workspace each domain is additionally weighted by how well-backed its measurement is (the number of connected sources and measured signals), and unmeasured domains are excluded entirely.
Where the dollar Value at Stake comes from
Value at Stake translates the same domain scores into money, so a board conversation can happen in dollars instead of grades. It is not a separate data source: every figure is derived from scores that were themselves computed from your connected systems, and a signal that isn’t measured contributes nothing rather than a guess. If nothing you have connected produces a dollar figure, the headline says so instead of showing $0.
Two kinds of dollars go into it, and they are summed and shown separately — never added together:
- Measured — money already committed or observable, like cloud spend and the engineer-months your technical debt represents. These need no probability priors.
- Modeled— expected loss from risks that haven’t happened, like a material breach or an end-of-life incident. These are a posture-scaled probability times an impact figure, expressed as a low/base/high range rather than a single number.
The modeled half is driven by assumptions — the loaded cost of an engineer-month, your team size, breach and incident impact, and the annual probability priors at a leading versus a critical posture. The defaults are deliberately coarse and defensible, meant to be tuned to your business, and every estimate carries the exact assumptions it used so a reviewer can check the arithmetic or disagree with the inputs. A modeled dollar is an estimate, and the product labels it as one.
Why some domains read “not measured”
A domain activates only once a source that feeds it is connected and synced. Until then it shows a “connect a source” state instead of a number — a deliberate choice so the score reflects evidence, not guesses. See the integration guides for what each source pulls, or the FAQ for how to read the scores.
How compliance readiness is scored
Alongside the nine engineering domains, ShipReady scores compliance readiness across ten frameworks — SOC 2, ISO 27001, NIST CSF 2.0, NIST 800-53, CIS, GDPR, HIPAA, PCI DSS, SOX ITGC, and CCPA/CPRA — on a shared canonical-control model, so a piece of evidence collected once counts toward every framework its control maps to. Readiness is the share of in-scope canonical controls that are evidenced as met.
The rollup is deliberately worst-honest: a control clears only when full-coverage evidence supports it, any linked gap keeps it a gap, expired evidence stops counting, and a tenant with nothing in scope reads “not assessed” rather than a fabricated 0%. It is an internal readiness indicator, not a certification or attestation. An authored library of governance-policy templates covers the control domains these frameworks expect, and any AI-drafted policy or remediation is a human-approved draft — never auto-accepted.
See your own score
Connect a source and your Executive Overview populates as the first sync completes — about a minute for small orgs, several minutes for large estates.