Every check, every weight, every rule. This page is generated from the same code that computes your score.
Your Security Posture Score is a number from 0 to 100 built from two ingredients: what our external scan observed about your public website and public records, and what you told us about your internal practices in the self-assessment. Before you complete the self-assessment, the score is 100% tool-observed. After, it blends 60% tool-observed + 40% self-reported. Reports always label which is which — we never present your own answers as something we verified.
Each check earns full points when passing, half points when partially in place (where partial credit applies), and zero when it's a gap. The section score is points earned divided by points possible, scaled to 100.
| Check | Data source | Weight |
|---|---|---|
| SPF email authenticationDeclares which servers may send email as your domain. | Public DNS | 15 |
| DKIM email signingCryptographically signs outbound email so receivers can verify it. | Public DNS | 11 |
| DMARC anti-spoofing policyTells receiving servers to quarantine or reject spoofed email. | Public DNS | 15 |
| TLS / SSL encryptionWe connect to your site ourselves and read the certificate it serves — whether it is trusted, covers your address, when it expires, and whether retired TLS versions are still accepted. | Our own TLS check | 20 |
| HSTS headerForces browsers to always use HTTPS. | Your homepage | 10 |
| X-Content-Type-Options headerStops browsers executing files disguised as other types. | Your homepage | 4 |
| X-Frame-Options headerBlocks your site from being framed on malicious pages. | Your homepage | 5 |
| Content Security PolicyBrowser-level defense against cross-site scripting. | Your homepage | 5 |
| Referrer-Policy headerLimits URL data leaked to third-party sites. | Your homepage | 5 |
| Website software vulnerabilitiesReads the software version your website publishes about itself, then checks that exact version against public vulnerability databases and CISA’s list of flaws attackers are exploiting right now. | OSV.dev · CISA KEV | 20 |
| Credential breach exposureChecks whether your domain appears in known breach data. | HaveIBeenPwned | 10 |
| Total points possible | 120 | |
What the website software check does not cover. It looks only at your public website — the software your site discloses about itself, and whether that exact version has publicly documented security flaws. It does not examine network services, remote-access tools, or any device on your office network. And when your site keeps its version number private (which is a sensible default), we look nothing up and report no result rather than guess.
Sometimes a check can't complete — our TLS check can't reach the site, a breach lookup is inconclusive, or a website hides its software version so there is nothing to look up. When that happens the check is marked “not measured” and removed from the denominator entirely. A scanner timeout is a fact about our scanner, not about your security, so it never lowers (or raises) your score, and we never raise an alarm about it.
The self-assessment asks about practices no external scan can see — MFA, backups, training. “Yes” earns full points, “Partial” earns half, “No” and “Unknown” earn zero. These answers are yours: they appear in every report marked self-reported, never as verified findings. The four HIPAA controls below only appear for medical and dental practices.
| Control | Category | Weight |
|---|---|---|
| Multi-Factor Authentication | Access Control | 15 |
| Tested Backups | Data Protection | 15 |
| Security Awareness Training | Workforce | 10 |
| Device Encryption | Data Protection | 10 |
| Access Reviews | Access Control | 8 |
| Incident Response Plan | Incident Response | 12 |
| Workstation Screen Lock | Access Control | 5 |
| Patch Management | Vulnerability Management | 15 |
| Password Policy | Access Control | 8 |
| Vendor Security Review | Third-Party Risk | 7 |
| Business Associate AgreementsHIPAA overlay | Compliance | 15 |
| ePHI Access ControlsHIPAA overlay | Access Control | 12 |
| Audit LoggingHIPAA overlay | Audit Controls | 10 |
| Transmission SecurityHIPAA overlay | Data Protection | 12 |
| Total points possible | 154 | |
A
90–100
Excellent
B
70–89
Good
C
50–69
Fair
D
30–49
Poor
F
0–29
Poor
See your own score in under a minute
Free, no account, external scan only.
Run a Free Scan