How these reports are built
A report is a set of observations across six categories, checked against publicly observable data. There is no score, no grade, and no ranking of one company against another — only what was found, and what could not be determined.
What we check
Six categories. Each is reported as a set of findings and checks that came back clear — never as a number.
Website Security
Response headers as any browser sees them: HSTS, Content-Security-Policy, cookie flags and what the server tells the world about itself.
Email Security
Whether SPF, DKIM and DMARC are published and enforcing, so someone else cannot send mail as this domain.
Network & DNS
Zone hygiene from public records — DNSSEC, nameserver spread and the records that give an attacker their map.
TLS & Certificate
The certificate presented to any client: expiry, chain, protocol versions still accepted and cipher suites still offered.
Credential Exposure
Corporate credentials for this domain found in breach dumps and stealer logs.
Attack Surface
Hosts and subdomains discoverable from certificate transparency logs and public DNS, including ones nobody meant to publish.
How we check it
Scanning is passive and limited to publicly observable data: DNS records, TLS certificates presented to any client, HTTP response headers, certificate-transparency logs, and the Intelsieve breach corpus. We perform no authenticated access, no brute forcing, no vulnerability exploitation and no intrusive testing of any kind.
Requests we make identify themselves as:
IntelsieveReportBot/1.0 (+https://intelsieve.com/security-report/methodology)
Port and service data is not something we generate ourselves — Intelsieve does not scan ports. Where a report shows a reachable service, it is attributed to the third-party internet-scan provider that observed it, alongside the date it was observed, so the reader can judge how current it is.
A site that blocks our requests yields undetermined checks for whatever we could not reach. We do not retry it under a different, unidentified user agent — an observation obtained by concealing who made it is not one we are willing to publish.
What we do not do
- No scoring or grading of any kind — no composite, no letter, no ranking.
- No characterisation of an incident or a company. A report states what was observed; it does not conclude that a company was breached, is negligent, or is unsafe to do business with.
- No per-record credential data. Exposure figures are aggregate counts only — a total, never an individual email address, password, or record.
- No aggregate is published below a floor of 5 records for a domain. A count of 1–4 identifies too few people to be safe to publish, so below that floor we report the category as not determined rather than a small number.
When a check cannot be completed
A category we could not check — a timeout, a blocked request, a provider outage — is reported as not determined. It is never reported as clear and never rendered as if it passed. Our own inability to check something is not evidence about anyone's security.