Turn a scan into compliance evidence
A security scan is only useful if you can act on it. Every finding here is organized into a concern category and mapped to the SOC 2 and GDPR controls it's relevant to.
Run free security auditWhat the scan covers
Headers & transport
CSP, HSTS (with a live check against the Chrome HSTS preload list), X-Frame-Options, and TLS/certificate configuration.
Exposure
Exposed secrets, sensitive files, and admin/backup paths accidentally revealed in robots.txt.
Cookies & CORS
Missing Secure/HttpOnly cookie flags and permissive CORS configuration.
Reference mapping
Every finding tagged with a CWE identifier and an OWASP Top 10 (2021) category, plus PCI relevance where applicable.
Concern category to control mapping
| Concern | SOC 2 | GDPR |
|---|---|---|
| Secrets exposure | CC6.1, C1.1 | Art. 32 |
| Transport encryption | CC6.7 | Art. 32 |
| Access control | CC6.1 | Art. 25 |
| Injection risk | CC6.8 | Art. 32 |
| Dependency vulnerabilities | CC6.8 | Art. 32 |
| Information disclosure | C1.1 | Art. 5(1)(f) |
| Monitoring gaps | CC7.2 | Art. 33 |
| Configuration hardening | CC6.6 | Art. 25 |
How it works
From raw findings to categorized, mapped evidence.
Paste your URL
No agent install, no code access - an external scan against your live site, the same view an attacker gets.
Findings, categorized
Each issue is bucketed into a concern category (secrets, transport encryption, access control, and more) rather than left as a flat list.
Mapped to controls
Every concern category is mapped to relevant SOC 2 Trust Services Criteria and GDPR articles, as a starting point for audit evidence.
Frequently asked questions
Is this a certified SOC 2 or GDPR compliance assessment?
No, and we're explicit about that in the product itself: this is a heuristic category mapping, not a certified assessment. A scanner finding is evidence relevant to a control, not proof the control is met - SOC 2 and GDPR compliance also require non-technical controls (policies, access reviews, vendor management) this scan can't evaluate. Use it as a useful starting point for gathering evidence, not a substitute for an actual audit.
What's the difference between this and the Security Headers Checker?
The Security Headers Checker goes deep on one thing - HTTP security headers, with full CSP directive analysis and HSTS preload verification. This audit takes the broader scan (headers plus secrets, cookies, CORS, and more) and organizes it around compliance-relevant concern categories and their mapped controls.
Which SOC 2 Trust Services Criteria are covered?
The scan's findings map to several Common Criteria (CC6.1 Logical Access, CC6.6 Network Security Configuration, CC6.7 Transmission Confidentiality, CC6.8 Malicious Code Prevention, CC7.2 System Monitoring) and the Confidentiality criterion (C1.1) - the criteria most directly tied to what an external website scan can actually observe.
Which GDPR articles does it reference?
Primarily Article 32 (Security of Processing), Article 25 (Data Protection by Design), and Article 5(1)(f) (Integrity and Confidentiality) - the articles concerned with technical security measures, which is what an external scan can speak to.
Related audits
Website Audit
Run a free instant audit for performance, SEO, accessibility, and best practices.
SEO Audit
Check crawlability, metadata, structured data, and AI-agent discoverability.
Performance Audit
A full Lighthouse lab run across desktop and mobile, with framework-aware fixes.
Accessibility Audit
See exactly which WCAG 2.1/2.2 success criteria your site fails, and why.
Website Speed Test
How fast your site loads, in plain language - one number, no jargon.
Core Web Vitals Test
Check LCP, CLS, and INP against Google's thresholds, lab and field.
Broken Link Checker
Crawl a page's links and find the ones that are dead before your users do.
Security Headers Checker
CSP, HSTS, and every other HTTP security header - analyzed, not just listed.
Open Graph Checker
See whether your page has the og:title, og:description, and og:image tags social platforms need.
Schema Markup Checker
Check whether your page ships JSON-LD structured data search engines and AI agents can read.
Sitemap Checker
Check whether your sitemap.xml is reachable, valid, and free of common mistakes.
Redirect Checker
Trace a URL's redirect chain and catch loops, excess hops, and HTTPS-to-HTTP downgrades.
Related reading
Website Security Headers Explained: The Complete Checklist
CSP, HSTS, X-Frame-Options, and every other HTTP security header your site should ship - with copy-pasteable examples.
How to Implement a Content Security Policy Without Breaking Your Site
CSP is the highest-leverage security header and the easiest one to break your own site with - a safe rollout strategy using report-only mode.
Run a free security audit
Findings categorized and mapped to SOC 2 and GDPR controls.
Run free audit