What the platform checks
The platform is not live yet, so everything below is coming soon. The first checks are built and in testing; the rest follow, in this order.
SSL/TLS certificate & encryption
Coming soonIs your HTTPS valid, trusted and modern? Certificate expiry and trust chain, every protocol version and cipher suite your server actually accepts, forward secrecy, HSTS, OCSP stapling, certificate transparency and CAA — graded A+ to F. Named weaknesses are actively probed, not guessed: Heartbleed, POODLE, ROBOT, DROWN, Logjam, CRIME, Ticketbleed, CCS injection, insecure renegotiation and the CBC padding-oracle family. A check we cannot complete says "not tested" rather than passing you.
HTTP security headers
Coming soonWhether your site sends the security response headers that protect visitors — HSTS (forced HTTPS), Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy — plus the cross-origin isolation headers, anything deprecated, and the headers that quietly advertise which software and version you run. Point it at a custom port if your app doesn't live on 443.
Email security (SPF, DKIM, DMARC)
Coming soonCan scammers spoof your domain? Checks your mail servers and your email authentication — MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI — so phishing and business-email-compromise can't impersonate you. The report carries the raw DNS answers we read, and a generator that writes out the exact records to paste into your DNS, already filled in with your domain.
Email spoofing test
Coming soonWe actually try to deliver a forged message to your own domain and show you whether it gets through — proof, not theory. One fixed, plain-text message that explains itself, sent only ever to an address at the domain being tested. If your server refuses it for the wrong reason we report the test as inconclusive rather than calling it a pass.
Email breach exposure
Coming soonWhich known breaches an address of yours appears in, and what types of data each one held — passwords, addresses, phone numbers. A mailbox is an asset in its own right here, so it gets the same history, scheduling and reports as a domain. We never receive the breached values themselves, and there is nowhere in our system to put them.
Domain threat intelligence
Coming soonFinds look-alike and typosquatting domains registered to impersonate your brand, so you catch phishing infrastructure early.
Open ports & perimeter
Coming soonFinds internet-exposed services on your servers. An active check — it will run only on assets whose ownership you've proven.
Subdomain & asset discovery
Coming soonFinds the subdomains and internet-facing hosts attached to your domain, so you can see — and check — your whole attack surface, not just the sites you already knew about.
Infrastructure vulnerability scan
Coming soonScans your internet-facing servers for known software vulnerabilities and misconfigurations — outdated services, missing patches (CVEs), weak configuration — with clear, prioritized fixes. Requires proven ownership.
Web app scan (DAST)
Coming soonActively tests your live web application the way an attacker would — injection, broken authentication, misconfiguration and more. Requires proven ownership.
Other types of scans
Coming soonWe're continuously adding new checks. Tell us what you need — and if you have a specific requirement, our experts can run it for you.
