nist.gov

A-
Pass · 90/100
Shows meaningful security gaps that need attention. Positive signals: DMARC / Email Security, Known Breaches, and DNS Configuration all passed. 3 action items identified, including 0 critical. The issues are configuration gaps, not architectural problems. A focused remediation effort of 1–2 days could address all findings.
Trust Score Trend
→ No change 1 scan · Last scanned February 15, 2026
Score
100 75 50 25 0
A-
nist.gov
90/100
Compliance & Certifications
Not yet verified
SOC 2 TYPE II
SOC 2 Type II
Audit report not on file
3rd party · AICPA
Pro subscribers only
ISO 27001
ISO 27001
Certificate not on file
3rd party · accredited body
Pro subscribers only
GDPR
GDPR
DPA not on file
Self-reported
Pro subscribers only
CCPA
CCPA
Privacy policy not on file
Self-reported
Pro subscribers only
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
Security Posture
3 items need attention
7 passed
Add a backup mail server record
MX Records & Mail Provider
30 minutes

This is a business-continuity gap — a single point of failure for all inbound email. nist.gov only has one mail server listed to receive email. If that single server has an outage, incoming email has nowhere else to go — it gets delayed or bounced back to the sender until the server recovers.

How to fix this
1Ask your email provider whether they publish a second/backup mail server address (most do).
2Add it as a second MX record in your DNS settings (you're using Microsoft 365 — see https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure), with a higher priority number than your main one (higher number = lower priority = used only as backup).
3Confirm it worked: search "mx record checker" and enter nist.gov — you should see 2 or more records.
Report unlocked.
View all 7 passed checks
DMARC / Email Security
Known Breaches
DNS Configuration
TLS Configuration
HSTS Header
CVE Exposure
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Self-hosted Trust Center
csrc.nist.gov
Security page
nist.gov/security ↗
Privacy Policy
nist.gov/privacy ↗
DPA (Data Processing Agreement)
nist.gov/dpa ↗
Updated recently
Subprocessors List
nist.gov/policies/subprocessors ↗
Tech Stack Detected
Subprocessors
Cloudflare
Similar companies
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
Track
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Track
Top AI vendors by trust score
94 companies · LynxRadar ranking
Track
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking
Track