nih.gov

B
Trust rating
Good · 85/100
Procurement snapshot
No critical findings. The 2 remaining items are configuration gaps, not architectural problems.
Strengths
Known Breaches
HSTS Header
CVE Exposure
DMARC / Email Security
Estimated remediation effort: 1–2 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change 1 scan · Last scanned February 15, 2026
Your rating Industry average
Score
100 75 50 25 0
B
nih.gov
85/100
Compliance & Certifications
Not yet verified
Fed RAMP
FedRAMP
ATO not on file
3rd party · 3PAO
Pro subscribers only
NIST 800-53
NIST 800-53
Not on file
Federal control baseline
Pro subscribers only
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
Security Posture
2 items need attention
8 passed
Add 2 optional security headers
Security Headers
< 1 hour

This is a minor hardening gap, not a significant risk on its own. nih.gov already has most of the recommended security headers — nice work. The remaining 2 are a smaller, best-practice improvement rather than an urgent gap.

How to fix this
1Add these headers exactly as shown. You're using Cloudflare in front of this site — add it there, see https://developers.cloudflare.com/rules/transform/response-header-modification/create-dashboard/.
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()
2Confirm it worked: search "http header checker" and enter nih.gov — check the headers below in the response.
Report unlocked.
View all 8 passed checks
Known Breaches
HSTS Header
CVE Exposure
DMARC / Email Security
MX Records & Mail Provider
Certificate Hygiene
DNS Configuration
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Trust Center
trust.nih.gov ↗
Security page
nih.gov/security ↗
Privacy Policy
nih.gov/privacy ↗
DPA (Data Processing Agreement)
nih.gov/dpa ↗
Updated recently
Subprocessors List
nih.gov/policies/subprocessors ↗
Tech Stack Detected
Subprocessors
Cloudflare
Similar companies in Government / Public Sector
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
Track
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Track
Top AI vendors by trust score
94 companies · LynxRadar ranking
Track
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking
Track