grc-scan
← Back to home

Security Posture Scanner

Enter a domain to check its public security hygiene. Plain-language results, no jargon.

NIST CSF 2.0ISO/IEC 27001CIS Controls v8

Findings mapped to the frameworks above, in plain language. Built by a risk & GRC practitioner. How it works →

What this check does to your site (and what it doesn't)

This is a passive check — it never logs in, sends no attack traffic, and changes nothing. It only reads information your domain already publishes to the public internet:

  • Your website's security headers (one ordinary page request, like a browser).
  • Public DNS records — SPF, DMARC, CAA, DNSSEC.
  • Your HTTPS certificate and TLS settings.
  • Your domain's reputation — we look up its public IP and ask free threat-intelligence databases (AbuseIPDB, VirusTotal, URLhaus, Google Safe Browsing) whether anyone has reported it as malicious. We query them about you; we never contact your server for this.

One privacy note: the reputation step shares the domain name (public information) with those third-party services so they can look it up. Nothing private is sent, and no login is required.