Security and encryption
Are exchanges with your visitors protected? Certificate validity, the cipher versions still accepted, the security headers sent, and the sensitive files left in plain sight.
Audit your home page for free
We look at your home page for Security and encryption, and we email you our report within 48 working hours.
One page, one pillar. The plans cover the 9 pillars across your whole site.
What we look at
- The certificate: its validity, its expiry date, and whether it was actually issued for your domain name. A certificate issued for your host’s name triggers a browser warning on every visit.
- The cipher versions your server still accepts, and the redirect from the insecure address to the secure one: in force, and permanent.
- The headers your site sends to every visitor: what stops your pages from being embedded by another site, or read as something they are not.
- The protective attributes set on session cookies, and the resources still loaded unencrypted from a page that is otherwise secure.
- The libraries and components your pages use whose version carries a known security flaw.
- What your site reveals about its own construction: versions printed in headers, development files left online, error pages that say too much, and credentials that have no place in public code.
On what basis
Recommended TLS versions, RFC 9116
A finding is only worth something if it rests on an identifiable basis. Where one exists, we lean on a law, a standard or a specification, and for every point recorded the report names the page and gives the value we measured.
What it changes for you
A security warning shown by the browser on your home page costs more than an invisible flaw: it stops the visitor before a single line is read, and it arrives without notice, the day a certificate expires.
The rest plays out more quietly. What a site publishes about its own construction (versions, development files, error pages) says more than it should. None of this is on display: these are technical properties of what your server answers.
What this audit does not say
We produce a passive audit. We establish what the site shows any visitor, search engine or AI agent, never what a logged-in session would reveal, and that is precisely the point: the report describes what your customers, your partners and search engines see.
Looking for exposed files or entry points belongs to a deeper examination, with access attempts, which only takes place with the site owner’s written agreement.
Every limit of the examination is stated in the methodology note of your report. A point that cannot be verified is never presented as compliant.
The weight of this pillar
An overall score has to weigh what matters for your business: the 9 pillars do not carry the same weight depending on what your site is for. Here is what “security and encryption” represents in the overall score, under each weighting. The report always states which one produced your score.
| Type of site | Share of the overall score |
|---|---|
| Type not determined | 15% |
| Brochure site | 10% |
| Online shop | 18% |
| Application, customer portal | 25% |
| Blog, media | 10% |
| Public-sector site | 12% |
