Featured in our Forbes AI 50 security study: see how sierra.ai compares with the other 49 →
A-
Trust rating
Excellent · 92/100
Procurement snapshot
0 critical findings identified — these point to architectural gaps, not just configuration tweaks.
Strengths
MX Records & Mail Provider
TLS Protocol Support
security.txt (RFC 9116)
TLS Configuration
Estimated remediation effort: 1–4 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change
1 scan · Last scanned September 28, 2026
Score
100
75
50
25
0
A-
92/100
Compliance & Certifications
SOC 2 Type II
3rd party · AICPA
ISO 27001
3rd party · accredited body
GDPR
Self-reported
CCPA
Self-reported
Incident History
No public breaches on record
Security Posture
5 items need attention
10 passed
Add missing cookie security settings
Cookie Security
This makes it meaningfully easier for an attacker to hijack authenticated customer sessions, increasing account-takeover risk. On sierra.ai, most cookies are missing key protections: 1 cookie(s) can be sent over an unencrypted connection (missing the "Secure" flag); 2 cookie(s) can be read by page scripts, including malicious ones (missing "HttpOnly"); 1 cookie(s) don't restrict cross-site requests (missing "SameSite").
OWASP ASVS3.4
Session cookies use Secure, HttpOnly, and SameSite attributes
How to fix this
1Add Secure to every cookie your site sets — this is usually one line in your app's session/cookie config, not a DNS or hosting setting.
2Add HttpOnly to login/session cookies — same place as above, in your app's cookie settings.
3Add SameSite=Lax (or Strict for sensitive cookies) to every cookie.
4This needs a developer — it's a one-line change per cookie in your website's code, not something changeable from a hosting dashboard.
5Re-scan afterward to confirm all three flags are now set.
Report unlocked.
View all 10 passed checks
MX Records & Mail Provider
TLS Protocol Support
security.txt (RFC 9116)
TLS Configuration
HSTS Header
Subprocessors & Tech Stack
CVE Exposure
Known Breaches
DMARC / Email Security
Certificate Hygiene
Couldn't check: Malware / Phishing Blocklist — the check didn't complete (the site blocked or timed out our scanner, or a data source was unavailable), so this isn't counted in the score.
Company Signals
Operational risk
Last funding
Employees
Trust Resources
Claim profile →
Trust Center
Not detected
Security contact (security.txt)
sierra.ai/.well-known/security.txt
Privacy Policy
DPA (Data Processing Agreement)
Subprocessors List
Similar companies
Appears in
Vendors graded A
377 companies · LynxRadar ranking
Top 10% by security score
287 companies · LynxRadar ranking
LynxRadar Pro
Unlock the full report
$9/mo · cancel anytime
- Step-by-step fixes with copy-paste values for every finding
- Procurement-ready PDF report for vendor reviews
- Alerts when a vendor's grade changes coming soon
- Company signals, incident history & compliance status coming soon
Pro is launching soon — we'll email you when it's ready.