Security Reports
See what an attacker sees before they do.
One page on any company's external security posture — website and email hardening, DNS and TLS hygiene, exposed attack surface, and the credentials already circulating in breach dumps and stealer logs.
Passive checks against publicly observable data. No authenticated access, no intrusive testing, no sign-up.
What is in a report
Six categories, each checked against publicly observable evidence. There is no score, grade or ranking — a category we could not check is reported as undetermined, never as a pass.
Website Security
Response headers as any browser sees them: HSTS, Content-Security-Policy, cookie flags and what the server tells the world about itself.
Email Security
Whether SPF, DKIM and DMARC are published and enforcing, so someone else cannot send mail as this domain.
Network & DNS
Zone hygiene from public records — DNSSEC, nameserver spread and the records that give an attacker their map.
TLS & Certificate
The certificate presented to any client: expiry, chain, protocol versions still accepted and cipher suites still offered.
Credential Exposure
Corporate credentials for this domain found in breach dumps and stealer logs.
Attack Surface
Hosts and subdomains discoverable from certificate transparency logs and public DNS, including ones nobody meant to publish.
Example reports
Published reports for well-known domains, so you can read a finished one before you generate your own.