Skip to main content

Germany security reports

Browse 14,812 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 296 of 297|Showing 14751-14800 of 14812
ad-agents.com favicon

ad agents GmbH

ad-agents.com

66
TechnologyGermanymediumMEDIUM

ad agents GmbH is a well-established digital marketing agency based in Germany, specializing in online and performance marketing services. Founded in 2006, the company offers a comprehensive portfolio including search engine advertising, SEO, Amazon marketplace services, affiliate management, social media advertising, consulting, analytics, and product data management. The agency serves a broad business audience seeking to enhance their digital marketing performance nationally and internationally. The website reflects a mature digital presence with excellent content quality, strong branding consistency, and multiple trust indicators such as client testimonials and industry certifications. Technically, the site is built on WordPress with modern performance optimizations and integrates advanced marketing and analytics tools like HubSpot, Usercentrics CMP, and eTracker. Security posture is good with valid SSL, HSTS enabled, and SPF records configured, though TLS protocols are currently disabled, which is a notable gap. Privacy compliance is well addressed with GDPR-aligned cookie consent mechanisms. Overall, the company demonstrates a strong market position with a professional and trustworthy online presence.

25
43
17
100
85
85
75
digitalmarketingperformancemarketingseoseaaffiliate+4 more
WordPressYoast SEOWP RocketHubSpot+6

Partner Domains:

adtraction.com
partnerpending
amalytix.com
partnerpending

+3 more partners

2025-06-14T13:03:27.397Z
solarisgroup.com favicon

Solarisbank AG

solarisgroup.com

72
FinanceGermanylargeMEDIUM

Solarisbank AG operates as a leading embedded finance platform in Europe, providing a comprehensive Banking-as-a-Service solution that enables businesses to integrate digital banking, payments, lending, and identification services via advanced APIs. The company holds a full German banking license, allowing it to operate across the EU with a strong compliance and regulatory framework. Solarisbank's market position is reinforced by partnerships with notable clients such as American Express and Tomorrow, and a clear focus on customer-centric financial product innovation. Technically, Solarisbank employs modern web technologies including React and Gatsby, hosted on AWS infrastructure, with a cloud-based banking platform emphasizing scalability and international expansion. The website demonstrates good performance, mobile optimization, accessibility, and SEO practices, supported by a robust API-driven backend. From a security perspective, Solarisbank maintains a valid SSL certificate, enforces HSTS with preload, and implements SPF DNS records. However, the absence of enabled TLS 1.2 or higher protocols and lack of DNSSEC and CAA records present areas for improvement. The company provides clear privacy policies, cookie consent mechanisms, and incident response contact channels, reflecting a mature security posture. Overall, Solarisbank presents a high-trust, professional digital presence with strong business and technical foundations. Strategic enhancements in security protocols and transparency around vulnerability disclosures would further strengthen its risk profile and customer confidence.

80
43
25
95
75
85
100
solarisbankbankbankingplatformdigital+6 more
ReactGatsbyRESTful APIsCloud-based infrastructure+1

Partner Domains:

whispli.com
serviceanalyzing...
americanexpress.com
partner72

+1 more partners

2025-06-14T13:03:15.572Z
volkswagen-versicherungsdienst.de favicon

Volkswagen Financial Services

volkswagen-versicherungsdienst.de

65
FinanceGermanyenterpriseMEDIUM

Volkswagen Financial Services AG operates the volkswagen-versicherungsdienst.de website, providing a comprehensive portfolio of automotive insurance products including liability, partial and full coverage, warranty extensions, leasing rate insurance, credit protection, and travel insurance. The site targets primarily German private and business customers, leveraging the strong Volkswagen brand and integrated financial services ecosystem. The website is built on Adobe Experience Manager with extensive use of modern web technologies and content delivery networks, ensuring excellent performance and user experience. However, the SSL configuration is critically flawed with a self-signed certificate and no enabled TLS protocols, which undermines secure communications. Security headers are well implemented, but the absence of a cookie consent mechanism and explicit security or incident response policies indicates gaps in compliance and transparency. The site integrates multiple marketing and analytics tools, including Adobe Analytics, Google Tag Manager, and UserZoom, reflecting extensive user tracking. Overall, the site is professional, content-rich, and trustworthy from a business perspective but requires urgent security improvements to protect user data and comply with best practices.

80
18
25
85
72
85
100
insuranceautomotiveleasingfinancingvolkswagen+5 more
Adobe Experience Manager (AEM)Adobe Launch (Tag Manager)Helix RUM (Adobe Helix Real User Monitoring)UserZoom (UX feedback tool)+7

Partner Domains:

volkswagenbank.de
partner69
vwfs.de
partner69

+2 more partners

2025-06-14T13:02:51.574Z
V

Volkswagen Financial Services AG

volkswagen-bank.com

69
FinanceGermanylargeMEDIUM

Volkswagen Financial Services AG operates as the financial and mobility services provider for the Volkswagen Group across Europe, managing financing, leasing, insurance, and mobility solutions in 17 markets. The company holds a strong market position as a wholly-owned subsidiary of Volkswagen AG, with a large operational footprint and a focus on sustainability and customer mobility. The website reflects a professional and consistent brand presence with comprehensive investor relations and media content. Technically, the site is built on Adobe Experience Manager, leveraging modern content delivery and third-party integrations for analytics and marketing. Security headers and policies are well implemented, though some SSL/TLS configuration anomalies were detected, likely due to scanning artifacts or misconfigurations. Overall, the security posture is solid but could be improved by enabling modern TLS protocols and publishing explicit security policies. The site demonstrates good privacy compliance with a comprehensive privacy policy and consent mechanisms for external data sources. Social media presence and trust indicators support a high level of trustworthiness.

80
43
22
75
80
85
100
volkswagenfinancialservicessustainabilityinvestorrelationscareer+4 more
Adobe Experience Manager (AEM)Adobe Launch (Tag Manager)JavaScriptHelix RUM+7

Partner Domains:

vwfs.com
subsidiary73
volkswagenbank.de
subsidiary69

+1 more partners

2025-06-14T12:59:57.378Z
arri.com favicon

ARRI GmbH

arri.com

69
MediaGermanylargeMEDIUM

ARRI GmbH is a well-established leader in the media industry, specializing in the design and manufacture of professional camera and lighting systems for the film and broadcast sectors. With a history dating back to 1917, ARRI maintains a strong market position supported by a comprehensive product portfolio including camera systems, lenses, lighting, rental services, and virtual production solutions. The company targets industry professionals and production companies worldwide, leveraging a large-scale operational footprint and partnerships such as ARRI Rental and Claypaky. Technically, the website is built on a modern stack including CoreMedia CMS, React, and is hosted on AWS CloudFront, delivering fast performance and good mobile optimization. Security measures include a valid SSL certificate and several HTTP security headers, though the lack of modern TLS protocols and DNSSEC indicates room for improvement. Privacy and cookie policies are present and GDPR compliant, with a consent mechanism implemented via Usercentrics. Overall, ARRI demonstrates a mature digital presence with strong branding, comprehensive content, and good security hygiene, though enhancements in encryption protocols and security disclosures could further strengthen its posture.

60
25
25
100
85
85
100
camerasystemslightingfilmindustrybroadcastvirtualproduction+3 more
nginxCoreMedia CMSJavaScriptReact (react-bundle)+7

Partner Domains:

arrirental.com
partnerpending
claypaky.it
partnerpending
2025-06-14T12:59:19.393Z
solarisbank.com favicon

Solarisbank AG

solarisbank.com

73
FinanceGermanylargeMEDIUM

Solarisbank AG operates as a leading embedded finance platform in Europe, offering a comprehensive Banking-as-a-Service solution that enables businesses to integrate digital banking, payment, lending, and identification services via advanced RESTful APIs. The company holds a full German banking license, allowing it to operate seamlessly across EU countries. Solarisbank targets businesses seeking to embed financial services into their products, positioning itself as a neutral B2B2X partner with a strong market presence and trusted by major innovators such as Samsung and American Express. Technically, Solarisbank's website is built on modern frameworks including React and Gatsby, hosted on Netlify, and leverages Contentful as a CMS. The platform demonstrates excellent performance, mobile optimization, and accessibility, with a well-structured navigation and high-quality content. Analytics are implemented via piwik.pro, reflecting a moderate level of user tracking with good privacy compliance. From a security perspective, Solarisbank employs robust HTTP security headers including HSTS with preload, X-Frame-Options, and Content-Security-Policy, although the absence of enabled TLS protocols is a notable gap. The site lacks a cookie consent mechanism and a public vulnerability disclosure page, but provides clear contact channels for incident reporting and names key compliance officers, including a Money Laundering Reporting Officer. Overall, Solarisbank presents a high level of professionalism, trustworthiness, and technical maturity. Strategic recommendations include enabling modern TLS protocols, refining CSP policies, implementing cookie consent, and publishing a vulnerability disclosure policy to further enhance security posture and regulatory compliance.

80
43
25
100
75
85
100
solarisbankbankbankingplatformdigital+5 more
ReactGatsbyNetlify

Partner Domains:

solarisgroup.com
servicepending
whispli.com
servicepending
2025-06-14T12:59:03.944Z
dekra-akademie.de favicon

DEKRA Akademie GmbH

dekra-akademie.de

65
EducationGermanylargeMEDIUM

DEKRA Akademie GmbH is a well-established German education and training provider specializing in professional development, certification, and continuing education across multiple sectors including transportation, healthcare, and technology. The company operates a comprehensive digital platform leveraging Salesforce Visualforce and Azure Search technologies, supported by a robust consent management system via Usercentrics. Their market position is strong with a nationwide presence and a broad portfolio of courses and services tailored to both private individuals and corporate clients. The website demonstrates high content quality, consistent branding, and clear navigation, supporting a positive user experience. Security posture is good with valid SSL certificates, HSTS, and content security policies, though the absence of modern TLS protocols and DNSSEC indicates room for improvement. Privacy and cookie policies are comprehensive and GDPR compliant, reflecting a mature approach to data protection. Overall, the digital infrastructure supports the business model effectively, though enhancements in security protocols and incident response transparency would further strengthen trust and resilience.

70
18
25
85
80
85
100
EducationTrainingCertificationDEKRACompliance+5 more
JavaScriptVisualforce (Salesforce)Azure SearchUsercentrics CMP+4

Partner Domains:

dekra.de
parent69
dekra-neo.com
relatedpending

+1 more partners

2025-06-14T12:47:13.462Z
heyflow.com favicon

Heyflow GmbH

heyflow.com

75
TechnologyGermanymediumMEDIUM

Heyflow GmbH is a technology company specializing in no-code lead generation solutions, offering interactive lead funnels, multi-step forms, and customizable landing pages. Positioned as a user-friendly platform with native analytics and extensive integrations, Heyflow targets performance marketers, designers, agencies, and enterprises seeking to optimize lead conversion. The company is based in Germany and founded in 2020, with a medium-sized operational scale. Technically, Heyflow employs modern web technologies including Eleventy for static site generation, Cloudflare and Netlify for hosting and CDN, and integrates analytics tools like Matomo and Google Analytics. The website demonstrates excellent performance, mobile optimization, and SEO practices. Security-wise, Heyflow maintains a strong posture with ISO 27001 certification, GDPR compliance, robust security headers, and HSTS enabled, though TLS protocols could be updated for enhanced security. The company actively manages user consent and privacy through Usercentrics CMP and provides clear legal documentation. Overall, Heyflow presents a professional, trustworthy, and technically mature digital presence with a focus on security and compliance.

95
43
25
100
75
85
100
lead generationno-codeinteractive formslanding pagesA/B testing+4 more
EleventyCloudflareNetlifyMatomo Analytics+6

Partner Domains:

trust.heyflow.com
service
get.heyflow.com
service

+1 more partners

2025-06-14T12:27:02.555Z
superfund.de favicon

Die neue Dimension der Geldanlage-Investieren in eine digitale Zukunft

superfund.de

51
financeGermanymediumMEDIUM

The website's security posture is currently weak, with significant deficiencies across multiple critical areas including privacy compliance, email authentication, and security policy frameworks. Critical gaps in GDPR adherence expose the business to regulatory penalties and reputational damage, especially given its EU operations without adequate privacy measures. The absence of key HTTP security headers leaves the site vulnerable to common web-based attacks such as clickjacking, content injection, and cross-site scripting. Email infrastructure lacks essential authentication mechanisms, increasing risks of phishing and email spoofing. Additionally, missing incident response and security documentation undermines the organization’s ability to detect, respond to, and recover from security incidents effectively. While SSL/TLS and DNS configurations are relatively stronger, urgent attention is needed to enable HSTS and extend certificate validity. Overall, this assessment reveals a pressing need to implement foundational security controls and compliance policies to safeguard the business and its customers. Failure to address these issues promptly could result in severe operational, financial, and legal consequences.

15
15
17
55
80
85
90
financeinvestmentdigital financecookie consent
JavaScriptCookiebotnginxJavaScript modules

Partner Domains:

superfundgroup.com
subsidiarypending
wirecard.com
paymentpending

+1 more partners

2025-06-13T18:13:49.869Z