Skip to main content

United Kingdom security reports

Browse 6,589 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

155884
Websites
130
Industries
113
Countries
52
Avg Score
Page 131 of 132|Showing 6501-6550 of 6589
katapult.io favicon

Krystal Hosting Ltd

katapult.io

63
TechnologyUnited KingdommediumMEDIUM

Katapult, operated by Krystal Hosting Ltd, is a cloud infrastructure provider focused on delivering high-speed, reliable, and scalable virtual infrastructure solutions tailored for developers and teams. The company emphasizes ease of use, transparency, and sustainability, positioning itself as a competitive player in the cloud technology sector with a strong commitment to renewable energy and certified business practices. The website presents a professional and comprehensive overview of its services, targeting technology professionals and businesses seeking cloud infrastructure with pay-as-you-go pricing. Technically, the website is built on modern frameworks such as Next.js and React, with good mobile optimization and accessibility features. However, the site suffers from a critical security shortfall due to the absence of a valid SSL certificate, resulting in no HTTPS support. This significantly impacts the security posture and user trust. Privacy and cookie policies are well implemented with consent mechanisms, and the site uses Google Tag Manager for analytics and marketing. Security-wise, while no major vulnerabilities or exposed sensitive data were detected, the lack of HTTPS and security headers is a major concern. No explicit security or incident response policies are published, and no vulnerability disclosure or security.txt files are present. The domain registration data is consistent and mature, supporting the legitimacy of the business. Overall, Katapult demonstrates strong business credibility and technical maturity but must urgently address its SSL/TLS configuration to improve security and trust. Strategic recommendations include installing a valid SSL certificate, enabling security headers, and publishing security policies to enhance compliance and incident readiness.

90
25
25
50
100
85
100
cloudvirtualmachinesinfrastructuredeveloperspubliccloud+2 more
Next.jsReactGoogle Tag ManagerSVG icons+1
2025-06-15T11:49:43.430Z
bristol.ac.uk favicon

University of Bristol

bristol.ac.uk

39
EducationUnited KingdomlargeHIGH

The University of Bristol operates a comprehensive and professional website serving prospective and current students, staff, alumni, and the wider community. The site provides detailed information on undergraduate and postgraduate courses, research activities, and community engagement, positioning the university as a leading educational institution in the UK and globally. The website content is well-structured, accessible, and rich in relevant information, reflecting a strong digital presence. Technically, the website employs modern JavaScript frameworks such as StencilJS and integrates tracking and analytics tools like Google Tag Manager and TrackedWeb. However, the site suffers from significant performance issues, including a slow load time and a large page size, which could impact user experience. Mobile optimization and accessibility are well addressed, contributing positively to overall usability. From a security perspective, the website exhibits critical weaknesses, notably the absence of a valid SSL certificate and HTTPS support, exposing users to potential data interception risks. Additionally, no security headers or advanced TLS protocols are enabled, and no incident response or vulnerability disclosure policies are publicly available. Privacy compliance is strong, with comprehensive privacy and cookie policies aligned with GDPR requirements. Overall, while the University of Bristol's website excels in content quality and business credibility, urgent improvements in security infrastructure and performance optimization are necessary to enhance trust and protect users. Strategic recommendations include implementing HTTPS, enabling security headers, optimizing performance, and publishing clear security policies.

15
15
5
50
-
85
100
educationuniversityresearchcoursesstudents+1 more
JavaScriptGoogle Tag ManagerTrackedWebTermly+1
2025-06-15T08:35:24.132Z
flexport.org favicon

Flexport Inc

flexport.org

40
TransportationUnited KingdomlargeHIGH

Flexport.org is a non-profit initiative under Flexport Inc that leverages logistics to facilitate global aid delivery and promote sustainability. The organization supports humanitarian relief efforts, discounted shipping for NGOs, and climate programs to reduce transport emissions. Their market position is strong within the humanitarian logistics sector, supported by partnerships with reputable NGOs and a clear mission to improve aid delivery efficiency. Technically, the website is built on modern frameworks like React and Gatsby, hosted on Amazon AWS, and employs advanced technologies such as Google reCAPTCHA and Mapbox GL JS. The site demonstrates good performance, mobile optimization, and accessibility, reflecting a mature digital infrastructure. Security posture is solid with HTTPS enforced using TLS 1.3 and strong cipher suites, absence of known vulnerabilities, and security headers that protect domain registration. However, improvements such as enabling HSTS, OCSP stapling, and DMARC records could enhance security further. Overall, the website is trustworthy, professional, and compliant with privacy regulations including GDPR. No blocking or WAF interference was detected, allowing full content access and analysis. Strategic recommendations include enhancing security headers and transparency measures to maintain and improve trust.

65
43
25
40
87
75
100
non-profitlogisticshumanitariansustainabilityaid+2 more
ReactGatsbyGoogle reCAPTCHAKetch (consent management)+1

Partner Domains:

flexport.com
parent68
2025-06-15T06:13:32.317Z
17capital.com favicon

17Capital

17capital.com

54
FinanceUnited KingdommediumMEDIUM

17Capital is a specialized private credit manager focused on providing NAV finance solutions to private equity investors and management companies globally. Founded in 2008 and headquartered primarily in the UK and US, the firm has established itself as a leading player in the private equity finance sector, offering a range of financing products tailored to portfolio growth and liquidity needs. The website reflects a professional and content-rich digital presence, leveraging WordPress and WP Engine hosting, with strong SEO and structured data implementations to enhance discoverability and user engagement. However, the technical infrastructure shows gaps in SSL certificate validity and HTTPS enforcement, which undermines security posture despite well-configured security headers. The site integrates multiple marketing and analytics tools, including Google Analytics and HubSpot, but lacks a cookie consent mechanism, indicating partial privacy compliance. Contact mechanisms rely on forms and partner emails, with no direct phone or physical address details prominently displayed. Overall, the website demonstrates high business credibility and professionalism but requires urgent remediation of SSL issues and enhanced privacy compliance to improve security and user trust.

80
25
25
50
50
85
100
privateequitynavfinancefinanceinvestmentprivatecredit+3 more
jQueryVimeo PlayerYoast SEOHubSpot Forms+4

Partner Domains:

prosek.com
partnerpending
h-advisors.global
partnerpending
2025-06-14T22:40:16.587Z
codecourse.com favicon

Codecourse Ltd.

codecourse.com

52
EducationUnited KingdomsmallMEDIUM

Codecourse Ltd. is a UK-based educational platform specializing in practical developer screencasts focused on Laravel, Livewire, Inertia, and Vue.js technologies. The company targets web developers seeking hands-on learning through real-world projects and tutorials. Their business model revolves around subscription-based and individual course sales, offering a rich library of content with a strong emphasis on modern PHP and JavaScript frameworks. The platform is well-branded, with consistent messaging and positive user testimonials, positioning it as a niche leader in Laravel education. Technically, the website leverages a modern tech stack including Laravel, Livewire, Inertia.js, Vue.js, and Alpine.js, hosted behind Cloudflare. However, performance is suboptimal with slow load times and a high number of resources. Mobile optimization and SEO are good, but accessibility is basic. The site lacks a valid SSL certificate and HTTPS support, which is a critical security deficiency. No security headers or advanced security mechanisms are detected, and cookie consent mechanisms are absent, indicating partial privacy compliance. From a security perspective, the absence of HTTPS and TLS protocols severely impacts the site's security posture, exposing users to potential risks. No incident response or security policies are publicly available, and no direct contact emails for security or abuse are found. While the platform uses minimal user tracking via Fathom Analytics, privacy compliance is basic and could be improved. Overall, the site demonstrates a moderate level of digital maturity but requires urgent security enhancements. Strategically, Codecourse should prioritize implementing HTTPS with a valid SSL certificate, enable modern security headers, and introduce cookie consent to align with GDPR requirements. Enhancing performance and accessibility will improve user experience and SEO. Establishing clear security policies and incident response contacts will bolster trust and compliance. These steps will strengthen Codecourse's market position and protect its user base effectively.

40
25
25
50
85
65
100
laravellivewireinertiavuejseducation+2 more
LaravelLivewireInertia.jsVue.js+4
2025-06-14T21:52:17.169Z
thoughtmachine.net favicon

Thought Machine Group Limited

thoughtmachine.net

54
FinanceUnited KingdomlargeMEDIUM

Thought Machine Group Limited is a leading provider of cloud-native core banking and payments platforms, offering innovative solutions such as Vault Core and Vault Payments. Their technology empowers banks and fintechs worldwide to build flexible, scalable financial products and payment schemes. Recognized as a leader in the 2025 Gartner Magic Quadrant for Retail Core Banking Systems, Thought Machine serves a global clientele including major financial institutions and investors. The website reflects a mature digital presence with comprehensive content, multi-language support, and strong branding. Technically, the site leverages modern web technologies including Webflow CMS, JavaScript libraries, and integrates marketing and analytics tools such as HubSpot, Google Analytics, and LinkedIn Insight. However, the site suffers from a lack of a valid SSL certificate and absence of key security headers, which significantly impacts its security posture. Performance is suboptimal with slow load times and a large number of resources. Security-wise, while no critical vulnerabilities or malware indicators were found, the missing HTTPS and security headers represent a major risk that should be addressed promptly. Privacy compliance is well-handled with a clear privacy policy and cookie consent mechanism via Cookiebot. Contact information is detailed with multiple global office addresses and a contact form, but no direct company emails or phone numbers were found. Overall, Thought Machine's website is professional and content-rich, supporting its position as a trusted technology provider in the finance sector. Addressing the SSL and security header issues would greatly enhance trust and security for visitors and clients.

45
43
25
50
50
85
100
corebankingcloudnativefinancepaymentsbankingtechnology+2 more
JavaScriptjQueryWebflowGoogle Tag Manager+9

Partner Domains:

avature.net
partner98
2025-06-14T21:41:56.489Z
sentium-consulting.com favicon

Agentycs Limited

sentium-consulting.com

60
TechnologyUnited KingdomsmallMEDIUM

Agentycs Limited operates a sophisticated Agentic AI platform designed to empower enterprises with custom AI applications tailored to their unique data, processes, and goals. The company positions itself as a leading UK-based provider of AI solutions emphasizing flexibility, security, and scalability. Their platform supports deployment across cloud, hybrid, and on-premises environments, with a strong focus on zero-trust architecture and data governance. Technically, the website is built using modern frameworks such as Astro and integrates third-party services like Vimeo for video content and PostHog for analytics. The hosting and DNS are managed via Cloudflare, providing performance and security benefits. However, a critical security gap exists as the site lacks a valid SSL certificate and does not serve content over HTTPS, exposing users to potential risks. Security posture is bolstered by claims of ISO 27001 certification, enterprise-grade penetration testing, and strict data privacy practices including no retraining on customer data and full data ownership. Despite these strengths, the absence of HTTPS and modern TLS protocols significantly undermines the overall security stance. Overall, while the business demonstrates strong domain expertise and a professional digital presence, the lack of HTTPS is a critical vulnerability that must be addressed immediately to protect user data and maintain trust. Strategic recommendations include implementing SSL/TLS, enhancing security headers, and publishing formal vulnerability disclosure policies.

30
25
25
75
100
80
100
aiagenticaidataanalyticsenterprisesecuritycloud+4 more
Astro frameworkVimeo PlayerCloudflarePostHog analytics+2
2025-06-14T21:28:47.881Z
cuprinol.co.uk favicon

Cuprinol

cuprinol.co.uk

46
RetailUnited KingdomlargeHIGH

Cuprinol.co.uk is a retail website specializing in wood treatment and exterior wood protection products, including their flagship Cuprinol Ducksback range. The site targets homeowners and gardening enthusiasts in the United Kingdom, offering a variety of garden shades and protective products. The business operates under the parent company AkzoNobel, a recognized entity in the coatings and chemicals industry. The website presents a professional and consistent brand image with good content quality and clear navigation, catering well to its target audience. Technically, the website is built using modern web technologies such as React and Next.js, with integrations for marketing and analytics tools like Google Tag Manager and Marketo. However, the site suffers from slow load times and lacks a valid SSL certificate, which impacts both user experience and security posture. Mobile optimization is good, but accessibility features are basic. From a security perspective, the absence of HTTPS and security headers is a critical vulnerability, exposing users to potential risks. No explicit security policies or incident response information is available, which may affect trust and compliance. Privacy and cookie policies are present and include consent mechanisms, indicating reasonable privacy compliance. Overall, the website is functional and professionally presented but requires urgent improvements in security infrastructure, particularly SSL implementation and security headers, to enhance trustworthiness and compliance.

15
25
25
50
50
75
100
woodtreatmentgardenprotectionexteriorwoodcuprinolgardenshades
ReactNext.jsGoogle Tag ManagerMarketo+1

Partner Domains:

akzonobel.com
parent72
2025-06-14T19:59:32.144Z
bigbustours.com favicon

Big Bus Tours Ltd

bigbustours.com

54
TransportationUnited KingdomlargeMEDIUM

Big Bus Tours Ltd operates as a leading global sightseeing bus tour provider, specializing in hop-on hop-off tours across major cities such as London, New York, and Paris. The company holds a strong market position as the largest operator of open-top sightseeing bus tours with over 30 years of service. Their business model focuses on tourism and travel services, offering additional experiences beyond bus tours to enhance customer engagement. The website reflects a professional and consistent brand presence targeting tourists worldwide. Technically, the website is built on Magento 2, leveraging modern web technologies including RequireJS, Google Tag Manager, and various marketing and analytics tools such as MoEngage and New Relic. Hosting and DNS services are provided by Cloudflare, ensuring global content delivery. While the site is mobile-optimized and SEO-friendly, performance metrics are not explicitly available. Accessibility is basic but functional. From a security perspective, the site implements several important HTTP security headers and a comprehensive Content Security Policy. However, a critical vulnerability is the absence of a valid SSL certificate and lack of TLS protocol support, severely impacting the security posture. This exposes users to risks and undermines trust. Privacy compliance is addressed with clear privacy and cookie policies, including consent mechanisms, but no explicit security or incident response policies are found. Overall, the website is functional and business credible but requires urgent security improvements to protect user data and maintain trust. Strategic recommendations include obtaining a valid SSL certificate, enabling modern TLS protocols, enhancing HSTS policies, and improving incident response readiness.

85
40
17
50
50
85
100
tourismbustourshop-onhop-offsightseeingtravel+2 more
Magento 2RequireJSGoogle Tag ManagerMoEngage+5

Partner Domains:

paypal.com
partner69
adyen.com
partner68

+3 more partners

2025-06-14T19:50:35.379Z
planonsoftware.com favicon

Planon

planonsoftware.com

72
Real EstateUnited KingdomlargeMEDIUM

Planon is a leading global provider of Smart Sustainable Building Management software solutions, connecting buildings, people, and processes to optimize workspace management and building performance. With a strong market position recognized by industry analysts such as Verdantix, IDC, Gartner, and Frost & Sullivan, Planon offers a comprehensive suite of services including Integrated Workplace Management, Campus Management, Lease Accounting, and Field Services. Their platform supports IoT-enabled solutions and is designed to meet the evolving needs of real estate and facilities management professionals worldwide. Technically, Planon's website leverages modern web technologies including jQuery, Bootstrap, Swiper, and Choices.js, integrated with advanced analytics and A/B testing tools like Google Analytics and Visual Website Optimizer. The site is hosted on Yourhosting DNS infrastructure and employs secure TLS 1.2 encryption with strong cipher suites. Cookie consent is managed via Cookiebot, ensuring compliance with GDPR and other privacy regulations. From a security perspective, Planon demonstrates good practices with SPF and DMARC email policies, absence of known SSL vulnerabilities, and a strict DMARC reject policy. However, there are opportunities to enhance security by enabling HSTS, OCSP stapling, TLS 1.3 support, and DNSSEC. No explicit vulnerability disclosure or incident response contacts were found, indicating potential areas for improvement in transparency and security readiness. Overall, Planon maintains a high-quality, professional web presence with strong trust indicators and comprehensive compliance measures. Strategic enhancements in security configurations and public disclosure policies could further strengthen their security posture and stakeholder confidence.

90
40
25
80
92
85
100
smartbuildingmanagementsustainabilityrealestatemanagementfacilitiesmanagementiot+4 more
jQueryBootstrapSwiperChoices.js+7

Partner Domains:

gxcloud.net
partnerpending
ubigreen.com
subsidiarypending
2025-06-14T18:46:51.222Z
cyncly.com favicon

Cyncly

cyncly.com

55
ManufacturingUnited KingdomlargeMEDIUM

Cyncly is a large, England-based software company specializing in end-to-end design software solutions for the spaces-for-living industries such as kitchen, bathroom, furniture, flooring, windows & doors, and manufacturing. The company offers a comprehensive integrated platform that connects designers, retailers, and manufacturers to a vast product content repository, enabling streamlined design, sales, manufacturing, and installation processes. With a strong market presence supporting 70,000 customers globally, Cyncly positions itself as a leader in transforming industry workflows and accelerating business operations. Technically, the website leverages modern web technologies including Alpine.js, Tailwind CSS, and integrates multiple marketing and analytics tools such as Google Tag Manager, Microsoft Application Insights, Marketo, Optimizely, and Cookiebot. The site is hosted behind Cloudflare, providing DNS and CDN services. However, a critical security gap is the absence of a valid SSL certificate and lack of HTTPS support, which undermines secure communications and user trust. From a security perspective, the domain has well-configured SPF and DMARC records to protect email integrity, but lacks advanced DNS security features like DNSSEC and CAA. The website employs a robust cookie consent mechanism compliant with GDPR, but no explicit security or incident response policies are publicly available. The extensive use of third-party tracking and marketing tools indicates a high level of user data collection and tracking. Overall, while Cyncly demonstrates strong business and technical maturity with excellent content quality and user experience, the lack of HTTPS and valid SSL certificate represents a significant security risk. Strategic improvements in web security infrastructure and transparency around security policies are recommended to enhance trust and compliance.

15
43
25
70
50
80
85
end-to-endsolutionscustomizableproductdesignprofessionaldesignnetworkproductcontentrepositoryglobalsoftwareplatform
Alpine.jsTailwind CSSGoogle Tag ManagerMicrosoft Application Insights+13

Partner Domains:

compusoftgroup.com
partner61
mozaik-software.com
partneranalyzing...

+3 more partners

2025-06-14T18:41:26.648Z
compusoftgroup.com favicon

Compusoft Group

compusoftgroup.com

61
TechnologyUnited KingdomlargeMEDIUM

Compusoft Group is a leading provider of specialized software solutions for the kitchen, bathroom, furniture, window, and door industries. Their portfolio includes design, presentation, business management, and production software, targeting professionals who require efficient and accurate tools to streamline their workflows. The company operates globally with a strong presence in over 100 countries and serves a large customer base, positioning itself as a key player in the configurable product software market. As a subsidiary of Cyncly, Compusoft benefits from a broader corporate ecosystem enhancing its market reach and technological capabilities. Technically, the website is built on WordPress with a comprehensive set of modern web technologies and analytics tools, including Google Analytics, Cookiebot for consent management, and various marketing and tracking integrations. The site demonstrates good performance and mobile optimization, although the page load time is relatively slow, likely due to extensive resources and scripts. Security-wise, the site employs a valid SSL certificate with HSTS enabled, SPF and DMARC records are properly configured, indicating a strong email security posture. However, the absence of DNSSEC and CAA records suggests room for improvement in DNS security. No explicit security or incident response policies are publicly available, which could be a gap in transparency. Overall, the website reflects a mature digital presence with robust privacy and cookie management practices, extensive tracking for marketing and analytics, and a professional, consistent brand image. The risk profile is moderate, with recommendations to enhance DNS security and publish clear security policies to improve trust and compliance.

50
58
25
50
59
85
100
kitchendesignbathroomdesignfurnituresoftwarecpq3ddesign+6 more
WordPressjQueryGoogle Tag ManagerGoogle Analytics+10

Partner Domains:

cyncly.com
parentanalyzing...
2020spaces.com
partneranalyzing...

+3 more partners

2025-06-14T18:41:26.519Z
mpamag.com favicon

KM Business Information UK Ltd

mpamag.com

82
MediaUnited KingdommediumLOW

Mortgage Introducer, operated by KM Business Information UK Ltd, is a leading UK-based media platform specializing in mortgage industry news, insights, and expert advice. The website offers a broad range of content including news articles, premium subscription content, mortgage broker software reviews, and industry resources targeting mortgage brokers and financial professionals. It maintains a strong market position as a trusted source within the UK mortgage sector, supported by a consistent brand and a professional online presence. Technically, the site leverages a modern tech stack including Bootstrap, jQuery, Algolia search, HubSpot analytics, and Google Ad Manager for advertising. However, the site suffers from an invalid SSL certificate and lacks advanced security configurations such as DNSSEC and HSTS, which impacts its security posture. The security best practices include a strict DMARC policy and SPF records, but the absence of a valid SSL certificate and missing security headers reduce overall trust. The website employs extensive user tracking and marketing tools, including Facebook Pixel and Bombora, indicating a mature digital marketing strategy but raising privacy considerations. Overall, the site is professional and content-rich but requires urgent security improvements to protect user data and enhance trust.

-
-
25
85
100
85
100
mortgagebrokernewsfinanceuk+4 more
Bootstrap 4.3.1jQuery 3.3.1Underscore.js 1.9.1Google Tag Manager+11

Partner Domains:

keymedia.com
partner57
2025-06-14T17:36:56.078Z
zoonou.com favicon

Zoonou Limited

zoonou.com

66
TechnologyUnited KingdommediumMEDIUM

Zoonou Limited is a UK-based software testing and quality assurance company, uniquely positioned as the UK's only employee-owned software testing firm. Established in 2007, it has delivered over 5,000 projects and holds multiple certifications including B Corp, ISO 9001, ISO 27001, and Cyber Essentials Plus. The company offers a comprehensive suite of services spanning QA strategy, delivery, accessibility, cybersecurity, and test automation, targeting private, public, and third sector organizations. Their business model emphasizes employee ownership and social responsibility, aligning with their B Corp certification and commitment to inclusivity and accessibility. Technically, Zoonou employs modern web technologies including React, HubSpot marketing and analytics tools, and Umbraco CMS. The site is hosted via UK2.net and integrates multiple third-party services for marketing and analytics. While the SSL certificate is valid and strong, the site currently lacks support for modern TLS protocols, which is a notable security gap. Performance metrics indicate a slower load time, suggesting opportunities for optimization. From a security perspective, the company demonstrates good practices such as HSTS enforcement and absence of known SSL vulnerabilities. However, the lack of DNSSEC, CAA records, and a published vulnerability disclosure policy or security.txt file indicates areas for improvement. No explicit incident response or security contact information was found, which could impact responsiveness to security events. Overall, Zoonou presents a professional, trustworthy, and socially responsible brand with solid technical infrastructure but with room to enhance its security posture and performance. Strategic improvements in TLS support, DNS security, and transparency around vulnerability management would strengthen their risk profile and client confidence.

55
25
25
80
97
85
100
softwaretestingqualityassuranceqaservicesemployee-ownedbcorp+5 more
JavaScriptHubSpotGoogle Tag ManagerGoogle Analytics+7
2025-06-14T13:25:06.738Z