Free tool
Free exposure snapshot.
Enter a domain and we'll run a quick, passive look at what's exposed to anyone on the public internet — HTTPS and headers, version disclosure, and a few commonly-leaked files. Results appear on screen; leave an email for the full written report.
Only snapshot a domain you own or are authorised to test. These are passive, public checks — the same requests any browser makes. We never log in, send payloads, or test beyond this. Deeper testing happens only under a signed authorisation.
What it checks
Passive, public signals only.
HTTPS & HSTS
Is the site reachable over HTTPS, does HTTP redirect to it, and is HSTS set?
Security headers
CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy.
Version disclosure
Does the server advertise software and versions attackers can look up?
Exposed files
Are common sensitive files (.env, .git/config, backups) publicly downloadable?
A snapshot is a starting point, not a pentest. It only sees the outside surface — it can't find broken access control, business-logic flaws or injection. For that, you need a human test.
Want the full picture?
A fixed-price pentest, reported in days, with a retest included.