C+
Trust rating
Fair · 78/100
Procurement snapshot
0 critical findings identified — these point to architectural gaps, not just configuration tweaks.
Strengths
MX Records & Mail Provider
TLS Protocol Support
TLS Configuration
MTA-STS & TLS Reporting
Questions to ask
Confirm DNSSEC rollout timeline
Estimated remediation effort: 1–3 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change
1 scan · Last scanned September 28, 2026
Score
100
75
50
25
0
C+
78/100
Compliance & Certifications
SOC 2 Type II
3rd party · AICPA
ISO 27001
3rd party · accredited body
GDPR
Self-reported
CCPA
Self-reported
Incident History
No public breaches on record
Security Posture
5 items need attention
10 passed
Turn on HSTS (forces browsers to always use HTTPS)
HSTS Header
This puts visitor logins and session data at risk of interception on untrusted networks. chrome.google.com doesn't send the HSTS header, so a browser can still be tricked into connecting over plain, unencrypted HTTP instead of HTTPS — an attacker on the same network (e.g. public wifi) can exploit that gap to intercept traffic. Turning HSTS on tells every browser "always use HTTPS for this site, no exceptions."
PCI-DSS 4.0Req 6.4.1
Required application security controls
NIST 800-53SC-8
Transmission confidentiality and integrity
How to fix this
1Add this response header to your site. If you manage your own server (nginx, Apache, IIS) or a CDN like Cloudflare, add it in that config. If your site is on a managed platform (Wix, Squarespace, Shopify, WordPress.com), search their help center for "custom headers" or ask their support — most support it, though a few don't.
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
2Before adding it, make sure every subdomain (not just the main site) also works over HTTPS — HSTS applies site-wide.
3Confirm it's live: search "http header checker" and enter chrome.google.com.
4Once confirmed, submit the domain at hstspreload.org so browsers enforce HTTPS even on a user's very first visit.
Report unlocked.
View all 10 passed checks
MX Records & Mail Provider
TLS Protocol Support
TLS Configuration
MTA-STS & TLS Reporting
DMARC / Email Security
Known Breaches
Cookie Security
Subprocessors & Tech Stack
CVE Exposure
Certificate Hygiene
Couldn't check: Malware / Phishing Blocklist — the check didn't complete (the site blocked or timed out our scanner, or a data source was unavailable), so this isn't counted in the score.
Company Signals
Operational risk
Last funding
Employees
Trust Resources
Claim profile →
Trust Center
Not detected
Privacy Policy
DPA (Data Processing Agreement)
Subprocessors List
Similar companies
Appears in
Vendors graded C
696 companies · LynxRadar ranking
LynxRadar Pro
Unlock the full report
$9/mo · cancel anytime
- Step-by-step fixes with copy-paste values for every finding
- Procurement-ready PDF report for vendor reviews
- Alerts when a vendor's grade changes coming soon
- Company signals, incident history & compliance status coming soon
Pro is launching soon — we'll email you when it's ready.