hunter.io

A+
Pass · 100/100
Shows significant security gaps that need urgent attention. Positive signals: DNS Configuration, TLS Protocol Support, and TLS Configuration all passed. 4 action items identified, including 0 critical. The issues point to real architectural gaps, not just configuration tweaks. A focused remediation effort of 1–2 days could address all findings.
Trust Score Trend
→ No change 1 scan · Last scanned April 15, 2026
Your rating Industry average
Score
100 75 50 25 0
A+
hunter.io
100/100
Compliance & Certifications
Not yet verified
SOC 2 TYPE II
SOC 2 Type II
Audit report not on file
3rd party · AICPA
Pro subscribers only
ISO 27001
ISO 27001
Certificate not on file
3rd party · accredited body
Pro subscribers only
GDPR
GDPR
DPA not on file
Self-reported
Pro subscribers only
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
Security Posture
4 items need attention
11 passed
Add missing cookie security settings
Cookie Security
1–2 hours

This makes it meaningfully easier for an attacker to hijack authenticated customer sessions, increasing account-takeover risk. On hunter.io, most cookies are missing key protections: 1 cookie(s) can be sent over an unencrypted connection (missing the "Secure" flag); 1 cookie(s) can be read by page scripts, including malicious ones (missing "HttpOnly").

OWASP ASVS3.4
Session cookies use Secure, HttpOnly, and SameSite attributes
How to fix this
1Add Secure to every cookie your site sets — this is usually one line in your app's session/cookie config, not a DNS or hosting setting.
2Add HttpOnly to login/session cookies — same place as above, in your app's cookie settings.
3This needs a developer — it's a one-line change per cookie in your website's code, not something changeable from a hosting dashboard.
4Re-scan afterward to confirm all three flags are now set.
Report unlocked.
View all 11 passed checks
DNS Configuration
TLS Protocol Support
TLS Configuration
HSTS Header
Security Headers
Known Breaches
DMARC / Email Security
MX Records & Mail Provider
CVE Exposure
Certificate Hygiene
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Trust Center
trust.hunter.io ↗
Security page
hunter.io/security ↗
Privacy Policy
hunter.io/privacy ↗
DPA (Data Processing Agreement)
hunter.io/dpa ↗
Updated recently
Subprocessors List
hunter.io/policies/subprocessors ↗
Tech Stack Detected
Subprocessors
Cloudflare
Similar companies in B2B SaaS / Software
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
Track
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Track
Top AI vendors by trust score
94 companies · LynxRadar ranking
Track
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking
Track