Skip to main content

Finance security reports

Browse 5,578 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

156451
Websites
130
Industries
113
Countries
52
Avg Score
Page 84 of 112|Showing 4151-4200 of 5578
pginkasso.ee favicon

PG Inkasso OÜ

pginkasso.ee

49
FinanceEstoniasmallHIGH

PG Inkasso OÜ is an Estonian private company specializing in debt collection and legal consulting services. The company positions itself as one of the largest players in Estonia's debt recovery market, offering both extrajudicial and judicial debt collection, legal advice, and client consultation. Their business model focuses on providing convenient and professional debt recovery services supported by qualified specialists and auditor-controlled financial processes. The website content is professionally presented and targets Estonian businesses and debtors needing collection services. Technically, the website uses a modern tech stack including Bootstrap, jQuery, and Google Analytics, hosted behind Cloudflare DNS and nameservers. The site is mobile optimized and has good SEO practices but lacks advanced accessibility features. The domain is very new (registered in 2024) which contrasts with the company's claimed founding year (2010), suggesting a recent domain acquisition or rebranding. From a security perspective, the site uses HTTPS and does not expose sensitive data or vulnerable libraries. However, it lacks DNSSEC, security headers, and any visible privacy or cookie policies, which are important for GDPR compliance and user trust. No incident response or vulnerability disclosure information is provided. Tracking is implemented via Google Analytics and Tag Manager without a visible consent mechanism. Overall, the website is functional and professional but could improve significantly in privacy compliance, security best practices, and transparency. The domain registration is consistent with the business location but the new domain age is a point to consider. Strategic improvements in security policies, contact information visibility, and compliance documentation are recommended.

15
10
2
60
65
65
100
inkassovladjuriidilineabidebtcollectionlegalservices+1 more
BootstrapjQueryGoogle AnalyticsGoogle Tag Manager+1

Partner Domains:

placetgroup.com
partner
laen.ee
partner

+3 more partners

2025-06-26T23:33:33.809Z
glimstedt.lv favicon

Glimstedt

glimstedt.lv

38
FinanceLatvialargeHIGH

Glimstedt is a well-established full-service sworn law firm specializing in business law, with a history dating back to 1935. The firm serves a diverse clientele including large foreign capital companies, medium and small enterprises, and private individuals. With 14 offices in Sweden and 3 in the Baltic states, Glimstedt operates an international team of 250 professionals, emphasizing collaboration and excellence. The website reflects this professional positioning with clear branding and relevant business content. Technically, the website is built on WordPress and uses modern JavaScript libraries such as jQuery and Modernizr. The site is mobile-optimized and performs moderately well, with proper SEO meta tags and Open Graph data. However, accessibility features are basic and could be improved. The site uses HTTPS with a good SSL configuration but lacks explicit security headers and visible privacy or cookie policies. From a security perspective, the site shows a good baseline with HTTPS and no exposed sensitive data. However, the absence of security headers, privacy policies, cookie consent mechanisms, and vulnerability disclosure information indicates room for improvement in compliance and security posture. No critical vulnerabilities or WAF blocking were detected, suggesting a stable but improvable security environment. Overall, the website is professional and trustworthy, reflecting the firm's reputable market position. Strategic recommendations include implementing comprehensive privacy and cookie policies, adding security headers, publishing incident response and vulnerability disclosure information, and enhancing accessibility and compliance features to strengthen trust and security posture.

15
10
2
70
62
70
-
lawfirmbusinesslawlatvialegalservicesprofessionalservices
jQueryModernizr

Partner Domains:

glimstedt.se
partner
glimstedt.ee
partner

+1 more partners

2025-06-26T23:30:43.165Z
T

The Options Clearing Corporation

theocc.com

52
FinanceUnited StateslargeMEDIUM

The Options Clearing Corporation (OCC) operates as a central counterparty clearing house based in Chicago, specializing in equity derivatives clearing and settlement services for the U.S. listed-options markets. It holds a unique market position as the sole entity clearing and settling every listed-options trade in the country, serving 16 exchanges. The website reflects a mature, large-scale financial institution with a focus on secure market operations, risk management, and member services. Technically, the website employs a modern technology stack including jQuery, Axios, Chart.js, Moment.js, Google Analytics, Google Tag Manager, and Microsoft Application Insights for telemetry. The site is well-structured, mobile-optimized, and demonstrates good SEO and accessibility practices. Performance is moderate, with no critical technical issues detected. From a security perspective, the site enforces HTTPS and uses secure analytics scripts, but lacks explicit published security policies, incident response contacts, and vulnerability disclosure mechanisms. No security headers were explicitly detected in the provided data, suggesting room for improvement. Privacy compliance is good with clear privacy and cookie policies, though no active cookie consent mechanism was found. Overall, the website presents a professional and trustworthy front for a critical financial market infrastructure entity. The absence of WHOIS data is a minor concern but likely due to query limitations or privacy services. Strategic recommendations include publishing formal security and incident response policies, implementing cookie consent mechanisms, and enhancing security headers to strengthen the security posture and compliance.

55
73
2
80
57
65
-
financeclearinghouseoptionsderivativesriskmanagement+1 more
jQuery 3.5.1Popper.js 1.9.9AxiosChart.js 2.7.3+4

Partner Domains:

infomemo.theocc.com
partner
marketdata.theocc.com
partner

+2 more partners

2025-06-26T23:28:32.855Z
moneyzen.ee favicon

Moneyzen

moneyzen.ee

56
FinanceEstoniasmallMEDIUM

Moneyzen is an Estonian-based online financial platform specializing in providing personal loans and investment opportunities through a transparent and empathetic approach. The platform targets individuals seeking flexible loan options and investment avenues, operating primarily in the Estonian market with multilingual support. The business model centers on connecting borrowers and investors, offering various loan types including personal, renovation, travel, health, auto, education, and refinancing loans. Despite recent challenges leading to the cessation of new loan and investment applications as of June 6, 2025, Moneyzen remains committed to servicing existing contracts and investor accounts. Technically, the website is built on WordPress using Elementor and Yoast SEO, integrating modern web technologies such as Google Tag Manager, reCAPTCHA, Hotjar, and Facebook Pixel for analytics and marketing. The site demonstrates good mobile optimization, SEO practices, and basic accessibility features. Security posture is strong with HTTPS enforced, security headers present, and no exposed sensitive data, although explicit security policies and incident response information are absent. Overall, Moneyzen presents a professional and trustworthy online presence with clear business information and contact channels. The domain registration aligns well with the business claims, enhancing legitimacy. However, improvements in privacy compliance documentation, security policy transparency, and incident response readiness are recommended to strengthen trust and regulatory adherence.

15
25
17
55
75
80
100
financeloansinvestmentestoniapeer-to-peerlending+1 more
WordPressElementorYoast SEOGoogle Tag Manager+5
2025-06-26T22:25:32.276Z
lei.fi favicon

LEI suomalaisille yrityksille

lei.fi

55
FinanceFinlandsmallMEDIUM

The website lei.fi provides a specialized online service for Finnish companies to apply for and renew Legal Entity Identifiers (LEI) quickly and reliably. The business is positioned as a niche provider focusing on the Finnish market with value-added services such as multi-year discounts and fast processing times. The company behind the domain is Computernik OÜ, an Estonian-registered entity, which aligns with the domain registration data and registrar information. The website content is professionally presented in Finnish, targeting local businesses needing LEI codes for financial transactions. Technically, the site is built on WordPress using a modern theme (GeneratePress) and common plugins for forms, social sharing, and table of contents. It leverages Cloudflare for DNS and uses Google Analytics for visitor tracking. The site is mobile-optimized and has good SEO practices with proper meta tags and structured data. However, some accessibility features are basic, and security headers are not explicitly detected. From a security perspective, the site uses HTTPS with a good SSL configuration and follows best practices such as opening external links with noopener. No critical vulnerabilities or exposed sensitive data were found. However, the absence of security headers and cookie consent mechanisms indicates room for improvement in compliance and security posture. No incident response or security policy pages are published, which could enhance trust. Overall, the website is legitimate, transparent, and well-aligned with its business purpose. The domain is newly registered but consistent with the business launch timeline. Recommendations include implementing cookie consent, adding security headers, publishing security policies, and enhancing contact options to improve user trust and compliance.

15
10
17
70
75
75
100
leileicodefinnishcompaniesfinancelegalentityidentifier+1 more
WordPressjQueryCloudflare DNSGoogle Analytics+4
2025-06-26T21:13:52.842Z
raison.app favicon

Raison FinTechnologies Inc.

raison.app

68
FinanceEstoniamediumMEDIUM

Raison FinTechnologies Inc. operates raison.app as a comprehensive digital family office platform offering investment opportunities across venture deals, public stocks, crypto-assets, structured products, and asset management services. The company targets both individual and institutional investors, providing tiered account plans and a broad range of financial instruments. With over 30,000 users globally and regulatory licenses from multiple jurisdictions, Raison positions itself as a trusted fintech innovator in the investment space. Technically, the website is built on a modern Nuxt.js and Vue.js stack, optimized for performance and mobile responsiveness. It integrates essential third-party services such as Google Tag Manager, reCAPTCHA, and Intercom for analytics, security, and customer engagement. The site demonstrates good SEO and accessibility practices, with comprehensive metadata and structured content. From a security perspective, the platform enforces HTTPS, employs security headers, and uses CAPTCHA to protect forms. It holds multiple financial regulatory licenses, enhancing trust and compliance. No critical vulnerabilities or exposed sensitive data were detected. However, explicit security policies and incident response information are not publicly detailed. Overall, raison.app presents a professional, secure, and user-friendly investment platform with strong regulatory backing and a clear business model. Strategic recommendations include publishing detailed security policies, adding vulnerability disclosure mechanisms, and enhancing transparency around data protection roles to further strengthen trust and compliance.

30
68
17
80
75
85
100
investmentfinancefintechventurecapitalcrypto+2 more
Vue.jsNuxt.jsGoogle Tag ManagerGoogle reCAPTCHA+3

Partner Domains:

publicreg.myafsa.com
partner
www.bvifsc.vg
partner

+3 more partners

2025-06-26T21:12:27.420Z
kreedix.ee favicon

Kreedix OÜ

kreedix.ee

69
FinanceEstoniamediumMEDIUM

Kreedix OÜ is an established Estonian company specializing in comprehensive credit management and debt collection services, operating since 2004. The company offers a full spectrum of services from sales credit management to cash collection, including credit ratings, debt portfolio analysis, and credit insurance. Kreedix holds a strong market position as a pioneer in the Estonian credit management sector, supported by partnerships with reputable finance and credit insurance companies such as Euler Hermes, Atradius, Coface, and EVUL. The website reflects a professional and consistent brand image targeting business clients requiring credit and debt management solutions. Technically, the website is built on WordPress using Elementor and Yoast SEO plugins, integrating modern web technologies such as Google Analytics and Google reCAPTCHA for security and analytics. The site is mobile-optimized with good SEO practices and moderate performance. Security posture is solid with HTTPS enforced and reCAPTCHA protecting forms, though some security headers could be improved. Privacy compliance is strong with a comprehensive privacy policy and cookie consent mechanism aligned with GDPR requirements. Overall, the security posture is good with no critical vulnerabilities detected, and the domain registration data supports the legitimacy of the business. The site does not show signs of blocking or WAF interference, allowing full content access. Strategic recommendations include enhancing security headers, publishing a security policy, and improving accessibility features to further strengthen compliance and user experience.

85
80
2
85
62
60
100
creditmanagementdebtcollectionfinanceestoniab2bservices+2 more
WordPressElementorYoast SEOGoogle Analytics+3

Partner Domains:

group.kreedix.ee
related
inforegister.ee
partner

+3 more partners

2025-06-26T17:43:31.707Z
M

meritaktiva.com

meritaktiva.com

43
FinanceEstoniamediumHIGH

Merit Aktiva operates as a provider of accounting software solutions, targeting companies seeking simplified accounting processes. With over 40,000 companies relying on their software and 25 years of experience, the company holds a solid market position primarily in Estonia and neighboring countries. The business model centers on delivering easy-to-use accounting software combined with customer support, catering to small and medium-sized enterprises in the finance sector. Technically, the website employs legacy technologies such as Bootstrap 3.3.7 and jQuery 1.8.3, indicating a need for modernization to improve security and performance. The site is moderately optimized for mobile and accessibility but lacks advanced SEO and modern frameworks. No CMS or hosting details were identified, and performance is assessed as moderate. From a security perspective, the site lacks visible security headers and privacy-related policies, which are critical for GDPR compliance and user trust. There is no evidence of HTTPS enforcement or incident response mechanisms. The absence of contact information and security disclosures further limits transparency. However, the domain WHOIS data aligns well with the business claims, supporting legitimacy. Overall, the website presents a functional but basic digital presence with room for significant improvements in security posture, privacy compliance, and technical modernization. Strategic enhancements in these areas will strengthen trust, compliance, and user experience.

15
35
2
60
77
75
20
accountingsoftwarefinanceestoniabusiness+1 more
Bootstrap 3.3.7jQuery 1.8.3jQuery Backstretch

Partner Domains:

merit.ee
partner
meritaktiva.fi
partner

+1 more partners

2025-06-26T16:38:36.115Z
luthor.ai favicon

Luthor, Inc.

luthor.ai

65
FinanceUnited StatessmallMEDIUM

Luthor, Inc. is a fintech company providing AI-powered fractional Chief Compliance Officer (CCO) services tailored for Registered Investment Advisors (RIAs) and broker-dealers. Their platform combines human expertise with automated workflows to help financial firms meet SEC and FINRA compliance obligations efficiently. Positioned as a modern RegTech solution, Luthor is backed by Y Combinator and trusted by firms managing over $6.8 billion in assets under management. Key services include compliance calendar management, automated filings, marketing compliance monitoring, and mock SEC exam preparation. Technically, the website is built on the Webflow CMS platform, leveraging modern web technologies such as Google Fonts, jQuery, and multiple third-party integrations for analytics and scheduling (Google Analytics, Apollo.io, SavvyCal, Cal.com, Koala). The site is well-optimized for performance, mobile responsiveness, and accessibility, with fast loading times and clear navigation. From a security perspective, the site enforces HTTPS with excellent SSL configuration and integrates several security best practices. However, some security headers like Content-Security-Policy and X-Frame-Options are missing, and there is no visible cookie consent mechanism, which impacts privacy compliance. The company is undergoing SOC 2 Type II certification, indicating a commitment to security and data protection. Overall, Luthor presents a professional, trustworthy online presence with strong business credibility and technical maturity. The lack of public WHOIS data is mitigated by other trust signals. Recommendations include enhancing security headers, implementing cookie consent for GDPR compliance, and publishing incident response contact information to further strengthen security posture and regulatory compliance.

30
53
25
75
72
80
100
aicompliancefinancesaasregtech+2 more
Webflow CMSGoogle Fonts (Inter)jQuery 3.5.1Google Tag Manager (gtag.js)+4
2025-06-26T15:29:16.179Z
propine.com favicon

Propine

propine.com

72
FinanceSingaporemediumMEDIUM

Propine is a Singapore-based enterprise-grade digital asset custodian specializing in custody, tokenization, trading, and DeFi solutions for institutional clients. The company holds a Capital Markets Services (CMS) license from the Monetary Authority of Singapore (MAS), positioning it as a trusted and regulated player in the digital asset custody market in Asia. Their platform targets banks, family offices, asset managers, corporates, exchanges, and protocol foundations, offering services such as Digital Custody ProTect™, Tokenization DASH™, and white label custody solutions. The website reflects a professional and consistent brand image with clear service offerings and a focus on institutional clientele. Technically, the website is built on WordPress using Elementor and several modern plugins like Yoast SEO and WP Rocket, hosted on AWS infrastructure. The site demonstrates good mobile optimization, SEO practices, and moderate performance. However, there is room for improvement in accessibility and security headers. The domain is mature, registered since 2001, and shows consistency with the business claims, enhancing trustworthiness. Security posture is solid with HTTPS enabled and domain transfer protections, but lacks DNSSEC and explicit security policies or incident response information. Privacy compliance is weak due to the absence of visible privacy and cookie policies or consent mechanisms. Contact information is primarily via forms, with no direct emails or phone numbers publicly listed. Overall, Propine presents as a credible and professional digital asset custody provider with a strong market position in Asia. Enhancing privacy compliance, security transparency, and adding direct contact channels would further strengthen trust and regulatory adherence.

55
70
47
85
52
85
100
digitalassetscustodytokenizationinstitutionalclientsfinance+3 more
WordPressElementorYoast SEOWP Rocket+3
2025-06-26T15:27:55.960Z
justpaid.ai favicon

JustPaid

justpaid.ai

69
FinanceN/asmallMEDIUM

JustPaid is a technology-driven SaaS company specializing in AI-powered revenue operations and billing automation. Their platform streamlines invoicing, payment collections, and customer communications, targeting financial experts, entrepreneurs, and accountants. The company is positioned as an innovative player in the finance technology sector, supported by Y Combinator backing, which enhances its market credibility. The website demonstrates a high level of professionalism, with comprehensive content and clear navigation, reflecting a mature digital presence. Technically, JustPaid leverages modern web technologies including Webflow CMS, Google Tag Manager, HubSpot, Hotjar, and various tracking and marketing tools. The site is mobile-optimized and performs moderately well, with good SEO and accessibility features. Hosting is provided by Webflow, a reputable platform for SaaS startups. From a security perspective, the site enforces HTTPS and employs standard marketing and analytics scripts. However, explicit security headers are not detected, and there is no public incident response or vulnerability disclosure information. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. The lack of exposed sensitive data and professional content supports a positive security posture. Overall, the risk assessment indicates a legitimate and trustworthy business with minor recommendations to enhance security headers and incident response transparency. The domain WHOIS data is privacy protected, which is typical for startups and does not raise immediate concerns. Strategic recommendations include improving security policy visibility, adding vulnerability disclosure, and enhancing trust signals through certifications or security frameworks.

60
68
2
80
72
85
100
aibillingautomationfinancesaasycombinator+2 more
WebflowGoogle Tag ManagerHubSpotHotjar+3

Partner Domains:

www.ycombinator.com
partner
2025-06-26T15:27:35.893Z
sprx.tax favicon

SPRX

sprx.tax

57
FinanceUnited StatesmediumMEDIUM

SPRX is a technology-driven company specializing in AI-powered software solutions for corporate tax incentives, specifically R&D tax credits, 179D deductions, and cost segregation. Their platform integrates with popular enterprise software to streamline data collection and uses AI to accelerate and improve the accuracy of tax credit claims. The company positions itself as a modern alternative to traditional tax firms by offering faster turnaround times and audit-ready reports, targeting medium-sized corporate clients primarily in the finance and technology sectors. Technically, the website is built on the Webflow CMS platform, leveraging modern web technologies including jQuery, Google Fonts, and Amazon Cloudfront CDN for performance optimization. The site is mobile responsive and well-structured with good SEO practices, though accessibility features are basic. No major technical issues or vulnerabilities were detected in the front-end code. From a security perspective, the site uses HTTPS with excellent SSL configuration but lacks visible security headers and published security policies. There is no evidence of privacy or cookie policies, which is a compliance gap especially for GDPR. The absence of WHOIS data limits domain trust verification, though the professional presentation and client testimonials provide positive trust signals. Overall, SPRX demonstrates a solid business and technical foundation with room for improvement in privacy compliance and security transparency. Strategic enhancements in these areas would strengthen trust and regulatory adherence.

30
35
2
70
57
85
100
aitaxcreditrdfinancetechnology+1 more
WebflowGoogle FontsjQueryJavaScript+1
2025-06-26T15:26:50.711Z
N

Nasdaq Baltic

nasdaqbaltic.com

67
FinanceEstonialargeMEDIUM

Nasdaq Baltic operates as the regional stock exchange platform for the Baltic countries of Estonia, Latvia, and Lithuania, providing trading services for shares, bonds, and funds. The website serves investors, companies, brokers, and advisers by offering real-time market data, news, and capital raising facilitation. It is part of the larger Nasdaq Inc. corporate group, reflecting a strong market position in the finance sector. The site is professionally designed with consistent branding and clear navigation, targeting financial market participants and stakeholders in the Baltic region. Technically, the website is built on WordPress with modern front-end technologies including Bootstrap, jQuery, Swiper.js, and Highstock for data visualization. It integrates Google Analytics and Tag Manager for user tracking and marketing insights. The site is mobile optimized and SEO friendly, with structured data enhancing search engine understanding. Hosting and domain registration are managed by reputable providers, ensuring stable infrastructure. From a security perspective, the site enforces HTTPS and employs domain status locks to prevent unauthorized changes. However, DNSSEC is not enabled, and no explicit security headers or incident response policies are published. Privacy compliance is well addressed with a comprehensive privacy policy and cookie consent mechanism. No critical vulnerabilities or exposed sensitive data were detected. Overall, Nasdaq Baltic's website demonstrates a mature digital presence with strong business credibility and good security hygiene. Strategic improvements could focus on enhancing DNS security, publishing formal security policies, and expanding incident response transparency to further strengthen trust and compliance.

80
80
2
40
77
75
100
financestockexchangebalticmarketinvestmenttrading
BootstrapjQuerySwiper.jsHighstock+3

Partner Domains:

nasdaqcsd.com
partner
business.nasdaq.com
partner
2025-06-26T15:26:25.604Z