Comparison Overview

Bronc Box

VS

DECATHLON FRANCE

Bronc Box

149 Harvest Dr, None, Coldwater, Ohio, US, 45828
Last Update: 2025-08-19 (UTC)
Between 900 and 1000

Excellent

Since 2015, the team at Signature 4 began their mission to develop our flagship product, the Bronc Box, with other gear and storage for hunting, weapons, and outdoor enthusiasts. The countless hours spent engineering, building, and testing reflects today in the quality product we make by our US-based, hard-working team in Ohio. We take pride in always doing the right thing, making storage gear at affordable prices without sacrificing quality, and delivering the best experience to every customer joining the Bronc family.

NAICS: 33992
NAICS Definition: Sporting and Athletic Goods Manufacturing
Employees: None
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

DECATHLON FRANCE

4, Boulevard de Mons Villeneuve-d'Ascq, Hauts-de-France 59650, FR
Last Update: 2025-03-15 (UTC)

Excellent

We are the world's Largest sports retailer. Founded in 1976, in France, we have set about making the pleasure and benefit of sports available for everyone across the globe. We do that by providing world class products at extremely affordable prices for all participants, from enthusiastic beginners to passionate professionals .

NAICS: 339
NAICS Definition:
Employees: 10,001+
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/bronc-box.jpeg
Bronc Box
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
https://images.rankiteo.com/companyimages/decathlon.jpeg
DECATHLON FRANCE
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
Compliance Summary
Bronc Box
100%
Compliance Rate
0/4 Standards Verified
DECATHLON FRANCE
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Sporting Goods Manufacturing Industry Average (This Year)

No incidents recorded for Bronc Box in 2025.

Incidents vs Sporting Goods Manufacturing Industry Average (This Year)

No incidents recorded for DECATHLON FRANCE in 2025.

Incident History โ€” Bronc Box (X = Date, Y = Severity)

Bronc Box cyber incidents detection timeline including parent company and subsidiaries

Incident History โ€” DECATHLON FRANCE (X = Date, Y = Severity)

DECATHLON FRANCE cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/bronc-box.jpeg
Bronc Box
Incidents

No Incident

https://images.rankiteo.com/companyimages/decathlon.jpeg
DECATHLON FRANCE
Incidents

No Incident

FAQ

Both Bronc Box company and DECATHLON FRANCE company demonstrate a comparable AI risk posture, with strong governance and monitoring frameworks in place.

Historically, DECATHLON FRANCE company has disclosed a higher number of cyber incidents compared to Bronc Box company.

In the current year, DECATHLON FRANCE company and Bronc Box company have not reported any cyber incidents.

Neither DECATHLON FRANCE company nor Bronc Box company has reported experiencing a ransomware attack publicly.

Neither DECATHLON FRANCE company nor Bronc Box company has reported experiencing a data breach publicly.

Neither DECATHLON FRANCE company nor Bronc Box company has reported experiencing targeted cyberattacks publicly.

Neither Bronc Box company nor DECATHLON FRANCE company has reported experiencing or disclosing vulnerabilities publicly.

Neither Bronc Box company nor DECATHLON FRANCE company has publicly disclosed detailed information about the number of their subsidiaries.

Neither Bronc Box company nor DECATHLON FRANCE company has publicly disclosed the exact number of their employees.

Latest Global CVEs (Not Company-Specific)

Description

Improper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to undervolt the platform resulting in a loss of confidentiality.

Risk Information
cvss4
Base: 8.6
Severity: LOW
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

Risk Information
cvss3
Base: 9.6
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Description

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hints in plaintext within the question object, regardless of whether the user has unlocked them via point deduction. Users can view all hints for free, undermining the business logic of the platform and reducing the integrity of the challenge system. This issue has been patched in version 2.3.0.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description

Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign high-privilege badges (e.g., Staff) to themselves. This could lead to privilege escalation and impersonation of administrative roles. This issue has been patched in version 2.2.0.

Risk Information
cvss3
Base: 8.2
Severity: LOW
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Description

parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.