B-
Trust rating
Good · 80/100
Procurement snapshot
0 critical findings identified — these point to architectural gaps, not just configuration tweaks.
Strengths
DNS CAA Records
TLS Configuration
TLS Protocol Support
Known Breaches
Estimated remediation effort: 1–2 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change
1 scan · Last scanned August 17, 2026
Score
100
75
50
25
0
B-
80/100
Compliance & Certifications
SOC 2 Type II
3rd party · AICPA
Pro subscribers only
ISO 27001
3rd party · accredited body
Pro subscribers only
GDPR
Self-reported
Pro subscribers only
CCPA
Self-reported
Pro subscribers only
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Pro subscribers only
Security Posture
6 items need attention
9 passed
Add 3 missing security headers
Security Headers
This leaves visitors exposed to attacks like clickjacking and content-type sniffing. umfrage.magenta.at is missing 3 of the 5 security headers browsers use to protect visitors — for example, one stops your site being loaded inside a hidden frame on another site to trick people into clicking things (clickjacking). These are settings, not code changes, so they're usually quick to add. On top of that, 2 of the headers you do have are misconfigured: CSP: 'unsafe-inline' in script directives — negates XSS protection; CSP: 'unsafe-eval' allows eval() — weakens XSS protection.
PCI-DSS 4.0Req 6.4.1
Security headers are required application controls
OWASPSecure Headers
Recommended baseline for web applications
How to fix this
1Add these headers exactly as shown. If you manage your own server (nginx, Apache, IIS) or a CDN like Cloudflare, add it in that config. If your site is on a managed platform (Wix, Squarespace, Shopify, WordPress.com), search their help center for "custom headers" or ask their support — most support it, though a few don't.
X-Frame-Options: SAMEORIGIN
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()
2Fix these existing headers — they're present but not doing their job: CSP: 'unsafe-inline' in script directives — negates XSS protection; CSP: 'unsafe-eval' allows eval() — weakens XSS protection. If you manage your own server (nginx, Apache, IIS) or a CDN like Cloudflare, add it in that config. If your site is on a managed platform (Wix, Squarespace, Shopify, WordPress.com), search their help center for "custom headers" or ask their support — most support it, though a few don't.
3Confirm it worked: search "http header checker" and enter umfrage.magenta.at — check the headers below in the response.
Report unlocked.
View all 9 passed checks
DNS CAA Records
TLS Configuration
TLS Protocol Support
Known Breaches
HSTS Header
Cookie Security
Certificate Hygiene
CVE Exposure
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Trust Center
trust.umfrage.magenta.at ↗
Security page
umfrage.magenta.at/security ↗
Privacy Policy
umfrage.magenta.at/privacy ↗
DPA (Data Processing Agreement)
umfrage.magenta.at/dpa ↗
Updated recently
Subprocessors List
umfrage.magenta.at/policies/subprocessors ↗
Similar companies
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Top AI vendors by trust score
94 companies · LynxRadar ranking
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking