chrome.google.com

C+
Trust rating
Fair · 78/100
Procurement snapshot
0 critical findings identified — these point to architectural gaps, not just configuration tweaks.
Strengths
MX Records & Mail Provider
TLS Protocol Support
TLS Configuration
MTA-STS & TLS Reporting
Questions to ask
Confirm DNSSEC rollout timeline
Estimated remediation effort: 1–3 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change 1 scan · Last scanned September 28, 2026
Score
100 75 50 25 0
C+
chrome.google.com
78/100
Compliance & Certifications
Not yet verified
SOC 2 TYPE II
SOC 2 Type II
Audit report not on file
3rd party · AICPA
ISO 27001
ISO 27001
Certificate not on file
3rd party · accredited body
GDPR
GDPR
DPA not on file
Self-reported
CCPA
CCPA
Privacy policy not on file
Self-reported
Incident History
No public breaches on record
Security Posture
5 items need attention
10 passed
Turn on HSTS (forces browsers to always use HTTPS)
HSTS Header
< 1 hour High

This puts visitor logins and session data at risk of interception on untrusted networks. chrome.google.com doesn't send the HSTS header, so a browser can still be tricked into connecting over plain, unencrypted HTTP instead of HTTPS — an attacker on the same network (e.g. public wifi) can exploit that gap to intercept traffic. Turning HSTS on tells every browser "always use HTTPS for this site, no exceptions."

PCI-DSS 4.0Req 6.4.1
Required application security controls
NIST 800-53SC-8
Transmission confidentiality and integrity
How to fix this
1Add this response header to your site. If you manage your own server (nginx, Apache, IIS) or a CDN like Cloudflare, add it in that config. If your site is on a managed platform (Wix, Squarespace, Shopify, WordPress.com), search their help center for "custom headers" or ask their support — most support it, though a few don't.
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
2Before adding it, make sure every subdomain (not just the main site) also works over HTTPS — HSTS applies site-wide.
3Confirm it's live: search "http header checker" and enter chrome.google.com.
4Once confirmed, submit the domain at hstspreload.org so browsers enforce HTTPS even on a user's very first visit.
Report unlocked.
View all 10 passed checks
MX Records & Mail Provider
TLS Protocol Support
TLS Configuration
MTA-STS & TLS Reporting
DMARC / Email Security
Known Breaches
Cookie Security
Subprocessors & Tech Stack
CVE Exposure
Certificate Hygiene
Couldn't check: Malware / Phishing Blocklist — the check didn't complete (the site blocked or timed out our scanner, or a data source was unavailable), so this isn't counted in the score.
Company Signals
Operational risk
Last funding
Employees
Trust Resources
Claim profile →
Trust Center
Not detected
Privacy Policy
DPA (Data Processing Agreement)
Subprocessors List
Similar companies
Appears in
Vendors graded C
696 companies · LynxRadar ranking