Run an external security check.

Ten security checks and thirteen SEO checks against what your domain publishes publicly. No account, no card, and nothing is logged into or changed.

scan

Running a check means you accept the terms of use. Checks are passive and read only what a domain publishes publicly.

An external security-hygiene snapshot of what's visible from outside your perimeter, with no login and no code access. A readiness indicator, not a certification.

About 20% of SOC 2 is visible from here

SOC 2 is mostly process, policy, and internal architecture. A domain scan - this one included - can only ever reach the sliver that happens to be externally observable.

~20% checkable
~80% needs credentials, code, or documents
10 checks below readiness checklist further down

The external checks

Open any finding for the steps to fix it.

Each one maps to a real SOC 2 Trust Services Criterion, but a pass here only ever covers the visible slice of that criterion.

The readiness checklist a scan will never fill in

This is where most of SOC 2 actually lives. An auditor will ask about every item below - none of it can be confirmed by looking at your domain from the outside. If you already know some of the answers, use "Tell us what you know" under each group to drill in - nothing here is verified, but it turns the checklist into a starting point instead of a wall of unknowns. Not sure where to look? Every question links to plain-language directions for finding it.

Data isolation

  • Row-level security / multi-tenant boundaries
  • IDOR / BOLA on authenticated endpoints
  • Service-role and API key scoping

Is Row-Level Security (or equivalent tenant isolation) enabled on every table holding customer data?

Where do I find this? →

Has anyone tested whether one customer can reach another customer's data by changing an ID in a request?

Where do I find this? →

Are your service-role / admin API keys scoped down, or do they have full database access?

Where do I find this? →

Backups & resilience

  • Backups, point-in-time recovery
  • RTO / RPO and disaster recovery plan
  • Dependency timeouts, error budgets

Do you have automated backups, and has anyone actually tested a restore?

Where do I find this? →

Do you have a written RTO/RPO (target recovery time and acceptable data loss) for your main database?

Where do I find this? →

If a critical dependency (payment processor, email provider) goes down, does your app degrade gracefully or break?

Where do I find this? →

Access governance

  • MFA enforced, not just offered
  • Access reviews, offboarding, key rotation
  • Session revocation

Is MFA required - not just available - for everyone with production access?

Where do I find this? →

When someone leaves or a contractor's engagement ends, is there a written checklist for revoking their access?

Where do I find this? →

Do you rotate API keys and secrets on a schedule, or only after an incident?

Where do I find this? →

Engineering process

  • Change management, branch protection, CI
  • Secrets management, encryption at rest
  • Webhook signing, SSRF controls

Is your main branch protected - required review before merge, no direct pushes?

Where do I find this? →

Are secrets (API keys, DB passwords) kept out of your code repo?

Where do I find this? →

Do you verify signatures on webhooks you receive from third parties?

Where do I find this? →

People & policy

  • Incident response plan
  • Risk assessment cadence
  • Security training, background checks

Do you have a written incident response plan, even a short one?

Where do I find this? →

Has anyone documented a risk assessment for your product in the last 12 months?

Where do I find this? →

Do new hires and contractors get any security or privacy training?

Where do I find this? →

Vendor management

  • Subprocessor list and DPAs / BAAs
  • Vendor risk reviews
  • Fourth-party exposure

Do you have a list of every subprocessor or vendor that touches customer data?

Where do I find this? →

Do you have signed DPAs (Data Processing Agreements) with those vendors?

Where do I find this? →

Has anyone reviewed the security posture of your most critical vendors?

Where do I find this? →
Self-reported readiness (not verified)
0 of 18 answered
This is not a SOC 2 certification. SOC 2 is an attestation performed by a licensed CPA firm against evidence a domain scan cannot see. "External security posture" means exactly that: hygiene signals visible from outside your perimeter, nothing more. Treat a passing grade here as a starting point, not a finish line.

Want the readiness checklist filled in, not just listed?

We turn the 80% above into a scoped plan - questionnaire, evidence collection, remediation - built to hand off cleanly to your auditor. Anything you answered above comes with you, so the full report picks up where this one leaves off instead of starting over.

One email, no spam. The list is not open yet, so this form does not send anything.

Noted - in a live version, your full report would be on its way.