Skip to main content

United States security reports

Browse 10,774 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157370
Websites
130
Industries
113
Countries
52
Avg Score
Page 209 of 216|Showing 10401-10450 of 10774
earnnest.com favicon

Earnnest

earnnest.com

53
Real EstateUnited StatesmediumMEDIUM

Earnnest is a U.S.-based digital payment platform specializing in secure and convenient earnest money and real estate transaction payments. Positioned as the largest digital earnest money service in the country, Earnnest serves a broad audience including agents, brokerages, title and escrow companies, lenders, homebuilders, and MLS organizations. The platform offers multiple products such as the Earnnest App, Earnnest Pro, and escrow services, emphasizing convenience, security, and transparency in real estate payments. The company is trusted by major industry organizations and holds a SOC 2 Type 2 certification, reinforcing its commitment to security and compliance. Technically, the website is built on Webflow and leverages modern web technologies including Google Fonts, Google Analytics, Jetboost, and Cloudflare for hosting and CDN services. The site is mobile-optimized with excellent design quality and user experience. However, performance is currently slow, and accessibility is good but could be improved. SEO practices are good with proper meta tags and structured data. From a security perspective, the site lacks a valid SSL/TLS certificate and does not properly enable HTTPS, which is a critical vulnerability. While some security headers are present, the absence of TLS protocols and HSTS enforcement significantly weakens the security posture. No incident response or security policy information is publicly available. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism detected. Overall, Earnnest presents a professional and trustworthy business with strong market positioning and credible trust signals. The primary risk lies in the lack of proper SSL configuration, which should be addressed immediately to protect user data and maintain trust. Strategic improvements in security and privacy compliance will enhance the platform's reliability and user confidence.

35
43
25
50
50
85
100
realestatedigitalpaymentsearnestmoneysecurepaymentsescrow+1 more
WebflowGoogle Fonts (Ubuntu)Google Analytics (gtag.js)Jetboost+5

Partner Domains:

dotloop.com
partner74
kellerwilliams.com
partneranalyzing...

+2 more partners

2025-06-15T08:03:37.735Z
bayequityhomeloans.com favicon

Bay Equity LLC

bayequityhomeloans.com

40
FinanceUnited StatesmediumHIGH

Bay Equity LLC operates as a full-service home mortgage lender in the United States, licensed in 48 states and DC. The company offers a range of home loan products including first-time homebuyer loans, refinancing options, and specialty loans such as FHA, Jumbo, VA, and USDA loans. Their market position is supported by a broad network of local teams and a focus on personalized service through dedicated loan officers. The website is professionally designed with clear navigation and comprehensive content aimed at homebuyers and current homeowners. Technically, the website is built on a modern React and Gatsby framework, hosted on Netlify, indicating a contemporary and scalable infrastructure. While the site is mobile-optimized and includes accessibility features, performance metrics are not available for a complete assessment. The site employs cookie consent mechanisms and integrates third-party marketing and tracking tools responsibly. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability that undermines user trust and data protection. Security headers are partially implemented, but important features like HSTS are not fully enabled. No explicit security or incident response policies are found, and there is no vulnerability disclosure or security.txt file. Overall, the business appears legitimate and well-established, but the critical security issues related to SSL/TLS must be addressed immediately to ensure secure user interactions and compliance with best practices. Strategic recommendations include fixing the SSL configuration, enabling strong security headers, and enhancing transparency around security policies.

30
43
25
40
50
85
100
mortgagehomeloansrefinanceloanofficersfirst-timehomebuyer+2 more
ReactGatsbyNetlifyJavaScript+1

Partner Domains:

bkiconnect.com
partneranalyzing...
2025-06-15T07:55:07.212Z
lucid.app favicon

Lucid Software Inc.

lucid.app

56
TechnologyUnited StatesenterpriseMEDIUM

Lucid Software Inc. operates the lucid.app domain, providing a comprehensive visual collaboration suite including Lucidchart and Lucidspark. The company targets teams and enterprises seeking intelligent diagramming and virtual whiteboarding solutions, positioning itself as a leader in the technology sector for collaboration tools. Their business model is SaaS-based with multiple integrated products, serving a global audience with a strong presence in the United States. The website demonstrates excellent content quality, professional design, and consistent branding, supporting a high level of business credibility. Technically, the website is built on modern frameworks such as Angular and integrates various third-party services including Google APIs, Microsoft Teams SDK, and Osano for cookie compliance. Hosting is managed via Akamai CDN, ensuring global availability. However, performance metrics are not available, and accessibility is basic but functional. SEO practices are good with proper meta tags and structured data. Security posture reveals critical issues: the SSL certificate is invalid or missing, and no TLS protocols are enabled, which is a significant risk for user data protection and trust. Security headers are well configured, but the lack of valid HTTPS severely impacts the overall security score. Privacy compliance is good, with a clear privacy policy, cookie consent mechanism, and GDPR compliance indicators. Contact information is transparent and professional, though no explicit incident response or vulnerability disclosure information is found. Overall, while the business and technical maturity are strong, the critical SSL/TLS misconfiguration poses a major risk. Strategic remediation of SSL issues is essential to restore trust and secure communications. The company should also consider publishing explicit incident response and vulnerability disclosure policies to enhance security transparency.

80
25
25
50
50
85
100
visualcollaborationdiagrammingsaasteamcollaborationvirtualwhiteboard+1 more
Angular (ng-version=16.1.2)jQueryGoogle Tag ManagerOsano CMP+8
2025-06-15T07:54:59.510Z
sailpoint.com favicon

SailPoint Technologies, Inc.

sailpoint.com

71
TechnologyUnited StatesenterpriseMEDIUM

SailPoint Technologies, Inc. is a leading enterprise software company specializing in identity security solutions that help organizations manage and protect all types of enterprise identities. The company holds a strong market position with recognition from Gartner, KuppingerCole, and Frost & Sullivan, serving a global enterprise audience including many Fortune 500 companies. Their core offerings include Identity Security Cloud, IdentityIQ software, and advanced capabilities such as machine identity security and AI-driven automation through Harbor Pilot. The website reflects a mature digital presence with comprehensive content, multilingual support, and a professional design that targets security leaders and IT professionals. Technically, the website is built on modern frameworks such as Next.js and React, hosted on Vercel with Cloudflare CDN integration. It employs a variety of third-party marketing, analytics, and security tools including Google Analytics, Hotjar, Marketo, and Bugcrowd. While the site is mobile optimized and accessible, performance is moderate and could benefit from further optimization. The SSL configuration is currently invalid or missing, which is a critical security concern that impacts the overall security posture. From a security perspective, the site implements a robust Content Security Policy and several security headers but lacks full HSTS enforcement and OCSP stapling. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is well addressed with clear privacy and cookie policies and GDPR compliance indicators. Contact information is primarily provided via forms and external portals, with security-related contact emails identified. Overall, the website demonstrates a high level of professionalism and trustworthiness, supported by strong business credibility and industry recognition. However, the invalid SSL certificate is a significant risk that should be addressed promptly to maintain user trust and security integrity.

45
40
35
85
90
90
100
identitysecurityenterprisesecurityidentitygovernancecloudsecurityai-drivensecurity+2 more
ReactNext.jsVercel hostingCloudflare CDN+10
2025-06-15T07:17:28.725Z
pingidentity.com favicon

Ping Identity

pingidentity.com

60
TechnologyUnited StatesenterpriseMEDIUM

Ping Identity is a leading enterprise identity security company specializing in identity and access management solutions. Their platform offers comprehensive services including customer identity, workforce identity, B2B identity, decentralized identity, and advanced authentication methods such as passwordless and zero trust. The company targets large enterprises across various sectors including government, financial services, healthcare, retail, media, and telecommunications. With a strong market position supported by industry analyst recognitions, Ping Identity delivers secure and seamless digital experiences for its customers. Technically, the website is built on a modern infrastructure leveraging Adobe Experience Manager CMS, AWS hosting, and advanced web technologies such as Lottie animations and Google Tag Manager. The site demonstrates good mobile optimization, accessibility, and SEO practices. However, the SSL certificate is currently invalid, and no TLS protocols are enabled, which significantly impacts the security posture. Security-wise, the site implements strong security headers and cookie policies with consent mechanisms, indicating good privacy compliance. Certifications like ISO 27001, SOC 2, and FedRAMP further strengthen their security credibility. Nonetheless, the invalid SSL certificate and lack of TLS support are critical issues that must be addressed urgently to ensure secure communications. Overall, Ping Identity's website reflects a mature and professional digital presence with strong business credibility and privacy compliance. Addressing the SSL and TLS issues will elevate their security posture and trustworthiness further.

85
25
25
80
50
85
100
identitysecurityiamenterprisesecuritycustomeridentityworkforceidentity+3 more
Adobe Helix RUMGoogle Tag ManagerLottie animationsMarketo forms+5
2025-06-15T07:17:28.134Z
daveyandkrista.academy favicon

Attention Required! | Cloudflare

daveyandkrista.academy

40
EducationUnited StatessmallHIGH

D&K Academy operates as an online educational platform providing membership-based access to courses or training content. The website is built on the Kajabi platform and leverages common web technologies such as Bootstrap and Font Awesome. The target audience appears to be students or members seeking educational resources. The business is small-scale, US-based, and has been established since 2017. However, the website lacks publicly available privacy, cookie, or terms of service policies, and does not display contact information, which limits transparency and trust. Technically, the site uses modern frameworks and third-party services for analytics and marketing, including RudderStack and Facebook Pixel. Despite this, the website suffers from poor performance with a slow load time and a large number of resources. Mobile optimization and accessibility are basic but functional. Critically, the site does not have a valid SSL certificate or HTTPS enabled, exposing users to security risks. From a security perspective, the absence of HTTPS, security headers, and DNSSEC, combined with no visible incident response or security policies, indicates a low security maturity level. The domain is privacy protected but mature and registered with a reputable registrar, suggesting legitimacy. Overall, the website presents significant security and privacy compliance gaps that should be addressed to improve user trust and regulatory adherence. Strategic recommendations include obtaining a valid SSL certificate, implementing security headers and DNS security measures, publishing privacy and cookie policies, and providing clear contact information. Improving site performance and accessibility will also enhance user experience and SEO.

35
25
25
60
100
70
100
educationonlinelearningmembershiploginkajabi+3 more
Bootstrap 4.0.0-alpha.4Font Awesome 4.5.0Google Fonts (Open Sans)Kajabi platform+6
2025-06-15T07:16:11.302Z
spacelift.io favicon

Spacelift, Inc.

spacelift.io

62
TechnologyUnited StatesmediumMEDIUM

Spacelift, Inc. operates a mature and reputable infrastructure orchestration platform that integrates with popular infrastructure as code tools such as Terraform, OpenTofu, Ansible, and others. The company targets DevOps and platform engineering teams, offering a SaaS and self-hosted solution to streamline infrastructure provisioning, configuration, governance, and collaboration. The website reflects a strong market position with endorsements from notable customers and partners, emphasizing secure, cost-effective, and high-performance infrastructure delivery. Technically, the website is built on modern frameworks including Next.js and React, hosted on Vercel, and employs a variety of analytics and marketing tools such as Segment, Google Analytics, and HubSpot. The site is well-optimized for SEO, mobile responsiveness, and accessibility, providing an excellent user experience. However, the SSL certificate is currently invalid or misconfigured, and modern TLS protocols are not enabled, which impacts the security posture. Security-wise, the site implements several best practices including strict transport security headers, content security policies, and XSS protections. Despite this, the lack of a valid SSL certificate and absence of OCSP stapling are notable weaknesses. Privacy compliance is well addressed with clear privacy and cookie policies, including consent mechanisms, and GDPR compliance indicators. Overall, Spacelift demonstrates a strong business and technical foundation with minor security and compliance gaps. Addressing SSL issues and enhancing security configurations will further strengthen trust and protect user data.

75
43
25
50
50
85
100
infrastructureascodedevopsautomationterraformansible+4 more
ReactNext.jsVercelSegment+3

Partner Domains:

checkout.com
partner71
1password.com
partnerpending

+3 more partners

2025-06-15T07:09:40.464Z
shralpin.com favicon

Shralpin

shralpin.com

40
MediaUnited StatessmallHIGH

Shralpin is a specialized media platform focused on skateboarding culture, providing news, videos, pictures, and event coverage targeted at skateboarders and enthusiasts. The website operates primarily as a content publisher and community hub, leveraging WordPress CMS and common digital marketing tools such as Google Analytics and Facebook Pixel. The business is positioned as a niche media outlet within the skateboarding industry, serving a small but engaged audience primarily in the United States. Technically, the website is built on WordPress hosted by SiteGround, using standard plugins and scripts for analytics and advertising. However, the site suffers from slow performance and lacks a valid SSL certificate, which critically impacts security and user trust. Mobile optimization and SEO are reasonably well implemented, but accessibility features are basic. From a security perspective, the absence of HTTPS and security headers exposes the site to risks and undermines user data protection. No advanced security policies or incident response contacts are evident. Privacy compliance is minimal, with a privacy policy present but no cookie consent mechanism or GDPR compliance indicators. Overall, the site is functional and professionally presented but requires urgent improvements in security infrastructure and privacy compliance to enhance trustworthiness and protect users. Strategic recommendations include implementing HTTPS, enabling security headers, and adding cookie consent mechanisms to align with privacy regulations.

30
43
25
75
85
85
-
skateboardingmediavideosnewscommunity+2 more
WordPressjQueryWooCommerceGoogle Analytics+3
2025-06-15T07:06:37.517Z
grammarly.com favicon

Grammarly, Inc.

grammarly.com

76
TechnologyUnited StatesenterpriseLOW

Grammarly, Inc. is a leading technology company specializing in AI-powered writing assistance tools designed to improve clarity, tone, and correctness across multiple platforms and applications. With a strong market position serving over 40 million users and 50,000 organizations worldwide, Grammarly offers a subscription-based SaaS model with free and premium tiers tailored for individuals, teams, enterprises, and educational institutions. The company emphasizes responsible AI usage, data privacy, and security, positioning itself as a trusted partner in digital communication enhancement. Technically, Grammarly employs a modern web infrastructure leveraging Next.js, React, and Contentful CMS, hosted on AWS with robust multimedia content delivery. The website demonstrates good performance, mobile optimization, and accessibility, supported by comprehensive SEO and privacy compliance mechanisms including GDPR adherence and cookie consent management via OneTrust. From a security perspective, Grammarly maintains a strong posture with HTTPS enforced, OCSP stapling enabled, and no detected SSL vulnerabilities. However, improvements such as enabling HSTS, DNSSEC, and CAA records could further enhance domain security. The absence of exposed sensitive data and secure form handling practices contribute positively to the overall security maturity. Overall, Grammarly presents a low-risk profile with high business credibility, excellent content quality, and a well-implemented technical stack. Strategic recommendations include enhancing security headers, expanding incident response transparency, and continuous monitoring of privacy compliance to maintain trust and regulatory alignment.

70
43
25
80
97
85
100
protectedcontentaiwritingproductivityeducationenterprise
React (implied by _next.js chunks)Next.jsGoogle Tag ManagerOneTrust (cookie consent)+4

Partner Domains:

coda.io
subsidiary70
2025-06-15T06:07:33.094Z
titanapps.io favicon

Railsware Products Studio LLC

titanapps.io

62
TechnologyUnited StatesmediumMEDIUM

TitanApps is a technology company specializing in productivity tools designed for professional teams using Jira and monday.com platforms. Positioned as a trusted Atlassian Platinum Marketplace Partner, TitanApps offers a suite of smart tools including checklists, templates, hierarchy visualization, productivity dashboards, and AI-powered release notes. Their market presence is supported by a client base of over 4000 organizations, including major enterprises such as Cisco, Microsoft, and Amazon. The company operates under the parent organization Railsware Products Studio LLC, based in the US, and was founded in 2022. Technically, the website is built using modern web technologies such as Astro, Google Tag Manager, Microsoft Clarity, and Cookiebot for consent management. Hosting is provided via Amazon AWS infrastructure. While the site demonstrates good mobile optimization, accessibility, and SEO practices, performance is currently slow, likely due to a large page size and resource count. The site integrates multiple analytics and marketing tools, reflecting a mature digital marketing strategy. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability impacting user trust and data security. Other security best practices such as HSTS, OCSP stapling, and security headers are missing or minimal. Email authentication is partially configured with SPF and DMARC (policy none). Privacy compliance is strong, with clear privacy and cookie policies and an active consent mechanism. Business credibility is high, supported by professional content, clear contact information, and trust signals. Overall, TitanApps presents a professional and trustworthy business with a strong market position and comprehensive privacy compliance. However, the lack of HTTPS and weak SSL/TLS configuration represent significant security risks that should be addressed immediately to protect users and maintain reputation.

15
58
55
75
85
65
100
productivityjiramondaycomprojectmanagementworkflow+4 more
Astro (static site generator)Google Tag ManagerMicrosoft ClarityCookiebot+5

Partner Domains:

railsware.com
parent58
atlassian.com
partner76

+1 more partners

2025-06-15T06:01:52.182Z
fiercevideo.com favicon

StreamTV Insider / Questex

fiercevideo.com

65
MediaUnited StatesmediumMEDIUM

StreamTV Insider, operated by Questex LLC, is a prominent media platform delivering daily news and analysis focused on the streaming video industry. The website offers comprehensive coverage of streaming video distribution, programming, technology, advertising, and industry events, serving a broad audience including service providers, programmers, equipment vendors, and analysts. The platform is closely integrated with related events such as the StreamTV Show, enhancing its market presence and content relevance. Technically, the website is built on Drupal 10 CMS with a modern Vue.js frontend, leveraging Cloudflare for DNS and hosting, and integrating advanced video and advertising technologies such as Brightcove and Google Ad Manager. While the site demonstrates good mobile optimization and SEO practices, performance metrics indicate a slower load time, suggesting opportunities for optimization. From a security perspective, the site employs valid SSL certificates but lacks advanced security headers like HSTS and DMARC, which are recommended to enhance protection. No critical vulnerabilities or exposed sensitive data were detected. Privacy and cookie policies are present and indicate GDPR compliance, with clear contact points for users. Overall, StreamTV Insider presents a professional, trustworthy, and content-rich platform with strong business credibility. Strategic improvements in security headers and performance optimization would further strengthen its digital maturity and user trust.

55
43
25
70
67
75
100
streamingvideomediaindustrynewseventsadvertising+1 more
Vue.jsDrupal 10 CMSGoogle Tag ManagerGoogle DoubleClick for Publishers (GAM)+6

Partner Domains:

fierce-network.com
partner40
streamtvshow.com
partner40
2025-06-15T05:49:20.992Z
spellingbee.com favicon

The E.W. Scripps Company

spellingbee.com

64
EducationUnited StatesmediumMEDIUM

The Scripps National Spelling Bee website represents a well-established educational competition with a rich history dating back to 1925. The site serves a diverse audience including students, educators, and regional partners by providing competition details, finalist information, historical content, and opportunities for engagement and donations. The business operates under the umbrella of The E.W. Scripps Company, a reputable media organization, reinforcing its credibility and market position in the education sector. Technically, the website is built on Drupal 10 and leverages modern web technologies such as Alpine.js, Google Tag Manager, and CDN-hosted assets to enhance user experience and performance. The site is mobile-optimized and features good SEO and accessibility practices, although some accessibility features could be improved. Hosting is via Amazon AWS CloudFront, ensuring reliable content delivery. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, which is a critical vulnerability that significantly lowers its security posture. While some security headers are present, the Content Security Policy is permissive, and no advanced SSL features like OCSP stapling or session resumption are enabled. Privacy compliance is reasonably addressed with a comprehensive privacy policy and cookie consent mechanisms, but no explicit incident response or vulnerability disclosure information is available. Overall, the website is professional and trustworthy in content and business credibility but requires urgent improvements in SSL/TLS configuration to protect user data and enhance trust. Strategic security enhancements and transparency in incident response would further strengthen its risk profile.

60
43
17
85
100
85
100
educationspellingbeecompetitionnon-profitdrupal+3 more
Drupal 10nginxAlpine.jsGoogle Tag Manager+5

Partner Domains:

scripps.com
parent54
2025-06-15T05:46:32.734Z
pandadoc.com favicon

PandaDoc Inc.

pandadoc.com

61
TechnologyUnited StatesenterpriseMEDIUM

PandaDoc Inc. is a mature, enterprise-level technology company founded in 2013, specializing in document workflow automation, e-signature solutions, and CPQ software. The company holds a strong market position with over 50,000 clients and offers a comprehensive suite of services including document generation, deal rooms, smart content, automations, and analytics. Their platform integrates with major CRM and payment systems, enhancing business efficiency and customer experience. Technically, PandaDoc employs a modern tech stack with JavaScript, HubSpot forms, Google Tag Manager, and various marketing and analytics tools. The website is hosted on AWS and uses WordPress CMS with WPML for multilingual support. Despite rich content and good mobile optimization, the website suffers from critical security issues due to an invalid SSL certificate and lack of TLS protocols, which significantly impacts its security posture. Security-wise, PandaDoc demonstrates strong compliance with SOC 2, HIPAA, GDPR, E-SIGN, and UETA standards, reflecting a robust security framework. However, the absence of a valid SSL certificate and modern TLS support exposes the site to potential risks. The domain is well-protected and mature, indicating a legitimate and trustworthy business. Overall, while PandaDoc excels in business credibility, content quality, and privacy compliance, it must urgently address its SSL/TLS configuration to improve security and maintain trust. Strategic improvements in SSL deployment and security best practices are recommended to enhance the company's digital security posture.

85
25
25
100
50
85
100
documentmanagemente-signaturecpqworkflowautomationcompliance+2 more
JavaScriptHubSpot formsGoogle Tag ManagerOneTrust (cookie consent)+7

Partner Domains:

hubspot.com
partner73
salesforce.com
partner67

+3 more partners

2025-06-15T05:41:16.962Z
highspot.com favicon

Highspot

highspot.com

59
TechnologyUnited StatesenterpriseMEDIUM

Highspot is a leading sales enablement platform provider offering a unified, AI-driven solution to improve marketing effectiveness, sales productivity, and revenue growth. The company targets global enterprise customers and provides a comprehensive suite of tools including sales content management, playbooks, buyer engagement, training, coaching, and analytics. Recognized by industry analysts and awards, Highspot holds a strong market position in the technology sector. The website demonstrates a mature digital presence with extensive marketing and analytics integrations, professional design, and comprehensive privacy compliance. However, the absence of a valid SSL certificate and HTTPS support represents a critical security vulnerability that undermines user trust and data protection. The site lacks explicit security and incident response policies, which could be improved to enhance overall security posture. Performance is suboptimal with slow load times and large page size, suggesting opportunities for optimization. Strategic recommendations include immediate remediation of SSL/TLS issues, enabling modern security protocols, and enhancing transparency around security policies to strengthen trust and compliance.

35
25
25
85
85
90
100
salesenablementaigtmmarketingsalesproductivity+4 more
WordPress CMSYoast SEOMarketoGoogle Tag Manager+8

Partner Domains:

marketo.net
partner96
sendgrid.net
partner93

+3 more partners

2025-06-15T02:49:29.540Z
brookfieldreit.com favicon

Brookfield Real Estate Income Trust

brookfieldreit.com

64
Real EstateUnited StateslargeMEDIUM

Brookfield Real Estate Income Trust (Brookfield REIT) is a large-scale real estate investment trust providing individual investors access to private real estate opportunities focused on income generation and capital appreciation. The company leverages a global network of experts and a partnership with Brookfield Oaktree Wealth Solutions to deliver diversified real estate investment products. The website is professionally designed, content-rich, and targets both individual investors and financial advisors with clear calls to action and comprehensive disclosures. Technically, the site is built on Drupal 10, hosted on Pantheon infrastructure, and employs modern web technologies including Google Tag Manager and OneTrust for cookie consent. The site is mobile optimized, accessible, and SEO friendly with structured data enhancing search visibility. Performance is fast with no blocking or WAF detected. Security posture is solid with HTTPS enforced and key security headers present, though improvements are recommended in HSTS configuration and DNS security (DNSSEC, CAA). No critical vulnerabilities or exposed sensitive data were found. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Overall, the site demonstrates a mature digital presence with strong business credibility and trust indicators. Strategic recommendations include enhancing DNS security, strengthening HSTS policies, and publishing explicit security and incident response policies to further improve trust and compliance.

50
40
25
50
67
85
100
realestateinvestmentfinancereitdrupal+1 more
Drupal 10nginxGoogle Tag ManagerOneTrust Cookie Consent+4

Partner Domains:

brookfieldoaktree.com
partner60
secureaccountview.com
service64
2025-06-14T22:42:34.367Z
ivansinsurance.com favicon

Ivans

ivansinsurance.com

69
TechnologyUnited StatesenterpriseMEDIUM

Ivans is a leading technology company specializing in digital insurance software that connects carriers, MGAs, and agencies. Positioned as an industry network, Ivans offers streamlined workflows and connectivity solutions to drive business growth for insurance professionals. The company operates under the parent organization Applied Systems, Inc., and serves primarily the US market with enterprise-level solutions. Their offerings include digital distribution platforms, claims communications, and industry insights, targeting insurance agents and brokers. The website reflects a strong market position with clear branding, comprehensive content, and multiple trust signals such as awards and customer testimonials. Technically, the website employs modern web technologies including jQuery, Bootstrap, and Marketo forms, hosted behind Cloudflare with robust SSL/TLS configurations supporting TLS 1.3 and OCSP stapling. Performance is fast with good mobile optimization and accessibility features. SEO is enhanced by structured data (JSON-LD) and proper meta tags. However, there is room for improvement in security headers (lack of HSTS) and DNS security (no DNSSEC or CAA records). From a security perspective, the site demonstrates good practices with secure cookies, no known SSL vulnerabilities, and no exposed sensitive data. The absence of a cookie consent mechanism and explicit GDPR compliance indicators suggests partial privacy compliance. No security policy or incident response information is publicly available, which could be a gap for enterprise clients. Overall, the security posture is strong but could be enhanced with additional headers and transparency. The overall risk assessment is low with a well-maintained, professional website that supports Ivans' business credibility and digital maturity. Strategic recommendations include implementing cookie consent for privacy compliance, enabling HSTS, adding DNS security records, and publishing security and incident response policies to further build trust and compliance.

20
43
25
50
92
80
100
insurancetechnologysoftwaredigitaldistributioninsuranceconnectivity+4 more
jQuery 3.6.0jQuery UI 1.12.1Bootstrap 4.6.0Marketo Forms+1

Partner Domains:

appliedsystems.com
parent50
2025-06-14T22:32:18.748Z