Skip to content

Security Reports

See what an attacker sees before they do.

One page on any company's external security posture — website and email hardening, DNS and TLS hygiene, exposed attack surface, and the credentials already circulating in breach dumps and stealer logs.

Passive checks against publicly observable data. No authenticated access, no intrusive testing, no sign-up.

What is in a report

Six categories, each checked against publicly observable evidence. There is no score, grade or ranking — a category we could not check is reported as undetermined, never as a pass.

Website Security

Response headers as any browser sees them: HSTS, Content-Security-Policy, cookie flags and what the server tells the world about itself.

Email Security

Whether SPF, DKIM and DMARC are published and enforcing, so someone else cannot send mail as this domain.

Network & DNS

Zone hygiene from public records — DNSSEC, nameserver spread and the records that give an attacker their map.

TLS & Certificate

The certificate presented to any client: expiry, chain, protocol versions still accepted and cipher suites still offered.

Credential Exposure

Corporate credentials for this domain found in breach dumps and stealer logs.

Attack Surface

Hosts and subdomains discoverable from certificate transparency logs and public DNS, including ones nobody meant to publish.

How these reports are built

Example reports

Published reports for well-known domains, so you can read a finished one before you generate your own.