Skip to main content

Finance security reports

Browse 5,578 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

156451
Websites
130
Industries
113
Countries
52
Avg Score
Page 106 of 112|Showing 5251-5300 of 5578
norisbank.de favicon

norisbank GmbH

norisbank.de

57
FinanceGermanylargeMEDIUM

norisbank GmbH is a direct bank subsidiary of Deutsche Bank Gruppe, headquartered in Bonn, Germany. The company offers a range of financial products including credit, checking accounts (Girokonto), savings accounts (Tagesgeld), credit cards, and securities depot services. The website demonstrates a strong market position with multiple awards and certifications, targeting private customers, business clients, students, and youth. The business model focuses on digital banking services with an emphasis on online and mobile banking platforms. Technically, the website is built on Adobe Experience Manager with integrations for Adobe Analytics and Usercentrics for consent management, reflecting a mature digital infrastructure. However, the website currently lacks a valid SSL/TLS certificate, which is a critical security vulnerability. Email security is well configured with SPF and DMARC policies. Privacy and cookie policies are present and GDPR compliant, but no explicit security or incident response policies are found. Overall, the site is professional, trustworthy, and well-optimized for SEO and accessibility, but requires urgent improvements in SSL security to protect user data and maintain trust.

65
18
25
70
50
85
100
bankingfinancedirectbankonlinebankingcredit+4 more
Adobe Experience Manager (AEM)Adobe LaunchUsercentrics Consent ManagementJavaScript+5

Partner Domains:

deutsche-bank.de
parent64
maxblue.de
partner61

+1 more partners

2025-06-14T18:32:19.516Z
berenberg.com favicon

Berenberg

berenberg.com

65
FinanceGermanylargeMEDIUM

Berenberg is a historic and well-established financial institution founded in 1590, headquartered in Hamburg, Germany, with a strong presence across Europe and the United States. The company offers a comprehensive suite of financial services including investment banking, corporate banking, asset management, and fund management. It is recognized as one of Europe's leading advisors with a large equity research team covering over 800 European companies. The website reflects a mature digital presence with detailed business information, multiple international office locations, and a focus on client service and sustainability. Technically, the website employs modern web technologies such as JavaScript frameworks, SVG graphics, lazy loading, and structured data for SEO. Hosting is on Microsoft Azure with DNS managed by Colt, and the SSL configuration is robust with TLS 1.2 and strong cipher suites. Cookie consent is managed via CookieFirst, ensuring compliance with privacy regulations. However, there is room for improvement in security headers and protocols, such as enabling HSTS, DNSSEC, and TLS 1.3. From a security perspective, the site demonstrates good practices including SPF and DMARC email protections, OCSP stapling, and no detected SSL vulnerabilities. The privacy policy and cookie consent mechanisms are comprehensive and GDPR compliant. No explicit incident response or vulnerability disclosure pages were found, which could be enhanced to improve transparency and security posture. Overall, Berenberg's website and digital infrastructure reflect a high level of professionalism and trustworthiness, supporting its position as a major player in the financial services sector. Strategic improvements in security protocols and transparency could further strengthen its risk management and client confidence.

80
25
25
65
92
85
100
financeinvestmentbankingassetmanagementcorporatebanking+4 more
JavaScriptSVGLazy loading imagesJSON-LD structured data+3

Partner Domains:

berenbergbank.de
partnerpending
berenberg-us.com
partnerpending

+3 more partners

2025-06-14T18:32:18.705Z
finstar.ch favicon

Finstar AG

finstar.ch

69
FinanceSwitzerlandmediumMEDIUM

Finstar AG is a Swiss-based company specializing in integrated IT solutions for private and universal banks as well as fintechs. With over 40 years of experience, the company offers customized and cost-effective banking software and services, positioning itself as a trusted partner in the financial technology sector. Their offerings include a broad range of products and services such as APIs, digital onboarding, and digital asset platforms, supported by a strong ecosystem of partner banks and financial institutions. The company is a subsidiary of Hypothekarbank Lenzburg AG and holds the prestigious 'swiss made software' label, underscoring its commitment to quality and reliability. Technically, the website is built on the Umbraco CMS and leverages modern JavaScript libraries including GSAP and ScrollMagic for enhanced user experience. It integrates Cookiebot for GDPR-compliant cookie consent management and Google Tag Manager for analytics and marketing. However, the website currently lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical security gap. Performance is slow, likely due to the large page size and resource count, but mobile optimization and accessibility are rated good. From a security perspective, the domain has well-configured SPF and DMARC records with a strict reject policy, reducing email spoofing risks. Despite this, the absence of HTTPS and security headers significantly lowers the security posture. No explicit security policy, incident response contacts, or vulnerability disclosure mechanisms were found. The cookie consent mechanism is comprehensive and transparent, supporting GDPR compliance. Overall, Finstar AG presents a professional and trustworthy digital presence with strong business credentials and compliance in privacy and cookie management. The primary risk lies in the lack of HTTPS, which should be addressed urgently to protect user data and maintain trust. Strategic improvements in security infrastructure and transparency around security policies would enhance the company's risk profile and customer confidence.

45
43
25
95
75
85
100
openbankingbankingsolutionsfintechintegrateditsolutionsswissmadesoftware+2 more
JavaScriptGoogle Tag ManagerCookiebotPhotoswipe+2

Partner Domains:

ersparniskassespeicher.ch
partnerpending
slwynigen.ch
partnerpending

+2 more partners

2025-06-14T18:32:03.834Z
bonify.de favicon

Forteil GmbH

bonify.de

65
FinanceGermanymediumMEDIUM

bonify.de is a German financial technology platform operated by Forteil GmbH, specializing in credit management and financial fitness services. The company provides users with free and transparent access to their SCHUFA credit data, credit scores, and personalized financial insights. With over 2.5 million users and certifications from TÜV Saarland and BaFin, bonify holds a strong market position in Germany's finance sector. The platform offers a comprehensive suite of services including credit monitoring, tenant credit reports, contract management, and credit offers, targeting consumers seeking to improve their financial health. Technically, bonify employs modern web technologies such as React with Next.js, Prismic CMS, and Cloudflare for hosting and DNS. The site integrates various third-party services including Google Tag Manager, Usercentrics for cookie consent, and Adjust for app marketing. Performance is moderate with good mobile optimization and SEO practices. Privacy compliance is well addressed with GDPR-aligned policies and cookie consent mechanisms. From a security perspective, bonify uses SSL encryption and domain verification but lacks advanced DNS security features like DNSSEC and HSTS. The DMARC policy is set to none, which could be strengthened to reduce email spoofing risks. The presence of a responsible disclosure page indicates security awareness, though no explicit incident response contacts were found. Overall, bonify.de demonstrates a mature digital presence with strong business and security fundamentals. Opportunities exist to enhance DNS and email security configurations and to publish more explicit security policies and incident response information to further build user trust and compliance posture.

85
18
35
85
67
80
100
financecreditschufabonittfinanzen+5 more
React (Next.js)Cloudflare DNS and CDNGoogle Tag ManagerUsercentrics (cookie consent)+8

Partner Domains:

schufa.de
partnerpending
tuev-saar.de
partnerpending
2025-06-14T18:22:14.276Z
hbl.ch favicon

Hypothekarbank Lenzburg AG

hbl.ch

67
FinanceSwitzerlandmediumMEDIUM

Hypothekarbank Lenzburg AG is a Swiss regional bank offering a hybrid model of digital and personal banking services targeting private and corporate customers. The website reflects a mature digital presence with comprehensive service offerings including e-banking, mortgages, savings, investments, and financial planning. The bank positions itself as a trusted regional financial institution with a focus on customer-centric solutions. Technically, the website is built on Umbraco CMS and leverages modern frontend libraries such as Swiper, GSAP, and Cookiebot for consent management. However, the current SSL/TLS configuration is invalid, which poses a significant security risk and undermines user trust. Security headers like SPF and DMARC are properly configured, but the absence of DNSSEC, CAA, and HSTS reduces the overall security posture. The site employs extensive tracking and advertising technologies including Google Analytics, TikTok, and Meta Platforms, with a robust cookie consent mechanism ensuring GDPR compliance. Overall, the bank demonstrates a strong market position with a professional and user-friendly website but must urgently address SSL/TLS issues to maintain security and trust.

45
43
25
70
100
85
100
bankingfinancedigitalbankinghypothekarbankswitzerland+3 more
Umbraco CMSGoogle Tag ManagerCookiebotjQuery (implied by plugins)+5

Partner Domains:

hblasset.ch
partnerpending
finstar.ch
partnerpending

+1 more partners

2025-06-14T18:22:14.104Z
banrisul.com.br favicon

Banrisul - Banco do Estado do Rio Grande do Sul, S.A.

banrisul.com.br

59
FinanceBrazillargeMEDIUM

Banrisul is a large, state-owned multiple bank operating primarily in the southern region of Brazil, specifically Rio Grande do Sul. It offers a range of banking and financial services including commercial banking, development banking, leasing, real estate credit, financing, and investment. The website serves as a portal for internet banking and related services, targeting residents and businesses in its regional market. The business model focuses on public banking services with a regional market position. Technically, the website infrastructure appears outdated, using framesets and lacking modern web technologies or CMS indicators. Performance is moderate but mobile optimization and accessibility are poor. The absence of modern security protocols and an invalid SSL certificate indicate significant technical debt and security risks. No advanced frameworks or analytics tools are detected, and SEO is basic. From a security perspective, the site lacks a valid SSL certificate and does not support any TLS protocols, exposing users to potential risks. There are no HTTP security headers, no privacy or cookie policies, and no visible incident response or vulnerability disclosure mechanisms. This reflects a low security maturity level and potential compliance gaps with data protection regulations. Overall, the website requires urgent improvements in security posture, modernization of technical infrastructure, and implementation of privacy and compliance policies to enhance trust and protect users. Strategic investments in security and digital modernization are recommended to align with industry standards and regulatory requirements.

80
40
25
50
50
85
100
bankingfinancebrazilpublicbankriograndedosul+1 more
2025-06-14T18:20:45.253Z
qwist.com favicon

Qwist GmbH

qwist.com

63
FinanceGermanymediumMEDIUM

Qwist GmbH is a leading open finance platform operating primarily in the DACH and Iberian markets, offering a comprehensive suite of B2B2X financial technology products. Their key offerings include digital account and portfolio switching, open banking compliance solutions, financial data analytics, and digital lending integration. The company positions itself as the #1 open finance company in its region, serving major banks and financial institutions with a strong investor backing from Finch Capital and Finleap. Technically, the website is built on WordPress with the Divi theme and leverages modern marketing and analytics tools such as HubSpot, Matomo, and SalesLoft. The site employs GDPR-compliant cookie consent via Cookiebot and maintains a valid SSL certificate, although some security enhancements like HSTS and DNSSEC are absent. Performance is moderate with good mobile optimization and SEO practices. From a security perspective, Qwist demonstrates solid foundational practices including SPF and DMARC email protections and encrypted communications. However, the absence of advanced DNS security measures and a public security or incident response policy suggests room for improvement. No critical vulnerabilities were detected in the current analysis. Overall, Qwist presents a professional and trustworthy digital presence aligned with its market leadership in open finance. Strategic security enhancements and transparency in incident response would further strengthen its risk posture and customer confidence.

30
43
25
80
67
85
100
openfinanceb2b2xapiplatformpsd2digitallending+5 more
WordPressDivi ThemeYoast SEOCookiebot+8

Partner Domains:

finchcapital.com
partnerpending
finleap.com
partnerpending

+3 more partners

2025-06-14T18:16:42.373Z
if.ee favicon

If P&C Insurance AS

if.ee

68
FinanceEstonialargeMEDIUM

If P&C Insurance AS operates the website if.ee, providing a broad range of insurance products and services targeted at both private individuals and business clients in Estonia. The company offers various insurance types including vehicle, home, travel, accident, and pet insurance, positioning itself as a leading insurance provider in the Baltic region. The website is multilingual and designed to facilitate online insurance purchases and claims management, reflecting a mature digital business model. Technically, the site leverages Microsoft Azure DNS, Episerver CMS, and integrates advanced analytics tools such as Microsoft Application Insights and Google Tag Manager. However, the absence of a valid SSL certificate and lack of modern TLS protocols represent significant security weaknesses that could undermine user trust and data protection. The site demonstrates good compliance with GDPR and cookie regulations, including explicit cookie consent mechanisms and published privacy policies. Contact information is clearly provided, including a company email and phone number, alongside active social media channels. Overall, the website reflects a professional and comprehensive insurance service platform but requires urgent security improvements to ensure safe and trusted user interactions.

-
18
25
85
100
85
100
insurancekindlustusliikluskindlustuskaskokindlustuskodukindlustus+5 more
jQueryAzure DNSMicrosoft Application InsightsGoogle Tag Manager+4

Partner Domains:

if.lv
partner63
if.lt
partneranalyzing...
2025-06-14T17:37:00.752Z
if.lt favicon

If P&C Insurance AS filialas

if.lt

55
FinanceLithuanialargeMEDIUM

If P&C Insurance AS filialas operates the website if.lt, providing a wide range of insurance products including automobile, home, pet, travel, personal, and business insurance primarily targeting private individuals and businesses in Lithuania. The company is positioned as a leading insurance provider in the Baltic region, offering online services and customer self-service portals. The website is well-branded and provides comprehensive information about insurance products and customer support. Technically, the site uses a mix of technologies including jQuery, Microsoft Application Insights, OneTrust for cookie consent, and Google Tag Manager, hosted on Microsoft Azure DNS infrastructure. However, the website suffers from a critical security issue due to the absence of a valid SSL certificate and lack of modern TLS protocol support, which undermines secure communications and user trust. The site demonstrates good GDPR compliance with detailed privacy and cookie policies and active consent mechanisms. Performance is slow with a high page load time and large page size, but mobile optimization and accessibility are well addressed. Overall, the security posture requires urgent improvement to protect user data and maintain trust.

-
-
25
85
50
85
100
insuranceinsuranceproductsprivacycookieconsentgdpr+2 more
jQueryMicrosoft Application InsightsOneTrust Cookie ConsentGoogle Tag Manager+1

Partner Domains:

if.ee
sister68
if.lv
sister63
2025-06-14T17:37:00.728Z
brokernews.com.au favicon

KM Business Information Australia Pty Ltd

brokernews.com.au

65
FinanceAustraliamediumMEDIUM

Australian Broker News, operated by KM Business Information Australia Pty Ltd, is a specialized online media platform delivering mortgage industry news, insights, and premium content targeted at Australian mortgage brokers and finance professionals. The website serves as a leading source of industry updates, lender product news, and expert commentary, positioning itself as a trusted resource within the Australian finance sector. The business model revolves around content publishing, premium subscriptions, event coverage, and advertising revenue. Technically, the site leverages modern JavaScript libraries, Algolia search, and Google advertising technologies, hosted behind Cloudflare DNS services. However, the website exhibits a slow load time and lacks a valid SSL certificate, which impacts user trust and security posture. Security configurations include valid SPF and DMARC email protections but lack DNSSEC and modern TLS implementations. The absence of published security policies and incident response information indicates a gap in transparency and readiness. Overall, the site maintains good content quality and user experience but requires significant improvements in security and performance to enhance trust and compliance.

40
58
17
50
100
85
100
mortgagefinanceaustralianbrokernewsindustry+3 more
JavaScriptGoogle Tag ManagerAlgolia SearchInstantSearch.js+8

Partner Domains:

australianmortgageawards.com.au
partnerpending
keymedia.com
partner57
2025-06-14T17:36:55.983Z
mercadopago.com favicon

MercadoLibre S.R.L.

mercadopago.com

73
FinanceArgentinaenterpriseMEDIUM

Mercado Pago is a leading digital payments platform operating primarily in Latin America, with a strong presence in Argentina. It offers a comprehensive suite of financial services including digital accounts, prepaid Mastercard cards, money transfers, payment of services, loans, and seller tools such as Point devices and QR code payments. The platform is integrated with its parent company MercadoLibre, a major e-commerce player in the region, positioning Mercado Pago as a critical enabler of digital commerce and financial inclusion. Technically, the website leverages modern web technologies, including React-based frameworks, New Relic for performance monitoring, and Google Tag Manager for analytics and marketing. The SSL configuration is robust with a valid certificate and HSTS enabled, although DNSSEC is not enabled and CAA records appear misconfigured. No critical vulnerabilities were detected, but there is room for improvement in DNS security and explicit vulnerability disclosure. Overall, Mercado Pago demonstrates a mature digital infrastructure and a strong security posture, supporting its role as a trusted financial services provider.

70
25
25
100
100
90
100
financepaymentse-commercedigitalwalletfinancialservices+1 more
React (implied by nordic and pog-landings)New Relic monitoringIntersectionObserver for lazy loadingGoogle Tag Manager+6

Partner Domains:

mercadolibre.com
parentpending
adj.st
partnerpending
2025-06-14T13:25:02.684Z
solarisgroup.com favicon

Solarisbank AG

solarisgroup.com

72
FinanceGermanylargeMEDIUM

Solarisbank AG operates as a leading embedded finance platform in Europe, providing a comprehensive Banking-as-a-Service solution that enables businesses to integrate digital banking, payments, lending, and identification services via advanced APIs. The company holds a full German banking license, allowing it to operate across the EU with a strong compliance and regulatory framework. Solarisbank's market position is reinforced by partnerships with notable clients such as American Express and Tomorrow, and a clear focus on customer-centric financial product innovation. Technically, Solarisbank employs modern web technologies including React and Gatsby, hosted on AWS infrastructure, with a cloud-based banking platform emphasizing scalability and international expansion. The website demonstrates good performance, mobile optimization, accessibility, and SEO practices, supported by a robust API-driven backend. From a security perspective, Solarisbank maintains a valid SSL certificate, enforces HSTS with preload, and implements SPF DNS records. However, the absence of enabled TLS 1.2 or higher protocols and lack of DNSSEC and CAA records present areas for improvement. The company provides clear privacy policies, cookie consent mechanisms, and incident response contact channels, reflecting a mature security posture. Overall, Solarisbank presents a high-trust, professional digital presence with strong business and technical foundations. Strategic enhancements in security protocols and transparency around vulnerability disclosures would further strengthen its risk profile and customer confidence.

80
43
25
95
75
85
100
solarisbankbankbankingplatformdigital+6 more
ReactGatsbyRESTful APIsCloud-based infrastructure+1

Partner Domains:

whispli.com
serviceanalyzing...
americanexpress.com
partner72

+1 more partners

2025-06-14T13:03:15.572Z
volkswagen-versicherungsdienst.de favicon

Volkswagen Financial Services

volkswagen-versicherungsdienst.de

65
FinanceGermanyenterpriseMEDIUM

Volkswagen Financial Services AG operates the volkswagen-versicherungsdienst.de website, providing a comprehensive portfolio of automotive insurance products including liability, partial and full coverage, warranty extensions, leasing rate insurance, credit protection, and travel insurance. The site targets primarily German private and business customers, leveraging the strong Volkswagen brand and integrated financial services ecosystem. The website is built on Adobe Experience Manager with extensive use of modern web technologies and content delivery networks, ensuring excellent performance and user experience. However, the SSL configuration is critically flawed with a self-signed certificate and no enabled TLS protocols, which undermines secure communications. Security headers are well implemented, but the absence of a cookie consent mechanism and explicit security or incident response policies indicates gaps in compliance and transparency. The site integrates multiple marketing and analytics tools, including Adobe Analytics, Google Tag Manager, and UserZoom, reflecting extensive user tracking. Overall, the site is professional, content-rich, and trustworthy from a business perspective but requires urgent security improvements to protect user data and comply with best practices.

80
18
25
85
72
85
100
insuranceautomotiveleasingfinancingvolkswagen+5 more
Adobe Experience Manager (AEM)Adobe Launch (Tag Manager)Helix RUM (Adobe Helix Real User Monitoring)UserZoom (UX feedback tool)+7

Partner Domains:

volkswagenbank.de
partner69
vwfs.de
partner69

+2 more partners

2025-06-14T13:02:51.574Z
simplicitygroup.com favicon

Simplicity Group

simplicitygroup.com

62
FinanceUnited StateslargeMEDIUM

Simplicity Group is a leading financial services distribution partnership focused on providing advisors, financial institutions, and consumers with wealth accumulation and financial protection products. Founded in 2016, it has rapidly grown to become a prominent player in the financial services industry, leveraging a partnership and employee-ownership business model. The company offers a comprehensive suite of services including marketing, practice management, wealth management, and specialized financial education, targeting a broad audience from independent agents to banks and broker dealers. Technically, the website is built on WordPress with a modern theme and plugins, hosted on WP Engine and protected by Cloudflare CDN. The site employs Google Analytics, Tag Manager, and Pardot for marketing and analytics, and includes accessibility features. Security posture is solid with a valid SSL certificate and no known vulnerabilities, though it lacks modern TLS protocols and advanced DNS security features. Privacy and terms policies are comprehensive and prominently presented, supporting GDPR and CCPA compliance. Overall, the website reflects a mature digital presence with good user experience and trust indicators.

15
43
17
90
60
85
100
financefinancialserviceswealthmanagementholisticfinancialplanningprivacy+5 more
WordPressAvada themeRevolution SliderjQuery+12

Partner Domains:

leadersgroup.net
partnerpending
protectedtomorrows.com
partnerpending
2025-06-14T13:02:37.849Z
alipayplus.com favicon

Alipay+

alipayplus.com

69
FinanceN/aenterpriseMEDIUM

Alipay+ is a global digital payment platform operated by Ant International, providing cross-border mobile payment solutions and digitalization technologies to millions of consumers and businesses worldwide. The platform enables seamless payments via multiple e-wallets and banking apps, targeting global brands, mobile payment providers, and merchants. Their extensive partner ecosystem and large consumer base position them as a significant player in the financial technology sector. Technically, the website leverages modern web technologies including React and Next.js, hosted on Alibaba Cloud infrastructure with CDN acceleration, ensuring fast and mobile-optimized user experiences. Security posture is generally strong with valid SSL certificates, HSTS enabled, and no detected major vulnerabilities. However, the absence of TLS 1.2+ protocols and DNSSEC implementation are notable gaps. Privacy and cookie policies are present and appear GDPR compliant, but explicit security and incident response policies are not publicly disclosed. Overall, Alipay+ demonstrates a mature digital presence with strong branding, comprehensive service offerings, and a good security baseline, though some improvements in security protocols and transparency could enhance trust and compliance.

25
40
17
100
92
85
100
mobilepaymentcross-borderpaymentsdigitalwallete-walletfinancialtechnology+3 more
ReactNext.jsTengine web serverCDN (marmot-cloud.com)+4

Partner Domains:

antglobal.com
partneranalyzing...
antom.com
partneranalyzing...

+2 more partners

2025-06-14T12:59:58.749Z
V

Volkswagen Financial Services AG

volkswagen-bank.com

69
FinanceGermanylargeMEDIUM

Volkswagen Financial Services AG operates as the financial and mobility services provider for the Volkswagen Group across Europe, managing financing, leasing, insurance, and mobility solutions in 17 markets. The company holds a strong market position as a wholly-owned subsidiary of Volkswagen AG, with a large operational footprint and a focus on sustainability and customer mobility. The website reflects a professional and consistent brand presence with comprehensive investor relations and media content. Technically, the site is built on Adobe Experience Manager, leveraging modern content delivery and third-party integrations for analytics and marketing. Security headers and policies are well implemented, though some SSL/TLS configuration anomalies were detected, likely due to scanning artifacts or misconfigurations. Overall, the security posture is solid but could be improved by enabling modern TLS protocols and publishing explicit security policies. The site demonstrates good privacy compliance with a comprehensive privacy policy and consent mechanisms for external data sources. Social media presence and trust indicators support a high level of trustworthiness.

80
43
22
75
80
85
100
volkswagenfinancialservicessustainabilityinvestorrelationscareer+4 more
Adobe Experience Manager (AEM)Adobe Launch (Tag Manager)JavaScriptHelix RUM+7

Partner Domains:

vwfs.com
subsidiary73
volkswagenbank.de
subsidiary69

+1 more partners

2025-06-14T12:59:57.378Z