Start your Pentest
Enter your domain to start. The first pass runs in minutes, with no account and nothing to install.
Passive checks only — public DNS, TLS, and headers. No account needed, and nothing is sent that a browser wouldn't.
What we check
- TLS certificate— expiry, and whether it covers the hostname
- HTTPS— whether the host serves it at all
- Email authentication— SPF and DMARC, and whether they enforce
- Security headers— CSP, HSTS, framing, MIME-sniffing, referrer
- Version disclosure— software versions leaked in responses
All of it is public information, gathered the way a browser would. Nothing here touches the application itself — that's the full pentest, which needs your authorization first.
What happens next
The free scan shows what a reviewer's first look would show. When a customer asks for more, the continuous security scan covers your authenticated web, API, and cloud surface, and the same-day pentest turns validated findings into a report their security team accepts.