Back to home

How the Security Posture Score works

Every check, every weight, every rule. This page is generated from the same code that computes your score.

The score in one paragraph

Your Security Posture Score is a number from 0 to 100 built from two ingredients: what our external scan observed about your public website and public records, and what you told us about your internal practices in the self-assessment. Before you complete the self-assessment, the score is 100% tool-observed. After, it blends 60% tool-observed + 40% self-reported. Reports always label which is which — we never present your own answers as something we verified.

Tool-observed checks and weights

Each check earns full points when passing, half points when partially in place (where partial credit applies), and zero when it's a gap. The section score is points earned divided by points possible, scaled to 100.

CheckData sourceWeight
SPF email authenticationDeclares which servers may send email as your domain.Public DNS15
DKIM email signingCryptographically signs outbound email so receivers can verify it.Public DNS11
DMARC anti-spoofing policyTells receiving servers to quarantine or reject spoofed email.Public DNS15
TLS / SSL encryptionWe connect to your site ourselves and read the certificate it serves — whether it is trusted, covers your address, when it expires, and whether retired TLS versions are still accepted.Our own TLS check20
HSTS headerForces browsers to always use HTTPS.Your homepage10
X-Content-Type-Options headerStops browsers executing files disguised as other types.Your homepage4
X-Frame-Options headerBlocks your site from being framed on malicious pages.Your homepage5
Content Security PolicyBrowser-level defense against cross-site scripting.Your homepage5
Referrer-Policy headerLimits URL data leaked to third-party sites.Your homepage5
Website software vulnerabilitiesReads the software version your website publishes about itself, then checks that exact version against public vulnerability databases and CISA’s list of flaws attackers are exploiting right now.OSV.dev · CISA KEV20
Credential breach exposureChecks whether your domain appears in known breach data.HaveIBeenPwned10
Total points possible120

What the website software check does not cover. It looks only at your public website — the software your site discloses about itself, and whether that exact version has publicly documented security flaws. It does not examine network services, remote-access tools, or any device on your office network. And when your site keeps its version number private (which is a sensible default), we look nothing up and report no result rather than guess.

If we couldn't measure it, it doesn't count against you

Sometimes a check can't complete — our TLS check can't reach the site, a breach lookup is inconclusive, or a website hides its software version so there is nothing to look up. When that happens the check is marked “not measured” and removed from the denominator entirely. A scanner timeout is a fact about our scanner, not about your security, so it never lowers (or raises) your score, and we never raise an alarm about it.

Self-reported controls and weights

The self-assessment asks about practices no external scan can see — MFA, backups, training. “Yes” earns full points, “Partial” earns half, “No” and “Unknown” earn zero. These answers are yours: they appear in every report marked self-reported, never as verified findings. The four HIPAA controls below only appear for medical and dental practices.

ControlCategoryWeight
Multi-Factor AuthenticationAccess Control15
Tested BackupsData Protection15
Security Awareness TrainingWorkforce10
Device EncryptionData Protection10
Access ReviewsAccess Control8
Incident Response PlanIncident Response12
Workstation Screen LockAccess Control5
Patch ManagementVulnerability Management15
Password PolicyAccess Control8
Vendor Security ReviewThird-Party Risk7
Business Associate AgreementsHIPAA overlayCompliance15
ePHI Access ControlsHIPAA overlayAccess Control12
Audit LoggingHIPAA overlayAudit Controls10
Transmission SecurityHIPAA overlayData Protection12
Total points possible154

Grades

A

90–100

Excellent

B

70–89

Good

C

50–69

Fair

D

30–49

Poor

F

0–29

Poor

What this score is not

  • Not a certification. ClearScan shows where your public-facing posture stands. It does not certify you as secure or compliant with HIPAA or any other regulation.
  • Not an internal audit.We only look at what's publicly visible — DNS, certificates, headers, and public breach data. We never access your systems, install anything, or handle patient or customer data.
  • Not a guarantee. A high score means the common, externally visible weaknesses attackers look for first are addressed — it cannot rule out every possible risk.

See your own score in under a minute

Free, no account, external scan only.

Run a Free Scan