A-
Trust rating
Excellent · 92/100
Procurement snapshot
No critical findings. The 1 remaining item is configuration gap, not architectural problems.
Strengths
Known Breaches
TLS Configuration
HSTS Header
Security Headers
Estimated remediation effort: 1–2 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change
1 scan · Last scanned February 15, 2026
Your rating
Industry average
Score
100
75
50
25
0
A-
92/100
Compliance & Certifications
FedRAMP
3rd party · 3PAO
Pro subscribers only
NIST 800-53
Federal control baseline
Pro subscribers only
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Pro subscribers only
Security Posture
1 item need attention
9 passed
Finish setting up email authentication
DMARC / Email Security
Spoofed emails can still reach your customers and partners until this is fully enforced. Email authentication for gsa.gov is partly set up, but there are gaps: SPF isn't set up. Until it's fully in place, someone could still send a convincing fake email pretending to be you.
NIST CSFPR.AC-7
Email authentication is a required access control
How to fix this
1Add an SPF record in your DNS settings (you're using Google Workspace — see https://knowledge.workspace.google.com/admin/security/set-up-dkim):
v=spf1 include:_spf.google.com -all
2Double-check it's live: search "dmarc record checker" and enter gsa.gov.
View all 9 passed checks
Known Breaches
TLS Configuration
HSTS Header
Security Headers
CVE Exposure
DNS Configuration
MX Records & Mail Provider
Certificate Hygiene
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Trust Center
trust.gsa.gov ↗
Security page
gsa.gov/security ↗
Privacy Policy
gsa.gov/privacy ↗
DPA (Data Processing Agreement)
gsa.gov/dpa ↗
Updated recently
Subprocessors List
gsa.gov/policies/subprocessors ↗
Tech Stack Detected
Subprocessors
Amazon CloudFront
Similar companies in Government / Public Sector
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Top AI vendors by trust score
94 companies · LynxRadar ranking
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking