PASSIVE · LEGAL ON ANY DOMAIN · NO KEY

See what an attacker sees before they do.

SecurScan reads the public signals of any company's domain — email spoofing, encryption, exposed hosts, leaked secrets — and returns a scored, plain-language risk report in seconds.

No signup. Auditing an AI chatbot instead? Run an LLM audit →

11
scan engines
19
AI attack classes
A–F
risk grade
COVERAGE

From the front door to behind the login.

A black-box scan stops at the login page. SecurScan goes deeper — safely, and only with signed authorization.

01 · Passive

Passive

Reads only public signals. Runs on any company in seconds — no key, fully legal.

  • SPF / DMARC / DKIM
  • TLS & security headers
  • Exposed subdomains & CVEs
  • Leaked secrets on GitHub
02 · Authenticated

Authenticated

Behind the login — the flaws a black-box scan can never reach. GET-only, staging.

  • IDOR / access control
  • Session-cookie security
  • Member-area injection
  • Nothing gets deleted
03 · AI / LLM

AI / LLM audit

Stress-tests the client's chatbot or agent across 19 attack classes — including your own business rules.

  • Prompt leak, jailbreak, injection
  • Multi-turn escalation
  • Insecure output (XSS/markdown)
  • Your custom policy rules
PIPELINE

Authorize. Scan. Verify. Report.

01

Authorize

Verify domain ownership, sign an electronic mandate. Active tiers stay locked until then.

02

Scan

Eleven engines run concurrently, each sandboxed behind an SSRF and timeout guard.

03

Verify

An adversarial AI judge refutes every finding — false positives are dropped, not shipped.

04

Report

A scored A–F report with an AI executive summary and a print-ready PDF.

ENGINES

Eleven scan engines. Nineteen AI attack classes.

Every check maps to a real attacker technique — and every finding is cited with evidence and a fix.

3

Email spoofing

SPF, DMARC, DKIM forgeability

TLS & certificates

Weak protocols, expiry

6

HTTP hardening & CORS

HSTS, CSP, frame, referrer — every header an attacker probes

4

DNS hygiene

CAA, DNSSEC, MTA-STS

Attack surface

Forgotten hosts via CT logs

Shodan exposure

Open ports + known CVEs

Leaked secrets

Public GitHub search

19

LLM attack classes

Prompt-injection, jailbreak, multi-turn, encoding, output-handling + your business rules

THE EDGE

An AI judge kills the false positives.

Generic scanners drown you in noise. SecurScan runs every ambiguous finding past an adversarial AI reviewer told to refute it — so what reaches your report is real, ranked, and worth your developer's time.

highMissing HSTS headerconfirmed
medReflected param on /searchconfirmed
low"Sensitive" subdomain img-cdnfalse positive

Know your exposure in 60 seconds.

Free passive scan on any domain. No signup, no card.

Scan my company →