What the platform checks

The platform is not live yet, so everything below is coming soon. The first checks are built and in testing; the rest follow, in this order.

SSL/TLS certificate & encryption

Coming soon

Is your HTTPS valid, trusted and modern? Certificate expiry and trust chain, every protocol version and cipher suite your server actually accepts, forward secrecy, HSTS, OCSP stapling, certificate transparency and CAA — graded A+ to F. Named weaknesses are actively probed, not guessed: Heartbleed, POODLE, ROBOT, DROWN, Logjam, CRIME, Ticketbleed, CCS injection, insecure renegotiation and the CBC padding-oracle family. A check we cannot complete says "not tested" rather than passing you.

HTTP security headers

Coming soon

Whether your site sends the security response headers that protect visitors — HSTS (forced HTTPS), Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy — plus the cross-origin isolation headers, anything deprecated, and the headers that quietly advertise which software and version you run. Point it at a custom port if your app doesn't live on 443.

Email security (SPF, DKIM, DMARC)

Coming soon

Can scammers spoof your domain? Checks your mail servers and your email authentication — MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI — so phishing and business-email-compromise can't impersonate you. The report carries the raw DNS answers we read, and a generator that writes out the exact records to paste into your DNS, already filled in with your domain.

Email spoofing test

Coming soon

We actually try to deliver a forged message to your own domain and show you whether it gets through — proof, not theory. One fixed, plain-text message that explains itself, sent only ever to an address at the domain being tested. If your server refuses it for the wrong reason we report the test as inconclusive rather than calling it a pass.

Email breach exposure

Coming soon

Which known breaches an address of yours appears in, and what types of data each one held — passwords, addresses, phone numbers. A mailbox is an asset in its own right here, so it gets the same history, scheduling and reports as a domain. We never receive the breached values themselves, and there is nowhere in our system to put them.

Domain threat intelligence

Coming soon

Finds look-alike and typosquatting domains registered to impersonate your brand, so you catch phishing infrastructure early.

Open ports & perimeter

Coming soon

Finds internet-exposed services on your servers. An active check — it will run only on assets whose ownership you've proven.

Subdomain & asset discovery

Coming soon

Finds the subdomains and internet-facing hosts attached to your domain, so you can see — and check — your whole attack surface, not just the sites you already knew about.

Infrastructure vulnerability scan

Coming soon

Scans your internet-facing servers for known software vulnerabilities and misconfigurations — outdated services, missing patches (CVEs), weak configuration — with clear, prioritized fixes. Requires proven ownership.

Web app scan (DAST)

Coming soon

Actively tests your live web application the way an attacker would — injection, broken authentication, misconfiguration and more. Requires proven ownership.

Other types of scans

Coming soon

We're continuously adding new checks. Tell us what you need — and if you have a specific requirement, our experts can run it for you.