One domain. One grade, A to E. No spin: what anyone who bothers to look can already see.
Nothing. The scan is free. You type in the domain and that is it: no account, no card, nothing to install. The A to E grade shows up on screen in about two minutes and you do not have to leave any data to see it. If you also want the full report, we send that one by email, and that is the only point where an address is asked for.
No. It is 100% passive: we only read information that is already public about your domain, meaning DNS records, certificates, the headers of your home page and public breach catalogues. We do not test passwords, we do not exploit anything and we do not send odd traffic to your servers. It is the same thing anyone can see from the outside, only sorted and explained. Active testing is a separate service and starts only once a work order is signed.
It is the twelve checks summed up in a single figure. A runs from 90 to 100 points, B from 80 to 89, C from 70 to 79, D from 50 to 69, and E is under 50. Every check ends in one of three states and never in two: verified with the raw evidence in plain sight, does not apply to this domain, or could not be verified. That last one is stated as such; it is never counted as a pass.
If you ask for the report we keep your email, the domain you scanned, the date and a summary of what the scan found. We use it for that and nothing else: it is not sold and it is not passed to anyone. We hold it for 6 months from the last contact and then it is deleted on its own. You can ask us to delete it sooner by writing to [email protected], and we do it within the following 5 working days. The full detail is in the privacy notice, at the foot of this page.
Every finding explained, with the risk and how to close it. It lands in your inbox in 2 minutes.
This is only what shows from the outside. The deep scan actually tests: access controls, business logic and whatever an attacker would try.