Run an external security check.
Ten security checks and thirteen SEO checks against what your domain publishes publicly. No account, no card, and nothing is logged into or changed.
Running a check means you accept the terms of use. Checks are passive and read only what a domain publishes publicly.
https://
Reading what this domain publishes
0.0s
SECURITY / 10 CHECKS
SEO / 13 CHECKS
Every one of these is a read. Nothing is logged into, nothing is submitted, and nothing on the domain is changed.
An external security-hygiene snapshot of what's visible from outside your perimeter, with no login and no code access. A readiness indicator, not a certification.
01 - scope
About 20% of SOC 2 is visible from here
SOC 2 is mostly process, policy, and internal architecture. A domain scan - this one included - can only ever reach the sliver that happens to be externally observable.
02 - what we can see
The external checks
Open any finding for the steps to fix it.
Each one maps to a real SOC 2 Trust Services Criterion, but a pass here only ever covers the visible slice of that criterion.
03 - what we can't see
The readiness checklist a scan will never fill in
This is where most of SOC 2 actually lives. An auditor will ask about every item below - none of it can be confirmed by looking at your domain from the outside. If you already know some of the answers, use "Tell us what you know" under each group to drill in - nothing here is verified, but it turns the checklist into a starting point instead of a wall of unknowns. Not sure where to look? Every question links to plain-language directions for finding it.
Data isolation
- Row-level security / multi-tenant boundaries
- IDOR / BOLA on authenticated endpoints
- Service-role and API key scoping
Is Row-Level Security (or equivalent tenant isolation) enabled on every table holding customer data?
Where do I find this? →Has anyone tested whether one customer can reach another customer's data by changing an ID in a request?
Where do I find this? →Are your service-role / admin API keys scoped down, or do they have full database access?
Where do I find this? →Backups & resilience
- Backups, point-in-time recovery
- RTO / RPO and disaster recovery plan
- Dependency timeouts, error budgets
Do you have automated backups, and has anyone actually tested a restore?
Where do I find this? →Do you have a written RTO/RPO (target recovery time and acceptable data loss) for your main database?
Where do I find this? →If a critical dependency (payment processor, email provider) goes down, does your app degrade gracefully or break?
Where do I find this? →Access governance
- MFA enforced, not just offered
- Access reviews, offboarding, key rotation
- Session revocation
Is MFA required - not just available - for everyone with production access?
Where do I find this? →When someone leaves or a contractor's engagement ends, is there a written checklist for revoking their access?
Where do I find this? →Do you rotate API keys and secrets on a schedule, or only after an incident?
Where do I find this? →Engineering process
- Change management, branch protection, CI
- Secrets management, encryption at rest
- Webhook signing, SSRF controls
Is your main branch protected - required review before merge, no direct pushes?
Where do I find this? →Are secrets (API keys, DB passwords) kept out of your code repo?
Where do I find this? →Do you verify signatures on webhooks you receive from third parties?
Where do I find this? →People & policy
- Incident response plan
- Risk assessment cadence
- Security training, background checks
Do you have a written incident response plan, even a short one?
Where do I find this? →Has anyone documented a risk assessment for your product in the last 12 months?
Where do I find this? →Do new hires and contractors get any security or privacy training?
Where do I find this? →Vendor management
- Subprocessor list and DPAs / BAAs
- Vendor risk reviews
- Fourth-party exposure
Do you have a list of every subprocessor or vendor that touches customer data?
Where do I find this? →Do you have signed DPAs (Data Processing Agreements) with those vendors?
Where do I find this? →Has anyone reviewed the security posture of your most critical vendors?
Where do I find this? →04 - the fine print, up front
05 - next step
Want the readiness checklist filled in, not just listed?
We turn the 80% above into a scoped plan - questionnaire, evidence collection, remediation - built to hand off cleanly to your auditor. Anything you answered above comes with you, so the full report picks up where this one leaves off instead of starting over.
One email, no spam. The list is not open yet, so this form does not send anything.
Noted - in a live version, your full report would be on its way.