Scanverra
Security Audit

Turn a scan into compliance evidence

A security scan is only useful if you can act on it. Every finding here is organized into a concern category and mapped to the SOC 2 and GDPR controls it's relevant to.

Run free security audit

What the scan covers

Headers & transport

CSP, HSTS (with a live check against the Chrome HSTS preload list), X-Frame-Options, and TLS/certificate configuration.

Exposure

Exposed secrets, sensitive files, and admin/backup paths accidentally revealed in robots.txt.

Cookies & CORS

Missing Secure/HttpOnly cookie flags and permissive CORS configuration.

Reference mapping

Every finding tagged with a CWE identifier and an OWASP Top 10 (2021) category, plus PCI relevance where applicable.

Concern category to control mapping

ConcernSOC 2GDPR
Secrets exposureCC6.1, C1.1Art. 32
Transport encryptionCC6.7Art. 32
Access controlCC6.1Art. 25
Injection riskCC6.8Art. 32
Dependency vulnerabilitiesCC6.8Art. 32
Information disclosureC1.1Art. 5(1)(f)
Monitoring gapsCC7.2Art. 33
Configuration hardeningCC6.6Art. 25
Heuristic category mapping, not a certified assessment - compliance also requires non-technical controls this scanner can't evaluate.

How it works

From raw findings to categorized, mapped evidence.

Paste your URL

No agent install, no code access - an external scan against your live site, the same view an attacker gets.

Findings, categorized

Each issue is bucketed into a concern category (secrets, transport encryption, access control, and more) rather than left as a flat list.

Mapped to controls

Every concern category is mapped to relevant SOC 2 Trust Services Criteria and GDPR articles, as a starting point for audit evidence.

FAQ

Frequently asked questions

Is this a certified SOC 2 or GDPR compliance assessment?

No, and we're explicit about that in the product itself: this is a heuristic category mapping, not a certified assessment. A scanner finding is evidence relevant to a control, not proof the control is met - SOC 2 and GDPR compliance also require non-technical controls (policies, access reviews, vendor management) this scan can't evaluate. Use it as a useful starting point for gathering evidence, not a substitute for an actual audit.

What's the difference between this and the Security Headers Checker?

The Security Headers Checker goes deep on one thing - HTTP security headers, with full CSP directive analysis and HSTS preload verification. This audit takes the broader scan (headers plus secrets, cookies, CORS, and more) and organizes it around compliance-relevant concern categories and their mapped controls.

Which SOC 2 Trust Services Criteria are covered?

The scan's findings map to several Common Criteria (CC6.1 Logical Access, CC6.6 Network Security Configuration, CC6.7 Transmission Confidentiality, CC6.8 Malicious Code Prevention, CC7.2 System Monitoring) and the Confidentiality criterion (C1.1) - the criteria most directly tied to what an external website scan can actually observe.

Which GDPR articles does it reference?

Primarily Article 32 (Security of Processing), Article 25 (Data Protection by Design), and Article 5(1)(f) (Integrity and Confidentiality) - the articles concerned with technical security measures, which is what an external scan can speak to.

Free - no sign-up required

Run a free security audit

Findings categorized and mapped to SOC 2 and GDPR controls.

Run free audit