Skip to main content

Finance security reports

Browse 5,578 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

156451
Websites
130
Industries
113
Countries
52
Avg Score
Page 102 of 112|Showing 5051-5100 of 5578
B

BMO Global Asset Management

bmogam.nl

35
FinanceCanadalargeHIGH

BMO Global Asset Management (BMO GAM) is a leading Canadian asset manager offering a broad range of investment products including mutual funds, ETFs, and alternative products. The website clearly targets investors, advisors, and institutional clients, reflecting a mature and well-established financial services business. The company operates under the larger Bank of Montreal (BMO) umbrella, reinforcing its market position and credibility. Technically, the website leverages modern web technologies such as Next.js and integrates with Adobe Launch and OneTrust for marketing and compliance. Hosting is provided via Akamai CDN, ensuring global content delivery. However, the absence of a valid SSL certificate and disabled TLS protocols represent significant technical and security shortcomings that undermine user trust and data protection. From a security perspective, while some security headers like HSTS and X-Frame-Options are present, the lack of HTTPS and modern TLS support is a critical vulnerability. No published security policies, incident response contacts, or vulnerability disclosure mechanisms were found, indicating gaps in security transparency and readiness. Overall, the website is professionally designed and content-rich, but the lack of proper SSL/TLS configuration and security disclosures lowers its security posture and trustworthiness. Strategic improvements in SSL deployment, security policy publication, and DNS security would significantly enhance the site's security and compliance standing.

40
-
5
50
-
40
100
financeassetmanagementinvestmentcanadianbusinessbmo
React (Next.js)jQueryjQuery UIOneTrust Cookie Consent+5
2025-06-15T21:48:25.719Z
R

Raiffeisenverband Salzburg eGen

rvs.at

39
FinanceAustrialargeHIGH

Raiffeisenverband Salzburg eGen operates as a large regional banking cooperative in Austria, providing a comprehensive range of financial services including retail banking, corporate banking, investment products, insurance, and real estate services. The website targets private and corporate customers primarily in the Salzburg region, emphasizing local presence and digital innovation. The business is well-positioned as the largest banking group in Austria by branch count and employees, with a strong community and regional focus. Technically, the website is built on Adobe Experience Manager CMS with modern web technologies and responsive design, offering good user experience and accessibility. However, a critical security gap exists due to the absence of a valid SSL certificate and HTTPS support, which severely impacts the security posture. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Contact information and trust indicators are prominently presented, supporting business credibility. Overall, the site is professional and content-rich but urgently requires SSL implementation to secure user data and maintain trust.

45
-
-
50
-
85
100
bankingfinanceraiffeisenaustriaregionalbank+2 more
JavaScriptAdobe Experience Manager (AEM)Google Tag Manager (implied by Adobe DTM)Cookielaw.org CMP+6

Partner Domains:

raiffeisen.at
partnerpending
integrityline.com
partner70

+1 more partners

2025-06-15T21:48:06.683Z
F

FERNBACH Financial Software

fernbach.com

40
FinanceAustriamediumHIGH

FERNBACH Financial Software operates FlexFinance, a specialized software suite designed to optimize lending business processes including loan origination, credit lifecycle management, and risk management. The company targets banks and financial institutions, offering solutions that enhance efficiency, transparency, and compliance. With a user base exceeding 12,000 and over one million credit decisions processed annually, FERNBACH holds a solid position in the finance software niche, supported by multilingual capabilities and a consistent brand presence. Technically, the website employs modern front-end technologies such as jQuery, Bootstrap, and Popper.js, alongside analytics tools like Google Analytics and Microsoft Clarity. However, the site suffers from poor performance with a notably high load time and lacks a valid SSL certificate, which critically undermines its security posture. The absence of HTTPS and security headers exposes the site to potential risks, despite no detected vulnerabilities in SSL protocols themselves. Privacy compliance is well addressed with comprehensive privacy and cookie policies, including consent mechanisms aligned with GDPR requirements. Contact information is limited but present, primarily via a company email address. The overall website quality is good in terms of design, content relevance, and user experience, though technical and security improvements are necessary. Strategically, the company should prioritize securing its website with a valid SSL certificate and enabling HTTPS to protect user data and improve trust. Performance optimization and implementation of security headers would further enhance the site's security and user experience. Maintaining transparent privacy practices and expanding contact options could strengthen business credibility and customer confidence.

35
33
-
50
-
85
100
financebankingsoftwareloanoriginationriskmanagementcompliance+1 more
jQuery 3.6.1Bootstrap 5Popper.jsGoogle Analytics+5
2025-06-15T21:47:46.218Z
sds.at favicon

Software Daten Service Gesellschaft m.b.H.

sds.at

40
FinanceAustriamediumHIGH

Software Daten Service Gesellschaft m.b.H. (SDS) is a medium-sized Austrian company specializing in software and services for the international financial industry, with additional focus on telecommunications and digital entertainment sectors. The company offers a comprehensive portfolio including securities processing, regulatory reporting, compliance, consulting, managed services, and professional testing. SDS benefits from a strong market position supported by its 50 years of history and affiliation with the Deutsche Telekom Group. The website reflects a professional and consistent brand image targeting financial institutions and related industries globally. Technically, the site is built on WordPress with modern plugins and SEO optimizations, but suffers from critical security shortcomings due to the absence of a valid SSL certificate and lack of HTTPS support. Security headers are present but insufficient to compensate for the missing encryption. Privacy and cookie policies are well implemented with consent mechanisms, supporting GDPR compliance. Contact information is clearly provided, enhancing business credibility. Overall, the site is content-rich and professionally maintained but urgently requires SSL/TLS remediation to improve security posture and trust.

65
-
-
50
-
85
100
financesoftwarecompliancetestingconsulting+1 more
ApachePHP 7.4WordPress 6.6.1jQuery+4

Partner Domains:

t-systems.jobs
partnerpending
2025-06-15T21:47:20.154Z
bausparen.at favicon

Raiffeisen Bausparkasse Gesellschaft m.b.H.

bausparen.at

24
FinanceAustriamediumCRITICAL

Raiffeisen Bausparkasse Gesellschaft m.b.H. is a well-established Austrian financial services company specializing in building savings contracts and financing solutions for housing and related needs. The company has a strong market presence with over 60 years of experience and offers a range of products including classic building savings, financing for construction, renovation, education, and health care. The website reflects a professional and consistent brand image targeting private individuals seeking secure and reliable financial products. Technically, the site is built on Adobe Experience Manager and uses modern web technologies such as AngularJS and Adobe DTM for analytics and marketing. It is hosted behind Cloudflare, ensuring good performance and security at the network level. However, a critical security issue is the invalid or missing SSL certificate and lack of TLS protocol support, which severely impacts the security posture and user trust. Privacy compliance is well addressed with comprehensive privacy and cookie policies and a consent mechanism in place. Contact information is clearly provided, enhancing business credibility. Overall, the site is functional and professional but requires urgent remediation of SSL/TLS issues to ensure secure user interactions.

40
-
5
50
-
85
-
financebausparenraiffeisenbuildingsavingsfinancing+1 more
Cloudflare (CDN and security)Adobe Dynamic Tag Management (Adobe DTM)JQueryVideo.js+5

Partner Domains:

raiffeisen.at
partnerpending
2025-06-15T21:47:16.437Z
venionaire.com favicon

Venionaire Capital

venionaire.com

28
FinanceAustriamediumHIGH

Venionaire Capital is a medium-sized, globally active investment and advisory firm specializing in Private Equity and Venture Capital. The company offers a broad range of services including fund management, corporate finance, M&A, restructuring, and research products. It targets investors, entrepreneurs, and corporates, positioning itself as an entrepreneurial partner with a strong global footprint and multiple co-founded initiatives enhancing the investment ecosystem. The website content is professionally presented with clear navigation and rich service descriptions, reflecting a mature business model and market presence. Technically, the website is built on WordPress using the Enfold theme and integrates common technologies such as jQuery, Yoast SEO, and Google Analytics. However, the site suffers from critical security shortcomings, notably the absence of HTTPS and a valid SSL certificate, which severely impacts its security posture. Performance is slow, and while mobile optimization and SEO are good, accessibility is basic. Cookie consent mechanisms are present, but no explicit security or incident response policies are published. Security-wise, the lack of HTTPS and modern TLS protocols is a major vulnerability, exposing users to data interception risks. No advanced security headers or certificate transparency measures are implemented. The WHOIS data is consistent with the business claims, showing no suspicious patterns. Overall, the site demonstrates good business credibility but requires urgent security improvements to protect user data and enhance trust. Strategically, Venionaire Capital should prioritize obtaining and configuring a valid SSL certificate, enabling HTTPS, and implementing modern security headers and protocols. Enhancing privacy and incident response disclosures would also improve compliance and user confidence. These steps will strengthen the company's digital maturity and reduce risk exposure.

15
18
5
50
-
85
40
financeventurecapitalprivateequityinvestmentcorporatefinance+3 more
nginxjQueryYoast SEOGoogle Analytics+5

Partner Domains:

superangels.club
partnerpending
worldventureforum.info
partnerpending

+2 more partners

2025-06-15T21:47:05.775Z
inbank.eu favicon

Inbank

inbank.eu

40
FinanceEstonialargeHIGH

Inbank operates as an embedded financing platform focused on accelerating sales for merchants and providing tailored financing solutions to consumers across multiple European markets. The company supports a broad range of sectors including retail, eco-friendly products, and automotive financing, positioning itself as a significant player with over 872,000 active contracts and partnerships with more than 6,000 retailers. The website reflects a professional and consistent brand image with clear business information and a user-friendly design. Technically, the website is built on modern frameworks such as Nuxt.js and Vue.js, styled with Tailwind CSS, and hosted on Amazon AWS infrastructure. While the site performs moderately well and is mobile optimized, it lacks a valid SSL certificate and HTTPS support, which is a critical security flaw. Additionally, no security headers or advanced TLS configurations are present, exposing the site to potential risks. From a security perspective, the absence of HTTPS and security headers significantly lowers the security posture score. Privacy and cookie policies are implemented with consent mechanisms, indicating basic GDPR compliance. Contact information is clearly available, but no explicit security or incident response policies are found. The WHOIS data is consistent with the business claims, supporting domain legitimacy. Overall, the website demonstrates good business credibility and content quality but suffers from critical security shortcomings. Immediate remediation of SSL/TLS issues and implementation of security best practices are recommended to enhance trust and protect users.

55
15
25
85
100
85
100
financeembeddedfinancingretaildigitalpaymentspersonalloans+3 more
Nuxt.jsVue.jsTailwind CSSGoogle Fonts+1
2025-06-15T17:01:15.342Z
slipcase.com favicon

Slipcase

slipcase.com

51
FinanceUnited KingdomsmallMEDIUM

Slipcase is a specialized content platform serving the global (re)insurance industry by aggregating and curating relevant news, insights, and thought leadership. The platform targets industry professionals and organizations, offering personalized dashboards, mobile app access, and organizational content distribution with reporting. The business is UK-based, established in 2000, and operates a niche service model focused on finance and insurance sectors. Technically, the website employs modern JavaScript modules, external libraries like Animate.css, and integrates marketing and analytics tools such as HubSpot and LinkedIn. Hosting is on Amazon AWS infrastructure. However, the website suffers from slow load times and lacks a valid SSL certificate, which significantly impacts security and user trust. From a security perspective, the absence of HTTPS, security headers, and domain protection measures exposes the site to risks and undermines compliance with modern security standards. Privacy compliance is basic, with policies present but lacking explicit consent mechanisms. Contact information is available, but no phone numbers are provided. Overall, Slipcase presents a professional and content-rich platform with good business credibility but requires urgent improvements in security posture and technical performance to enhance trust and compliance.

90
25
25
50
50
70
100
insurancereinsuranceindustrynewscontentcurationfinance
JavaScript ES ModulesAnimate.cssGoogle Fonts (Roboto)HubSpot scripts+4
2025-06-15T13:15:10.077Z
aviva.com favicon

Aviva plc

aviva.com

40
FinanceUnited KingdomenterpriseHIGH

Aviva plc is a leading diversified insurer headquartered in the United Kingdom, offering a broad range of insurance, wealth management, and retirement services primarily across the UK, Ireland, and Canada. The company targets investors, shareholders, career seekers, and socially conscious individuals, positioning itself as a trusted financial services provider with a strong market presence and extensive subsidiary network. The website reflects a professional and comprehensive corporate portal with rich investor relations content, leadership profiles, and sustainability initiatives. Technically, the website leverages modern JavaScript frameworks, Adobe Experience Manager CMS, and Akamai CDN for content delivery. It integrates advanced analytics and marketing tools such as Adobe Helix RUM and OneTrust for privacy compliance. The site is mobile-optimized, accessible, and SEO-friendly, providing a high-quality user experience. From a security perspective, while several best practices are implemented including CSP, X-Content-Type-Options, and HSTS headers, the SSL certificate is invalid and no TLS protocols are enabled, representing a critical vulnerability that undermines secure communications. No WAF or blocking mechanisms are detected, and privacy policies are comprehensive and GDPR compliant. The domain registration data aligns well with the business claims, indicating high legitimacy. Overall, the website is professional and credible but requires urgent remediation of SSL and TLS issues to ensure secure user interactions and maintain trust.

65
33
5
50
-
85
100
insurancefinancecorporateinvestorrelationssustainability+2 more
JavaScriptReact componentsHandlebarsRequireJS+6

Partner Domains:

marsh.com
partner66
slipcase.com
partnerpending
2025-06-15T13:07:55.360Z
tasgroup.eu favicon

TAS group

tasgroup.eu

40
FinanceItalylargeHIGH

TAS group is a leading Italian ICT company specializing in digital payment software and services for banks, fintechs, and corporates. The company offers a comprehensive Global Payment Platform and a suite of solutions covering digital payments, capital markets, real-time liquidity, financial networks, and PSD2 compliance. TAS is recognized in the IDC FinTech Top 100 and holds certifications such as UNI/PdR 125:2022, reflecting its commitment to social responsibility and workplace equality. The website targets financial institutions and technology providers, positioning TAS as a trusted partner in the evolving payments ecosystem. Technically, the website is built on WordPress with modern plugins and technologies including Kadence Blocks, HubSpot forms, and advanced analytics tools like Matomo and Plausible. The site is well-optimized for mobile and accessibility, with strong SEO practices and structured data markup enhancing discoverability and user experience. However, performance metrics indicate slow loading times, suggesting room for optimization. From a security perspective, the site implements several important HTTP security headers but lacks a valid SSL certificate and does not support TLS protocols, severely impacting its security posture. The absence of HTTPS and related best practices exposes the site to risks and undermines user trust. Privacy compliance is well addressed with clear privacy and cookie policies, consent mechanisms, and GDPR adherence. Overall, TAS group presents a professional and credible online presence with strong business and technical foundations. The primary risk lies in the lack of proper SSL/TLS configuration, which should be urgently addressed to secure communications and maintain trust. Strategic recommendations include implementing HTTPS, enabling modern TLS protocols, and enhancing security configurations to align with industry best practices.

65
33
5
50
-
85
100
digitalpaymentsbankingsoftwarefintechpaymentsolutionsopenbanking+2 more
WordPressKadence BlocksjQueryLottie animations+4

Partner Domains:

worldpay.com
partner69
2025-06-15T13:07:45.786Z
guarantee.money favicon

ООО «Айкюсофт»

guarantee.money

65
FinanceRussiamediumMEDIUM

The website guarantee.money operates as an escrow service platform primarily targeting Russian-speaking users. It facilitates secure transactions between buyers and sellers by acting as a trusted third party holding funds in escrow until transaction conditions are met. The business is positioned as a medium-sized technology and finance service founded in 2017, with a focus on online marketplaces, arbitration, and payment link generation. The company behind the service is ООО «Айкюсофт», based in Russia. Technically, the site is built on a modern React and Next.js stack with Material-UI for UI components, indicating a contemporary digital infrastructure. However, the site suffers from a critical security shortcoming: the absence of a valid SSL certificate and proper HTTPS support, which undermines user trust and data security. While HSTS headers are configured, they are ineffective without valid SSL. Privacy and terms of service pages exist but cookie consent mechanisms are missing, indicating partial privacy compliance. Contact information is limited to an email address at iqsoft.company, with no phone or physical address provided. Overall, the site is functional and content-rich but requires urgent security improvements to meet industry standards and user expectations.

70
40
25
70
100
70
100
escrowsafetransactionssecurepaymentsarbitrationpaymentlinks+1 more
ReactNext.jsMaterial-UIJavaScript+1

Partner Domains:

iqsoft.company
partnerpending
2025-06-15T10:26:32.553Z
banqup.com favicon

Banqup Group

banqup.com

65
FinanceBelgiumenterpriseMEDIUM

Banqup Group operates a sophisticated digital platform focused on streamlining invoicing, payments, and compliance for a wide range of business customers including professionals, accountants, SMEs, and large enterprises. The company holds a strong market position in Europe, supported by its parent company Unifiedpost Group, and offers key services such as e-invoicing, compliance management, and integration with existing business software. The platform is designed to reduce administrative overhead and accelerate financial workflows. Technically, the website leverages modern web technologies including React and Next.js, with content managed via Storyblok CMS and hosted through a combination of Webflow and cloud services. While the site is content-rich and well-structured with good SEO and accessibility practices, performance is somewhat slow, and the SSL/TLS configuration is currently invalid, which poses a significant security risk. Security posture is moderate; the site employs HSTS and DMARC policies but lacks a valid SSL certificate and modern TLS support, which are critical for secure communications. Privacy compliance is strong, with a comprehensive privacy policy and cookie consent mechanism in place. Business credibility is high, supported by clear contact information, leadership announcements, and investor relations presence. Overall, Banqup presents a professional and trustworthy digital presence with room for improvement in security infrastructure. Addressing SSL/TLS issues and enhancing security headers would significantly improve the security posture and user trust.

50
25
25
85
97
80
100
financee-invoicingcompliancedigitalpaymentspeppol+1 more
ReactNext.jsWebflow (proxy-ssl.webflow.com TXT record)Google Tag Manager+2
2025-06-15T10:07:15.360Z
mycreditinfo.ge favicon

სს “საკრედიტო საინფორმაციო ბიურო კრედიტინფო საქართველო”

mycreditinfo.ge

61
FinanceGeorgiamediumMEDIUM

Mycreditinfo.ge is a Georgian finance sector website operated by სს “საკრედიტო საინფორმაციო ბიურო კრედიტინფო საქართველო”, providing credit information services including free and premium credit reports, credit score monitoring, and educational content. The site targets individuals and legal entities in Georgia seeking to manage and improve their credit profiles. The business model includes both free access and paid premium services, positioning it as a key player in the local credit information market. Technically, the website is built on Angular 13 and integrates common analytics and marketing tools such as Google Analytics and Facebook Pixel. It is hosted on Microsoft Azure, indicating a modern cloud infrastructure. However, the site suffers from slow performance due to large page size and load times, which could impact user experience. From a security perspective, the site has significant weaknesses: it lacks a valid SSL certificate and does not support any TLS protocols, severely limiting secure communications. While HSTS is enabled, its benefits are negated by the missing SSL. The site implements SPF and DMARC for email security and has basic security headers, but lacks advanced features like OCSP stapling and session resumption. Privacy and cookie policies are present with a consent mechanism, but GDPR compliance is not clearly demonstrated. Overall, the site is functional and content-rich but requires urgent improvements in SSL/TLS configuration to ensure user data protection and trust. Performance optimization and enhanced privacy compliance would further strengthen its digital maturity and security posture.

65
25
17
85
100
70
100
financecreditgeorgiacreditscorecreditreport+1 more
Angular 13Google AnalyticsFacebook SDKreCAPTCHA+1
2025-06-15T10:06:32.973Z
creditinfo.ee favicon

AS Creditinfo Eesti

creditinfo.ee

40
FinanceEstonialargeHIGH

AS Creditinfo Eesti operates Estonia's largest and most trusted business information database, offering comprehensive credit information, payment default registers, credit ratings, and business lists. As part of the international Creditinfo Group, it serves a broad audience including businesses and individuals seeking to manage credit risks and make informed financial decisions. The company is well-established with a domain age of 9 years and recognized certifications such as ISO 27001, underscoring its commitment to information security. Technically, the website is built on WordPress with modern JavaScript libraries like jQuery and Slick Carousel, integrated with analytics and marketing tools including Google Tag Manager, Hotjar, and Facebook Pixel. The site demonstrates good SEO and mobile optimization, though performance is moderate and could benefit from further optimization. The hosting and DNS infrastructure is stable but lacks advanced security features like DNSSEC and domain protection locks. Security posture reveals critical issues, notably the absence of a valid SSL certificate, which severely impacts user trust and data protection. While DMARC policies and some best practices are in place, the lack of HTTPS and HSTS headers exposes the site to potential risks. Privacy compliance is strong, with clear cookie consent mechanisms and GDPR adherence. Business credibility is high, supported by clear contact information, social media presence, and trust signals. Overall, the site is functional and professional but requires urgent remediation of SSL/TLS issues to ensure secure communications and maintain trust. Strategic improvements in DNS security and domain management would further enhance its security posture.

25
-
25
50
50
70
100
creditinfokrediidireitingudmaksehiredkrediidiraportidriinfo+3 more
WordPressjQuerySlick CarouselGoogle Tag Manager+2

Partner Domains:

creditinfo.com
parent59
e-krediidiinfo.ee
servicepending
2025-06-15T10:04:10.430Z