SecurScan
PASSIVE · LEGAL ON ANY DOMAIN · NO KEY

SecurScan reads the public signals of any company's domain — email spoofing, encryption, exposed hosts, leaked secrets — and returns a scored, plain-language risk report in seconds.

Free account. Auditing an AI chatbot instead? Run an LLM audit → · Free SEO audit →

0
scan engines
0
AI attack classes
A–F
risk grade
Scroll
THE OFFER

One target. Four depths.

Every level deploys several analysis engines in parallel against your target. Start free, then go as deep as you need — each tier includes the ones below it.

5 engines

Free

€0 · no card

The external surface any attacker can already see.

  • Email spoofing (SPF/DMARC/DKIM)
  • TLS & security headers
  • DNS hygiene & leaked secrets
  • A–F risk grade
8 engines

Level 1

€99 · one-off

Deep active scan of the exposed perimeter.

  • Everything in Free
  • Active perimeter probing
  • Attack-surface mapping (CT logs)
  • Shodan exposure + known CVEs
11 engines

Level 2 · Intrusion

€149 · one-off

Authenticated intrusion testing + detailed report.

  • Everything in Level 1
  • Authenticated intrusion (GET-only)
  • IDOR / access-control / sessions
  • Detailed remediation report
11 engines + 19 AI classes

Level 3 · AI audit

€299 · one-off

Everything, plus a full AI/LLM security audit.

  • Everything in Level 2
  • AI/LLM audit — 19 attack classes
  • Prompt injection, jailbreak, leakage
  • Full report + AI executive summary
PIPELINE

Authorize. Scan. Verify. Report.

01

Authorize

Verify domain ownership, sign an electronic mandate. Active tiers stay locked until then.

02

Scan

Eleven engines run concurrently, each sandboxed behind an SSRF and timeout guard.

03

Verify

An adversarial AI judge refutes every finding — false positives are dropped, not shipped.

04

Report

A scored A–F report with an AI executive summary and a print-ready PDF.

ENGINES

Eleven scan engines. Nineteen AI attack classes.

Every check maps to a real attacker technique — and every finding is cited with evidence and a fix.

0

Email spoofing

SPF, DMARC, DKIM forgeability

TLS & certificates

Weak protocols, expiry

0

HTTP hardening & CORS

HSTS, CSP, frame, referrer — every header an attacker probes

0

DNS hygiene

CAA, DNSSEC, MTA-STS

Attack surface

Forgotten hosts via CT logs

Shodan exposure

Open ports + known CVEs

Leaked secrets

Public GitHub search

0

LLM attack classes

Prompt-injection, jailbreak, multi-turn, encoding, output-handling + your business rules

THE EDGE

An AI judge kills the false positives.

Generic scanners drown you in noise. SecurScan runs every ambiguous finding past an adversarial AI reviewer told to refute it — so what reaches your report is real, ranked, and worth your developer's time.

highMissing HSTS headerconfirmed
medReflected param on /searchconfirmed
low"Sensitive" subdomain img-cdnfalse positive

Know your exposure in 60 seconds.

Free passive scan on any domain. No signup, no card.

Scan my company →