Skip to main content

N/a security reports

Browse 29,065 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149319
Websites
130
Industries
113
Countries
52
Avg Score
Page 166 of 582|Showing 8251-8300 of 29065
un.org favicon

United Nations

un.org

71
GovernmentN/aenterpriseMEDIUM

The United Nations website serves as the official digital presence of the international intergovernmental organization dedicated to global peace, security, and humanitarian efforts. It provides multilingual access to reports, programs, and initiatives, targeting a global audience including governments, NGOs, and the public. The site is professionally designed with consistent branding and good content quality, reflecting its authoritative position. Technically, the site employs a mature technology stack including Bootstrap, jQuery, and Google Analytics with IP anonymization, ensuring a responsive and accessible user experience. However, the absence of explicit privacy and cookie policies and lack of security headers indicate areas for improvement in privacy compliance and security hardening. From a security perspective, the site uses HTTPS effectively but lacks visible security headers and detailed incident response or data protection contact information. The WHOIS data is unavailable or malformed, which limits domain registration trust analysis but does not detract from the site's legitimacy given its branding and content. Overall, the website is trustworthy and professional but would benefit from enhanced privacy disclosures, security headers, and transparent contact information to improve compliance and security posture.

85
35
2
85
100
80
100
governmentinternationalnon-profitmultilingualhumanitarian+1 more
jQuery 3.7.1Bootstrap 3.3.5Font Awesome 4.6.3Google Fonts (Roboto)+1
2025-10-07T17:38:06.498Z
F

🖤 ANTI-META FEDI PACT 🖤

fedipact.online

63
OtherN/asmallMEDIUM

The website fedipact.online serves as a community-driven platform advocating for Fediverse instance administrators and moderators to block Meta-owned instances, specifically targeting the project92 threat. It operates as a niche initiative within the decentralized social media ecosystem, providing a list of participating admins and a mechanism to sign a pact via an external cryptpad form. The site is simple in design and content, focusing on community coordination rather than commercial activity. Technically, the website is built with standard HTML, CSS, and JavaScript without reliance on major frameworks or CMS platforms. Hosting appears to be through Namecheap, consistent with the domain registration data. The site demonstrates basic mobile optimization and accessibility but lacks advanced SEO and performance optimizations. No analytics or advertising technologies are detected, indicating minimal user tracking. From a security perspective, the site lacks important security headers and does not enable DNSSEC, which could be improved to enhance domain and site security. There is no published privacy, cookie, or terms of service policy, which limits compliance with GDPR and other privacy regulations. Contact information is minimal but present, including an email address and a Mastodon handle for communication. Overall, the website is functional and serves its community purpose but would benefit from improved security practices, privacy compliance, and more professional content presentation to enhance trust and credibility.

40
50
17
70
95
70
100
fediversecommunitymoderationanti-metaprivacy+1 more
HTML5CSS3JavaScript
2025-10-07T17:38:00.803Z
masto.host favicon

Masto.host

masto.host

53
TechnologyN/asmallMEDIUM

Masto.host is a specialized service provider offering fully managed Mastodon hosting solutions. Founded in 2017, the company targets individuals and organizations seeking an easy and secure way to run Mastodon instances without the complexity of self-hosting. Their business model is subscription-based, with plans starting at $6 per month, emphasizing managed installation, security, and upgrades. The website reflects a focused niche market position with clear service offerings and positive user testimonials, indicating a trusted presence in the Mastodon hosting ecosystem. Technically, the website is built using modern static site generation technology (Eleventy), delivering fast performance and good mobile optimization. The absence of heavy scripts or analytics tools suggests a privacy-conscious approach. However, the site lacks some advanced security headers and cookie consent mechanisms, which could be improved to enhance compliance and security posture. From a security perspective, the site enforces HTTPS and uses domain status protections but does not enable DNSSEC or publish a security policy or incident response contacts. No vulnerabilities or exposed sensitive data were detected in the content. Overall, the security posture is solid but could benefit from additional hardening and transparency. The overall risk assessment is low, with no critical issues found. Strategic recommendations include enabling DNSSEC, implementing security headers, adding cookie consent for privacy compliance, and publishing a security policy. These steps will improve trust, compliance, and resilience against potential threats.

25
53
17
72
72
80
20
mastodonhostingmanagedservicesocialmediaopensource
Eleventy v2.0.1Font Awesome Pro 6.4.0Poppins fontSVG graphics
2025-10-07T17:37:45.718Z
thisisbeacon.com favicon

Veracity Trust Network

thisisbeacon.com

74
TechnologyN/amediumMEDIUM

Veracity Trust Network is a technology company specializing in AI-powered bot protection and ad fraud prevention solutions. Their patented Veracity Bot Protection Suite aims to secure digital infrastructure from automated attacks, API abuse, and fraudulent activities in real time. The company targets businesses and organizations that require advanced cybersecurity measures to protect their online assets and advertising investments. The website reflects a professional and consistent brand presence with a focus on B2B cybersecurity services. Technically, the website is built on WordPress using modern frameworks such as Bootstrap and Font Awesome, with integrations for Google Tag Manager and Cookiebot for analytics and cookie consent management. Hosting and DNS are managed via Cloudflare, providing a reliable infrastructure. Security posture is good with HTTPS enforced and domain registration locked against unauthorized transfers, though there is room for improvement in publishing explicit security policies, incident response contacts, and vulnerability disclosure information. Privacy compliance is partially addressed through cookie consent but lacks a clearly published privacy policy and terms of service. Overall, the website is professional, trustworthy, and well-positioned in the cybersecurity market, but could enhance transparency and security communication to further build trust.

55
95
47
60
75
80
100
cybersecuritybotprotectionadfraudpreventionaisecuritywebthreatprotection
WordPressWPBakery Page BuilderFont Awesome 6.7.2Google Tag Manager+3
2025-10-07T17:36:44.982Z
registry.pw favicon

Radix FZC

registry.pw

57
TechnologyN/amediumMEDIUM

Registry.pw operates as the official registry for the .PW top-level domain, targeting professionals and businesses seeking a dedicated online namespace. Established in 2012 and managed by Radix FZC, the website offers domain registration services, registrar accreditation, and policy information. The site positions itself as a registrar-friendly TLD operator with a global reach, emphasizing professional identity online. The business model revolves around domain registry operations and partnerships with registrars worldwide. Technically, the website is built on WordPress 5.8.12, utilizing common plugins such as Contact Form 7 and Cookie Law Info for forms and compliance. The site employs Cloudflare for DNS services and integrates Google Analytics and AdRoll for tracking and advertising. The technical infrastructure is moderately optimized with basic mobile responsiveness and accessibility features. SEO practices are good, with proper meta tags and structured navigation. From a security perspective, the site enforces HTTPS and includes a cookie consent banner with granular controls, indicating good privacy compliance. However, DNSSEC is not enabled, representing a minor security gap. No critical vulnerabilities or exposed sensitive data were detected. The site lacks explicit security certifications and a vulnerability disclosure policy, which could enhance trust. Incident response is facilitated via an abuse reporting page. Overall, registry.pw demonstrates a solid security posture and business credibility with professional content and clear policies. Recommendations include enabling DNSSEC, adding security headers, improving accessibility and mobile optimization, and establishing a formal vulnerability disclosure process to further strengthen security and compliance.

20
80
2
70
65
35
100
domainregistryprofessionalwebtldregistrarscookieconsent+2 more
WordPress 5.8.12jQueryCufon font replacementGoogle Analytics+4
2025-10-07T16:23:51.751Z
platform.sh favicon

Upsun

platform.sh

72
TechnologyN/asmallMEDIUM

Upsun is a technology company specializing in providing a highly flexible Platform as a Service (PaaS) designed for developers and organizations seeking customizable cloud application hosting. The platform emphasizes developer flexibility, self-service capabilities, and predictable pricing, supporting multiple frameworks and languages such as Django, Next.js, Drupal, and more. The company has a strong market position as a modern, developer-friendly cloud platform, with a focus on eliminating staging drift and accelerating release confidence. Founded in 2010, Upsun has evolved from its former identity as Platform.sh and maintains a consistent brand presence with a professional and well-structured website. Technically, the website is built using modern web technologies including Gatsby and React, optimized for performance, mobile responsiveness, and SEO. The platform integrates with major cloud providers like AWS, Azure, and Google Cloud Platform, indicating a mature and scalable infrastructure. The site employs extensive analytics and marketing tools with appropriate consent mechanisms, reflecting digital maturity and compliance awareness. From a security perspective, Upsun enforces HTTPS, implements a strict Content-Security-Policy, and maintains domain transfer protections. However, DNSSEC is not enabled, and there is no public security.txt or explicit incident response contact, which are areas for improvement. No vulnerabilities or exposed sensitive data were detected in the analysis. Overall, Upsun presents a trustworthy and professional online presence with strong business credibility and technical implementation. Strategic recommendations include enabling DNSSEC, publishing a security.txt file, and enhancing incident response transparency to further strengthen security posture and compliance.

60
68
25
82
72
80
100
paasclouddeveloperplatformhosting+1 more
Gatsby 5.11.0ReactJavaScriptCSS+1

Partner Domains:

agencypartner.platform.sh
partner
2025-10-07T16:23:27.269Z
keap.app favicon

Thryv, Inc.

keap.app

66
TechnologyN/aenterpriseMEDIUM

Keap, operated by Thryv, Inc., is a well-established SaaS provider specializing in CRM and marketing automation solutions tailored for small businesses. The login portal analyzed is professionally designed, offering secure authentication options including Google and Okta single sign-on integrations. The platform targets small business users seeking to scale their operations through automated marketing and customer management tools. The website demonstrates consistent branding and a clear business focus, reinforcing its market position as a trusted technology provider in this niche. From a technical perspective, the site employs a modern technology stack including jQuery, Bootstrap, and Lodash, ensuring responsive design and usability across devices. The presence of secure form validation and HTTPS encryption indicates a mature digital infrastructure. However, some areas such as accessibility and SEO could be enhanced to improve overall user experience and discoverability. Security posture is strong with enforced HTTPS, secure cookie settings, and integration of trusted third-party authentication providers. The absence of explicit security headers and cookie consent mechanisms suggests room for improvement in compliance and defense-in-depth strategies. No vulnerabilities or suspicious activities were detected in the analyzed content, supporting a high trust level. Overall, the website presents a low-risk profile with robust business credibility and technical implementation. Strategic recommendations include implementing comprehensive security headers, adding cookie consent for GDPR compliance, and enhancing accessibility features to further strengthen security and user trust.

55
58
2
70
75
85
100
loginkeapcrmmarketingautomationsmallbusiness+2 more
jQuery 3.7.1Bootstrap 3.2.0Font Awesome 4.3.0Lodash 4.17.21+1

Partner Domains:

try.keap.com
partner
keap.com
parent

+2 more partners

2025-10-07T16:23:07.146Z
A

Adobe

bizible.com

50
TechnologyN/aenterpriseMEDIUM

Adobe's Marketo Measure is a sophisticated B2B multi-touch marketing attribution tool designed to empower marketers with precise insights into campaign, channel, and content performance impacting pipeline, revenue, and ROI. Positioned as a market leader, it leverages AI-powered attribution models and comprehensive data aggregation across online and offline channels to optimize marketing investments effectively. The platform integrates seamlessly within Adobe's Experience Cloud ecosystem, targeting enterprise-level marketing teams seeking advanced attribution capabilities. Technically, the website is built on Adobe Experience Manager CMS, utilizing modern web technologies including HTML5, CSS3, and JavaScript, with Adobe-specific marketing scripts and Typekit fonts enhancing the user experience. The site demonstrates good mobile optimization and SEO practices, though some accessibility features appear basic. Performance is moderate, with room for improvement in loading speed and security header implementation. From a security perspective, the site uses HTTPS but lacks visible security headers and explicit privacy or cookie policies on the analyzed page, which may impact compliance and user trust. No forms or direct contact information are present, limiting data collection risks but also reducing transparency. The absence of WHOIS data for the subdomain is expected and does not detract from the domain's legitimacy, given Adobe's established corporate presence. Overall, the website presents a professional, trustworthy, and content-rich platform aligned with Adobe's brand. Strategic improvements in privacy disclosures, security headers, and contact transparency would enhance compliance and security posture, further solidifying user trust and regulatory adherence.

-
50
17
65
-
85
100
HTML5CSS3JavaScriptTypekit fonts+2
2025-10-07T16:17:36.013Z
css-tricks.com favicon

CSS-Tricks

css-tricks.com

68
TechnologyN/amediumMEDIUM

CSS-Tricks is a well-established online platform dedicated to web development education, focusing primarily on CSS and front-end technologies. Founded in 2007, it serves a global audience of web developers, designers, and technologists by providing high-quality articles, guides, and tutorials. The site maintains a strong market position as a reputable resource in the web development community, supported by consistent content updates and a professional digital presence. The business model revolves around content publishing, advertising partnerships, and newsletter subscriptions, with DigitalOcean as a notable sponsor and hosting partner. Technically, the website is built on WordPress, leveraging modern web technologies including PHP, JavaScript, and CSS. It employs Cloudflare for DNS and CDN services, ensuring fast performance and robust availability. The site demonstrates excellent mobile optimization, accessibility, and SEO practices, contributing to a superior user experience. Hosting on DigitalOcean via Cloudways further supports its performance and scalability needs. From a security perspective, CSS-Tricks enforces HTTPS with strong security headers, protecting user data and enhancing trust. While DNSSEC is not enabled, the domain registration is secured with registrar locks preventing unauthorized transfers or deletions. No critical vulnerabilities or exposed sensitive data were detected. Privacy and cookie policies are comprehensive and GDPR compliant, with active consent mechanisms. However, explicit security policies or incident response information are not publicly available, representing an area for potential improvement. Overall, CSS-Tricks presents a low-risk profile with a high degree of professionalism and trustworthiness. Strategic recommendations include enabling DNSSEC, publishing a formal security policy and incident response plan, and considering a vulnerability disclosure program to further enhance security posture and stakeholder confidence.

70
50
25
60
75
75
100
csswebdevelopmentfrontendeducationtechnology
WordPressPHPJavaScriptCSS+1
2025-10-07T16:16:40.724Z
fdroidstatus.org favicon

The F-Droid Team

fdroidstatus.org

63
TechnologyN/asmallMEDIUM

F-Droid Monitor is a specialized web service operated by The F-Droid Team that provides real-time monitoring and status updates for the F-Droid app repository build processes. The website targets developers and users interested in the health and status of F-Droid builds, offering detailed insights into build server cycles, app build statuses, and website build statuses. The service operates within the open source software ecosystem, focusing on transparency and community trust. Technically, the website employs a simple and clean design using Bootstrap CSS for layout and styling. The infrastructure appears modest, hosted likely via NameCheap as indicated by WHOIS data. The site is accessible without any WAF or blocking mechanisms, but lacks advanced security headers and DNSSEC, which are recommended for improved security posture. Mobile optimization and accessibility are basic but functional. From a security perspective, the site does not expose sensitive data or use vulnerable libraries, but it lacks formal privacy, cookie, and security policies, which limits compliance with GDPR and other regulations. No contact or incident response information is provided, which could hinder transparency and trust. The domain registration is consistent and appropriate for the service, with no privacy protection enabled, enhancing legitimacy. Overall, the website is functional and serves its niche purpose well but would benefit from enhanced security practices, formal privacy and cookie policies, and improved contact transparency to increase trust and compliance.

95
50
2
60
52
75
100
f-droidbuildstatusopensourcemonitoringsoftwarebuilds
HTML5Bootstrap CSS
2025-10-07T16:16:20.642Z
floss.social favicon

FLOSS.social

floss.social

71
TechnologyN/asmallMEDIUM

FLOSS.social is an independent Mastodon server launched in 2018, dedicated to the Free, Libre, and Open Source Software (FLOSS) community. It provides a decentralized social media platform encouraging open discussion primarily in English, with a strong emphasis on community guidelines and inclusivity. The platform is supported financially through a supporter program using Liberapay and is hosted on infrastructure provided by Masto.Host and OVH, with additional services from BunnyCDN and SparkPost. The website is well-structured, with clear policies and contact information, reflecting a mature community-focused service. Technically, FLOSS.social leverages Mastodon and a customized TangerineUI frontend, employing modern JavaScript modules and CDN resources. Hosting and infrastructure choices indicate a reliable and scalable setup. The website demonstrates good mobile optimization, accessibility, and SEO practices, although some improvements in security headers and cookie consent mechanisms are recommended. From a security perspective, the site enforces HTTPS and maintains a comprehensive community code of conduct with clear enforcement and incident reporting channels. However, explicit security headers and a formal vulnerability disclosure policy are absent, representing areas for enhancement. The WHOIS data is privacy-protected but consistent with the site's legitimate community focus. Overall, FLOSS.social presents a trustworthy, community-driven social media platform with solid technical foundations and a positive security posture. Strategic improvements in security policy transparency and cookie consent would further strengthen its compliance and user trust.

75
58
17
70
75
90
100
mastodonflossopensourcesocialmediacommunity+1 more
MastodonTangerineUIRuby on Rails (implied by Mastodon)JavaScript ES Modules+2

Partner Domains:

masto.host
partner
ovh.com
partner

+3 more partners

2025-10-07T16:16:15.624Z
raceforward.org favicon

Race Forward

raceforward.org

66
Non-profitN/amediumMEDIUM

Race Forward is a non-profit organization dedicated to advancing racial justice through policies, institutions, and culture. The organization provides training, resources, and advocacy to communities and public institutions, with a strong focus on government partnerships such as the Government Alliance on Race and Equity (GARE) and the Federal Initiative to Govern for Racial Equity (FIRE). Their market position is that of a recognized leader in racial equity advocacy with a medium-sized organizational footprint. The website is built on Drupal 10, leveraging modern web technologies and Google Tag Manager for analytics, indicating a mature digital infrastructure. The site is well-designed, mobile-optimized, and accessible, providing a professional user experience with clear navigation and relevant content. Security posture is good with HTTPS enabled and secure forms, though the absence of security headers and explicit cookie consent mechanisms are areas for improvement. WHOIS data is unavailable due to privacy protection, which is typical for non-profits, and the website content and external partnerships support the legitimacy of the domain. Overall, the site demonstrates a strong commitment to its mission with professional digital presence but could enhance privacy compliance and security best practices.

40
58
17
85
65
85
100
racialjusticenon-profittrainingadvocacygovernment+2 more
Drupal 10Google Tag ManagerGoogle AnalyticsTypekit Fonts

Partner Domains:

colorlines.com
partner
racialequityalliance.org
partner

+1 more partners

2025-10-07T15:14:55.690Z
googleanalytics.com favicon

Google

googleanalytics.com

69
TechnologyN/aenterpriseMEDIUM

Google Marketing Platform's Analytics page provides comprehensive tools for businesses to understand customer behavior across devices and platforms. The website is professionally designed, well-structured, and integrates seamlessly with Google's broader advertising and cloud ecosystem. It targets businesses ranging from small enterprises to large corporations, offering advanced analytics and marketing solutions to improve ROI and customer engagement. The platform is positioned as a market leader in digital analytics, supported by Google's strong brand and infrastructure. Technically, the site leverages AngularJS, Google Tag Manager, and Google Fonts, hosted on Google's infrastructure ensuring fast performance and excellent mobile optimization. Security best practices are observed with HTTPS, cookie consent mechanisms, and no visible vulnerabilities. Privacy policies and terms of service are linked to Google's comprehensive and GDPR-compliant documents, enhancing trust and compliance. The security posture is strong with modern encryption and security headers, though continuous monitoring and updates to frameworks like AngularJS are recommended. No direct contact information or incident response details are provided on this page, which is typical for a product marketing site under a large corporation. Overall, the site is trustworthy, professional, and aligns with Google's brand standards.

45
68
2
83
75
90
100
analyticsgoogleanalyticsmarketingplatformcustomerinsightsdigitalmarketing+1 more
AngularJS 1.6.6Google Tag ManagerGoogle Fonts (Roboto, Google Sans, Product Sans)Google Analytics+1
2025-10-07T15:14:25.393Z
globalcyberalliance.org favicon

Global Cyber Alliance

globalcyberalliance.org

82
TechnologyN/amediumLOW

Global Cyber Alliance (GCA) is a well-established non-profit organization focused on eradicating cyber risk through collective action, community engagement, and the deployment of free cybersecurity tools and resources. The website reflects a mature organization with a clear mission, targeting a broad audience including small businesses, individuals, technologists, and mission-based organizations. GCA offers a variety of cybersecurity toolkits, actionable tools, and educational materials to improve internet security globally. Technically, the website is built on WordPress, leveraging modern technologies such as jQuery, Google Tag Manager, and Cloudflare for hosting and security. The site demonstrates excellent performance, mobile optimization, and accessibility features. The presence of a comprehensive cookie consent mechanism indicates good privacy awareness, although explicit privacy and terms of service documents are not found in the provided content. From a security perspective, the site uses HTTPS with strong SSL configuration and Cloudflare protections. Security headers are likely managed by Cloudflare, and no vulnerabilities or exposed sensitive data were detected. However, enabling DNSSEC and publishing explicit security policies and incident response contacts would enhance trust and security posture. Overall, the website is professional, trustworthy, and safe for general audiences. It effectively communicates GCA's mission and services, though improvements in privacy documentation and contact transparency are recommended.

55
83
82
100
65
85
100
cybersecuritynon-profitcyberriskinternetsecuritycommunity+4 more
WordPressjQueryGoogle Tag ManagerYouTube embedded videos+4
2025-10-07T15:13:01.643Z
freshworks.com favicon

Freshworks Inc.

freshworks.com

78
TechnologyN/aenterpriseLOW

Freshworks Inc. is a leading enterprise SaaS provider specializing in customer service and IT service management software. Their platform leverages AI to deliver personalized, efficient support solutions for businesses globally. Positioned as a technology enterprise, Freshworks targets customer service and IT teams seeking scalable, uncomplicated software solutions. The company emphasizes AI-driven automation and insights to enhance service operations and customer satisfaction. Technically, Freshworks employs a modern web infrastructure utilizing React, Next.js, and Material UI frameworks, supported by advanced analytics and consent management tools such as Google Tag Manager and OneTrust. The website demonstrates excellent performance, mobile optimization, and accessibility, reflecting a mature digital presence. From a security standpoint, Freshworks maintains a strong posture with HTTPS enforcement, comprehensive security headers, and recognized certifications including ISO 27001 and SOC 2. Their privacy and cookie policies are comprehensive and GDPR compliant, supported by clear incident response contacts. No significant vulnerabilities or suspicious elements were detected. Overall, Freshworks presents a low-risk profile with robust business credibility and technical sophistication. The absence of WHOIS data is noted but does not undermine the legitimacy given the professional website and security practices. Strategic recommendations include implementing a security.txt file and enhancing transparency on data retention to further strengthen trust.

65
100
17
95
77
85
100
customerserviceitservicemanagementsaasaienterprisesoftware+2 more
ReactNext.jsMaterial UIWistia video player+3

Partner Domains:

shopify.com
partner
stripe.com
partner
2025-10-07T15:12:41.513Z
earthspecies.org favicon

Earth Species Project

earthspecies.org

58
OtherN/asmallMEDIUM

Earth Species Project is a nonprofit organization pioneering the use of advanced AI and large language models to decode animal communication and understand diverse intelligences on Earth. Their innovative approach positions them as leaders in the emerging field of bioacoustics and interspecies communication research. The organization collaborates with leading biologists and researchers globally, leveraging AI to unlock new insights into animal languages and support conservation efforts. Technically, the website is built on the Webflow platform, utilizing modern web technologies including Google Analytics, Google Tag Manager, Crazy Egg, and Givebutter for fundraising. The site is well-optimized for performance, mobile responsiveness, and accessibility, reflecting a mature digital infrastructure suitable for their audience and mission. From a security perspective, the site enforces HTTPS and follows several best practices, though it lacks explicit security headers and a cookie consent mechanism, which are recommended for enhanced compliance and protection. The absence of WHOIS data due to privacy protection is common for nonprofits and does not detract from the site's legitimacy, which is supported by strong trust signals such as nonprofit status, reputable media coverage, and clear contact information. Overall, Earth Species Project presents a professional, trustworthy, and technically sound online presence aligned with its mission. Strategic improvements in privacy compliance and security policies would further strengthen their posture and user trust.

30
53
2
70
52
75
100
aibioacousticsanimalcommunicationnonprofitresearch+3 more
WebflowGoogle AnalyticsGoogle Tag ManagerCrazy Egg+4
2025-10-07T15:12:16.462Z
S

STOP ShotSpotter

stopshotspotter.com

58
Non-profitN/asmallMEDIUM

STOP ShotSpotter is a coalition of local and national organizations advocating against the use of ShotSpotter surveillance technology, which they argue disproportionately harms Black, brown, and poor communities. The website serves as an advocacy platform to raise awareness, mobilize community action, and demand the cancellation of ShotSpotter contracts in favor of social services. Their market position is that of a small non-profit advocacy group focused on social justice and surveillance reform. Technically, the website is built with standard HTML5, CSS3, and JavaScript, including the use of the Rellax.js library for parallax effects. Hosting and DNS are managed via Amazon Registrar, indicating reliable infrastructure. The site is moderately optimized for performance and mobile use but lacks advanced accessibility and SEO features. No CMS or major frameworks were detected. From a security perspective, the site lacks key security headers and DNSSEC is not enabled, which are areas for improvement. There is no privacy or cookie policy, nor any incident response or security contact information published, which impacts compliance and trust. However, no critical vulnerabilities or exposed sensitive data were found. The site does not use analytics or tracking scripts, reflecting a privacy-conscious approach. Overall, the website is a functional and professional advocacy platform with moderate technical maturity and some security and compliance gaps. Strategic improvements in security headers, privacy policies, and incident response transparency would enhance trust and compliance.

15
53
17
60
72
75
100
advocacysurveillancesocialjusticegunviolencecommunity+2 more
HTML5CSS3JavaScriptRellax.js (parallax scrolling)
2025-10-07T15:12:10.982Z
G

g2.com

g2.com

58
OtherN/aMEDIUM

The website www.g2.com is currently inaccessible due to a security challenge page implemented via captcha-delivery.com scripts and iframe interstitials, indicating the presence of a Web Application Firewall (WAF) or bot mitigation system. This prevents access to any meaningful content, metadata, or business information, severely limiting the ability to perform a comprehensive analysis. The WHOIS query for the domain returned no match, providing no registrar, creation, or expiry data, which further complicates trust and legitimacy assessments. Due to these access restrictions, no contact information, privacy policies, or business details could be extracted or verified. From a technical perspective, the site employs third-party captcha services to mitigate automated access, which is a positive security measure but also restricts content visibility. No information about the technology stack, hosting provider, or CMS could be determined. Security headers and SSL configuration details are unavailable due to the blocked content. Given the lack of accessible content and WHOIS data, the overall risk assessment is elevated due to transparency concerns. However, no direct evidence of malicious activity or vulnerabilities was found. Strategic recommendations focus on enabling controlled access for security and compliance audits, improving WHOIS transparency, and ensuring publicly accessible privacy and security policies to enhance trust.

40
50
2
87
75
85
100
captcha-delivery.com script
2025-10-07T15:11:09.718Z
maze.co favicon

Maze

maze.co

79
TechnologyN/amediumLOW

Maze is a technology company providing a SaaS user research platform designed for modern product teams. The platform enables teams to conduct user interviews, usability tests, and surveys efficiently, leveraging AI to accelerate insights and decision-making. With over 60,000 teams using Maze, it holds a strong market position in the user research domain, supported by notable customers such as Atlassian and Volvo. The website reflects a professional and consistent brand image with excellent content quality and user experience. Technically, Maze employs modern web technologies including Gatsby and React, supported by analytics and marketing tools like Segment, Amplitude, and Facebook Pixel. The site is well-optimized for performance, mobile responsiveness, and SEO, indicating a mature digital infrastructure. The use of a comprehensive cookie consent mechanism demonstrates attention to privacy compliance. From a security perspective, the site enforces HTTPS, employs standard security headers, and avoids exposing sensitive data. However, it lacks a dedicated security policy page and explicit incident response contacts, which are recommended for enhanced transparency and trust. No vulnerabilities or suspicious patterns were detected in the WHOIS data or site content. Overall, Maze presents a low-risk profile with strong business credibility and technical maturity. Strategic recommendations include publishing detailed security and incident response policies, and establishing a vulnerability disclosure program to further strengthen security posture and stakeholder confidence.

80
80
17
100
77
90
100
userresearchusabilitytestingaimoderatorproductteamsuxresearch+3 more
Gatsby 5.14.5ReactSegment analyticsGoogle Tag Manager+3
2025-10-07T15:10:49.314Z
onesignal.com favicon

OneSignal

onesignal.com

70
TechnologyN/alargeMEDIUM

OneSignal is a leading customer engagement platform specializing in unified messaging services including mobile push notifications, web push, email, SMS, in-app messaging, and emerging channels like RCS and Live Activities. Established in 2011, the company serves millions of businesses worldwide and is recognized as a market leader in marketing automation software. Their platform enables businesses to orchestrate multi-channel messaging for enhanced customer engagement and retention. Technically, OneSignal's website demonstrates a mature digital infrastructure leveraging modern JavaScript frameworks, third-party marketing and analytics tools such as Google Tag Manager, Bizible, and Visual Website Optimizer, and is hosted with Cloudflare DNS services. The site is well-optimized for mobile devices and accessibility, with fast loading animations and structured navigation. However, explicit privacy and cookie policies are not readily found, which is a gap in compliance and transparency. From a security perspective, the domain is well-protected with multiple EPP status flags preventing unauthorized transfers or deletions, and HTTPS is enforced. The absence of DNSSEC is a minor security gap. No explicit security policies or incident response contacts are published, and security headers are not detected in the provided data, indicating room for improvement in hardening the web presence. Overall, OneSignal presents a professional and trustworthy business front with strong market credibility and technical maturity. The main risks relate to privacy compliance and explicit security disclosures. Addressing these gaps would enhance trust and regulatory adherence.

40
70
17
82
75
90
100
pushnotificationscustomerengagementmarketingautomationmobilepushwebpush+3 more
JavaScriptLottie animationsGoogle Tag ManagerBizible+2
2025-10-07T15:10:15.485Z
osano.com favicon

Osano

osano.com

80
TechnologyN/amediumLOW

Osano is a technology company specializing in data privacy compliance solutions, offering a comprehensive SaaS platform that simplifies global privacy regulations such as GDPR and CPRA. The company positions itself as a trusted leader in privacy management, providing key services including cookie consent management, subject rights automation, privacy assessments, and vendor risk management. Their platform is supported by a strong brand presence and a notable 'No Fines, No Penalties' guarantee, reflecting confidence in their compliance capabilities. Technically, Osano's website is built on the HubSpot CMS platform, utilizing modern JavaScript libraries like Swiper.js and integrating their own consent management scripts. The site demonstrates good performance, mobile optimization, and accessibility features. Security best practices are evident through the implementation of HTTPS, robust security headers, and a strict content security policy, contributing to a strong security posture. While the WHOIS data for the domain www.osano.com is not publicly available, possibly due to privacy protection or registry restrictions, the website's professional content, clear business information, and trust indicators support the legitimacy of the company. No critical security vulnerabilities or compliance gaps were detected in the analysis. However, the absence of explicit security policy and incident response information suggests areas for improvement. Overall, Osano presents a mature, secure, and privacy-focused digital presence suitable for organizations seeking reliable privacy compliance solutions.

55
95
47
95
75
85
100
privacycompliancegdprccpacookieconsent+2 more
HubSpot CMSSwiper.jsGoogle Tag ManagerOsano Consent Management Platform
2025-10-07T15:10:10.456Z