iana.org

B
Trust rating
Good · 85/100
Procurement snapshot
1 critical finding identified — these point to architectural gaps, not just configuration tweaks.
Strengths
DNS CAA Records
TLS Configuration
TLS Protocol Support
DNS Configuration
Questions to ask
Confirm email authentication (SPF/DKIM/DMARC) rollout plans
Sign in to see 1 more
Estimated remediation effort: 2–5 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change 1 scan · Last scanned April 10, 2026
Your rating Industry average
Score
100 75 50 25 0
B
iana.org
85/100
Compliance & Certifications
Not yet verified
Fed RAMP
FedRAMP
ATO not on file
3rd party · 3PAO
Pro subscribers only
NIST 800-53
NIST 800-53
Not on file
Federal control baseline
Pro subscribers only
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
Security Posture
2 items need attention
13 passed
0 of 1 fixed
All 1 critical issue marked as fixed
Re-scan to confirm and update your score.
Turn on email authentication (SPF, DKIM, DMARC)
DMARC / Email Security
1–2 days

This exposes customers, partners, and employees to phishing attacks that impersonate your brand. Right now, anyone can send an email that looks like it came from [email protected] — no password or hack required. This is how the vast majority of phishing scams that impersonate a company work, and it can damage your reputation with customers even though your systems were never touched. Missing: DKIM.

NIST CSFPR.AC-7
Email authentication is a required access control
ISO 27001A.13.2.1
Information transfer policies require email security controls
HIPAA§164.312(e)
Transmission security for electronic PHI
How to fix this
1Turn on DKIM signing — look for "DKIM" under your email provider's admin/security settings. It will generate a record for you to paste into the same DNS settings above.
2After 2–4 weeks, check the DMARC reports for anything legitimate that got flagged, then tighten the policy from quarantine to reject.
Report unlocked.
View all 13 passed checks
DNS CAA Records
TLS Configuration
TLS Protocol Support
DNS Configuration
MX Records & Mail Provider
Cookie Security
HSTS Header
Security Headers
Known Breaches
security.txt (RFC 9116)
CVE Exposure
Certificate Hygiene
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Trust Center
trust.iana.org ↗
Security page
iana.org/security ↗
Privacy Policy
iana.org/privacy ↗
DPA (Data Processing Agreement)
iana.org/dpa ↗
Updated recently
Subprocessors List
iana.org/policies/subprocessors ↗
Tech Stack Detected
Subprocessors
Cloudflare
Similar companies in Government / Public Sector
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
Track
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Track
Top AI vendors by trust score
94 companies · LynxRadar ranking
Track
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking
Track