Skip to main content

Government security reports

Browse 7,671 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 9 of 154|Showing 401-450 of 7671
prerov.eu favicon

Statutární město Přerov

prerov.eu

62
GovernmentCzech RepublicmediumMEDIUM

Statutární město Přerov operates an official municipal website serving residents, tourists, and local businesses by providing comprehensive information about city governance, public services, news, and events. The site functions as a key communication channel for the city administration, offering online services such as payment portals, grant applications, and contact directories. The website is well-branded with consistent city identity and includes multilingual support via Google Translate. Technically, the website uses a custom CMS called Public4u, with common web technologies including jQuery, jQuery UI, and Swiper.js for UI components. The site is mobile-optimized and includes accessibility features at a basic level. Performance is moderate with no critical errors detected. Security is enforced via HTTPS, and cookie consent mechanisms are implemented to comply with GDPR requirements. Security posture is generally good, with no visible vulnerabilities or exposed sensitive data. However, the site lacks explicit security headers and dedicated incident response or vulnerability disclosure pages, which could be improved. WHOIS data is unavailable due to EURid privacy policies, but the domain is consistent with an official city domain, enhancing trustworthiness. Overall, the website presents a professional, trustworthy, and functional digital presence for the city of Přerov, with recommendations to enhance security headers, incident response transparency, and accessibility compliance to further strengthen its posture.

40
25
17
85
67
85
100
governmentmunicipalcitypublicservicesczechrepublic+5 more
jQueryjQuery UISwiper.jsCustom JavaScript+1

Partner Domains:

realitniweb.prerov.eu
partner
dotace.prerov.eu
partner

+3 more partners

2025-11-01T01:08:43.809Z
mesto-lipnik.cz favicon

Město Lipník nad Bečvou

mesto-lipnik.cz

50
GovernmentCzech RepublicsmallMEDIUM

Město Lipník nad Bečvou operates an official municipal website providing comprehensive information about the town, its governance, public services, events, and tourism. The site targets residents, visitors, and local businesses, serving as a central hub for municipal communication and community engagement. The business model is that of a government service portal, with a focus on transparency and accessibility. Technically, the website employs a mix of legacy and modern web technologies including jQuery 1.8.3, Bootstrap 4.3.1, Google Analytics, and Google reCAPTCHA for security. The CMS platform is Vismo, a specialized system for municipal websites. The site is mobile-optimized, accessible, and SEO-friendly, though some technology updates could improve security and performance. Security posture is solid with HTTPS enforced, reCAPTCHA on forms, and a cookie consent mechanism compliant with GDPR. However, the absence of explicit security headers and a vulnerability disclosure policy suggests room for improvement. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website is trustworthy, professional, and well-maintained, reflecting the legitimacy and stability of the municipal entity. Strategic recommendations include enhancing HTTP security headers, updating legacy libraries, and publishing a security policy or security.txt file to improve transparency and incident response readiness.

50
25
17
70
62
75
20
municipalgovernmentlocalgovernmentczechrepubliclipnknadbevou+4 more
jQuery 1.8.3Google AnalyticsGoogle Tag ManagerGoogle reCAPTCHA v2+4

Partner Domains:

info.mesto-lipnik.cz
partner
mesto-lipnik.munipolis.cz
partner
2025-11-01T01:08:33.782Z
finfoveskole.cz favicon

Finanční správa České republiky

finfoveskole.cz

61
GovernmentCzech RepubliclargeMEDIUM

The website finfoveskole.gov.cz is an official Czech government educational portal dedicated to supporting financial literacy and tax education for students and teachers. It is a collaborative project between the Financial Administration and Customs Administration of the Czech Republic, providing comprehensive information and resources related to taxes and customs. The site is well-structured, professionally designed, and targets primarily educational institutions and individuals seeking knowledge in financial matters. The presence of official government domains and partner links reinforces its legitimacy and authoritative position in the market. From a technical perspective, the website employs modern web technologies including HTML5, CSS3, JavaScript, Google Fonts, and integrates Cookiebot for cookie consent management and Matomo for privacy-conscious analytics. The site is mobile optimized, accessible, and demonstrates good SEO practices. However, there is no detected CMS or explicit hosting provider information. Performance is moderate, with room for optimization. Security posture is solid with HTTPS enforced and cookie consent mechanisms in place. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of security headers and explicit security or incident response policies publicly available suggests areas for improvement. The lack of WHOIS data is notable but likely due to registry policies for government domains rather than malicious intent. Overall, the website presents a low-risk profile with strong business credibility and privacy compliance. Strategic recommendations include enhancing security headers, publishing incident response and vulnerability disclosure policies, and improving transparency around contact information for security matters.

15
88
17
65
52
70
100
governmenteducationfinancialliteracytaxcustoms+3 more
HTML5CSS3JavaScriptGoogle Fonts (Roboto)+2

Partner Domains:

financnisprava.gov.cz
partner
celnisprava.gov.cz
partner

+1 more partners

2025-11-01T00:35:02.137Z
hsh-berlin.com favicon

HSH Soft- und Hardware Vertriebs GmbH

hsh-berlin.com

71
GovernmentGermanymediumMEDIUM

HSH Soft- und Hardware Vertriebs GmbH is a medium-sized German company specializing in software and hardware solutions for public administration, particularly in the government sector. Their offerings include a range of specialized software products such as MESO, GESO, AUSO, and biometric solutions like Biometric Go®, positioning them as a market leader in municipal resident registration software in Germany. The company actively participates in federal IT modernization initiatives, demonstrating a strong presence in the eGovernment domain. Technically, the website employs a modern but standard technology stack including jQuery and Bootstrap, with a custom CMS backend. The site is mobile-optimized and provides a good user experience with clear navigation and professional design. However, performance is moderate and accessibility features are basic. Privacy and cookie policies are implemented with GDPR compliance, but no direct contact emails or phone numbers are visible on the homepage. From a security perspective, the site lacks explicit security headers and there is no information about HTTPS or SSL configuration in the provided data. The presence of BSI-certified biometric software indicates some level of security awareness. The absence of WHOIS data for the domain is a concern, as it is inconsistent with the active and professional website presence, reducing overall trustworthiness. Overall, the website is professional and content-rich, serving a specialized government software market. The main risks relate to domain registration transparency and security header implementation. Strategic improvements in these areas would enhance trust and security posture significantly.

80
68
2
85
77
80
100
behrdensoftwaremeldeamtgewerbeamtsoftwareegovernment+5 more
jQueryBootstrapHTML5CSS3+1
2025-11-01T00:33:54.324Z
pet.dk favicon

Politiets Efterretningstjeneste

pet.dk

70
GovernmentDenmarklargeMEDIUM

Politiets Efterretningstjeneste (PET) is the Danish Security and Intelligence Service responsible for national security, counterterrorism, and intelligence operations within Denmark. The website serves as an official government portal providing information about PET's roles, recent news, recruitment opportunities, and security advice. It targets Danish citizens, government officials, and security professionals, offering authoritative content and resources. Technically, the website employs modern web technologies including AngularJS and Cookiebot for cookie consent management, alongside Google Maps API integration. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. However, some security headers are not detected, and DNSSEC is not enabled, indicating areas for security enhancement. From a security perspective, the site enforces HTTPS, uses CSRF protection tokens, and manages cookie consent in compliance with GDPR. No critical vulnerabilities or exposed sensitive data were identified. The domain registration is consistent with a legitimate government entity, with a long history dating back to 1997. Overall, PET's website demonstrates a strong security posture, good privacy compliance, and professional business credibility. Recommendations include enabling DNSSEC, adding security headers, and publishing explicit security policies or incident response contacts to further enhance trust and security transparency.

30
83
17
100
77
70
100
governmentsecurityintelligenceprivacycookie-consent+1 more
AngularJSjQuery Validation UnobtrusiveCookiebotGoogle Maps API
2025-10-31T23:41:11.486Z
politi.dk favicon

Politi (Danish Police)

politi.dk

51
GovernmentDenmarklargeMEDIUM

The website politi.dk is the official online presence of the Danish Police, providing comprehensive public services including crime reporting, legal information, news updates, and contact details for police stations across Denmark. It serves a broad audience of Danish residents and visitors seeking law enforcement information and services. The site is well-positioned as a national government authority with a large operational scope and a clear mission to serve public safety needs. Technically, the site employs modern web technologies such as AngularJS and jQuery, integrates Cookiebot for cookie consent management, and uses secure session management practices. The infrastructure supports mobile responsiveness and accessibility, ensuring a good user experience across devices. The presence of HTTPS and CSRF protection tokens indicates a solid security foundation. Security posture is strong with HTTPS enforced and cookie consent mechanisms in place, although DNSSEC is not enabled, which could be improved. No critical vulnerabilities or exposed sensitive data were detected. The site respects privacy regulations with a cookie consent banner and detailed cookie declarations, though a dedicated privacy policy page was not found in the analyzed content. Overall, politi.dk demonstrates a trustworthy, professional, and secure government website with good technical implementation and user experience. Strategic recommendations include enabling DNSSEC, verifying security headers, and publishing explicit privacy and security policies to enhance compliance and user trust.

-
-
-
85
67
70
100
governmentpolicelawenforcementpublicservicedenmark+3 more
AngularJSjQuery Validation UnobtrusiveCookiebotASP.NET (implied by ASP.NET_SessionId cookie)+4
2025-10-31T23:41:06.471Z
regeringen.dk favicon

Regeringen

regeringen.dk

58
GovernmentDenmarklargeMEDIUM

Regeringen.dk is the official website of the Danish government, serving as a primary platform for disseminating government news, speeches, publications, and information about ministers and government structure. It targets the general public, media, and stakeholders interested in Danish governmental affairs. The website is well-established with a domain age dating back to 1998, reflecting its longstanding role as an authoritative government source. Technically, the site employs modern web technologies including React and WebP images, with good mobile optimization and accessibility features. The CMS appears to be Umbraco, a common enterprise-level content management system. Performance is fast, and SEO practices are well implemented, though some security headers are missing. From a security perspective, the site uses HTTPS but lacks DNSSEC and visible security headers, which are recommended for enhanced protection. No privacy or cookie policies were found, indicating gaps in GDPR compliance. Contact information is limited but includes an official government email and physical address. No incident response or vulnerability disclosure information is provided. Overall, the website is professional, trustworthy, and serves its purpose effectively but would benefit from improved privacy compliance and enhanced security configurations to align with best practices.

30
10
17
100
77
55
100
governmentofficialnewsdanishgovernmentpublicinformation
JavaScriptCSSHTML5WebP images
2025-10-31T23:40:51.438Z
medjimurska-zupanija.hr favicon

Međimurska županija

medjimurska-zupanija.hr

43
GovernmentCroatiamediumHIGH

Međimurska županija operates as the official regional government entity for the Međimurje County in Croatia, providing a comprehensive digital platform for residents, businesses, and visitors. The website offers extensive information on local governance, administrative departments, EU-funded projects, transparency in budget and procurement, and public announcements. It targets local citizens, stakeholders, and tourists, positioning itself as a trusted source of regional governmental information and services. Technically, the website is built on WordPress 6.8.3 using the Oxygen Builder theme, integrating modern web technologies such as Google Fonts, Flickity carousel, and Google reCAPTCHA for security. The site demonstrates good mobile optimization, accessibility features, and SEO practices, although some minor improvements in security headers could enhance its posture. From a security perspective, the site enforces HTTPS, employs cookie consent mechanisms compliant with GDPR, and uses reCAPTCHA to mitigate automated abuse. No critical vulnerabilities or exposed sensitive data were detected in the HTML content. However, additional HTTP security headers and regular updates are recommended to maintain a robust security posture. Overall, the website presents a professional, trustworthy, and user-friendly interface consistent with government standards. It complies with privacy regulations and provides clear contact information, enhancing its credibility and user trust.

20
25
2
70
62
80
-
governmentregionalcroatiapublicservicestransparency+4 more
WordPress 6.8.3Google Fonts (Montserrat, Qwigley, Inter, Cardo)jQuery (commented out but referenced)Google reCAPTCHA+4

Partner Domains:

visitmedimurje.com
partner
transparentnost-mz.kipos.hr
partner

+1 more partners

2025-10-31T23:35:35.634Z
licko-senjska.hr favicon

Ličko-senjska županija

licko-senjska.hr

52
GovernmentCroatiamediumMEDIUM

Ličko-senjska županija is the official regional government entity for the Ličko-senjska County in Croatia. The website serves as the primary digital platform for disseminating public administration information, news, official documents, tenders, and transparency reports. It targets residents, businesses, and stakeholders within the county, providing comprehensive access to government services and updates. The site reflects a medium-sized government organization with a focus on regional development, public services, and community engagement. Technically, the website employs a modern tech stack including jQuery, Modernizr, Owl Carousel, and Google Fonts, built on a CMS platform by VIT. It is mobile-optimized, accessible, and SEO-friendly, with a moderate performance profile. Security is robust with HTTPS enforced and a Content-Security-Policy header, although some additional security headers could enhance protection. Privacy compliance is well addressed with clear cookie consent mechanisms and GDPR-aligned policies. The security posture is strong, with no detected vulnerabilities or exposed sensitive data. The site lacks a security.txt file and explicit incident response contacts, which are recommended for improved security transparency. The domain registration is consistent with the official government entity, enhancing trustworthiness. Overall, the website is professional, trustworthy, and well-maintained, serving its public sector role effectively.

35
25
17
85
62
85
20
governmentregionaladministrationpublicservicescroatialiko-senjskaupanija+2 more
jQueryModernizrOwl CarouselGoogle Fonts+1

Partner Domains:

lucka-uprava-novalja.com
partner
lucka-uprava-senj.hr
partner

+3 more partners

2025-10-31T23:35:30.620Z
dalmacija.hr favicon

Splitsko-dalmatinska županija

dalmacija.hr

56
GovernmentCroatiamediumMEDIUM

Splitsko-dalmatinska županija operates as the official regional government authority for the Split-Dalmatia County in Croatia, providing public administration, regional development, tourism promotion, and social services. The website serves as a comprehensive portal for citizens and stakeholders, offering news, public procurement information, official documents, and contact avenues. The organization maintains a consistent brand presence and leverages social media channels to engage with the public. Technically, the website is built on the DNN (DotNetNuke) CMS platform using ASP.NET WebForms, Bootstrap, and modern JavaScript libraries such as Swiper.js and Mmenu.js. It integrates Google Tag Manager, Google Analytics, and Facebook Pixel for analytics and marketing purposes. The site is mobile-optimized and demonstrates good SEO and accessibility practices, although some accessibility features could be enhanced. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms, but lacks explicit security headers and a published security policy or incident response contacts. No vulnerabilities or suspicious activities were detected in the content or scripts. The domain WHOIS data aligns with the official government entity, confirming legitimacy. Overall, the website presents a professional, trustworthy, and functional digital presence for the regional government, with room for improvement in security header implementation and incident response transparency.

15
10
17
65
77
85
100
governmentregionaladministrationcroatiapublicservicestourism+2 more
ASP.NET WebFormsjQueryBootstrapSwiper.js+5
2025-10-31T23:35:15.584Z
I

Industrie- und Handelskammer Siegen (IHK Siegen)

ihk-siegen.de

50
GovernmentGermanymediumMEDIUM

IHK Siegen operates as a regional Chamber of Industry and Commerce in Germany, providing a broad range of services including vocational training, business founding and succession consulting, international trade support, legal and tax advice, and environmental and energy consulting. The website serves as a comprehensive resource for local businesses, entrepreneurs, trainees, and regional economic stakeholders, reflecting a well-established institution with a strong market position in the South Westphalia region. The content is professionally presented, well-structured, and primarily in German, targeting a regional audience. Technically, the website is built on TYPO3 CMS, a mature and secure content management system. It integrates modern tools such as Usercentrics for cookie consent and eTracker for analytics, indicating a commitment to privacy compliance and user tracking transparency. The site is mobile-optimized and accessible, with good SEO practices evident. Hosting is managed via domaincontrol.com, a common provider for domain management. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms, but explicit security headers and incident response policies are not clearly published. No vulnerabilities or exposed sensitive data were detected in the analyzed content. The WHOIS data shows no privacy protection and is consistent with the domain's public institutional use, supporting legitimacy. Overall, the website demonstrates a strong business credibility and technical maturity with good privacy compliance. Recommendations include enhancing security headers, publishing a formal security policy and incident response contacts, and considering a vulnerability disclosure program to further strengthen trust and security posture.

55
28
22
60
67
65
20
ihkchamberofcommercevocationaltrainingbusinessconsultinginternationaltrade+4 more
TYPO3 CMSJavaScriptCSSUsercentrics (cookie consent)+1
2025-10-31T23:19:00.819Z
zielonagora.pl favicon

Urząd Miasta Zielona Góra

zielonagora.pl

60
GovernmentPolandmediumMEDIUM

The website www.zielona-gora.pl is the official online portal for the City Office of Zielona Góra, Poland. It serves as a government information hub providing residents, visitors, and businesses with access to city authorities, departments, local districts, public services, cultural events, and tourism information. The site is positioned as a trusted municipal government resource with clear branding and official social media presence. The business model is public service oriented, focusing on transparency and accessibility for the local community. Technically, the website is built on WordPress using the Avada theme, incorporating common plugins such as Contact Form 7, Cookie Notice, and WP Accessibility Helper. The site demonstrates moderate performance and good mobile optimization, with accessibility features implemented to support diverse users. SEO is basic but functional, and the site uses HTTPS with a valid SSL certificate ensuring secure communications. From a security perspective, the site enforces HTTPS and includes cookie consent mechanisms, but lacks advanced security headers and a dedicated security policy page. No vulnerabilities or exposed sensitive data were detected in the provided content. Privacy compliance is basic with a privacy policy present and GDPR considerations addressed. Contact information is clearly provided, enhancing trust and credibility. Overall, the website is a safe, legitimate government portal with a solid foundation but could benefit from enhanced security policies and technical hardening. The risk level is low, with recommendations focusing on improving security headers, incident response transparency, and privacy documentation to strengthen compliance and user trust.

65
25
2
70
67
75
100
governmentmunicipalcityportalpublicservicespoland+1 more
WordPressPHPjQueryOwl Carousel+4
2025-10-31T23:12:12.424Z
bundesjustizamt.de favicon

Bundesamt für Justiz

bundesjustizamt.de

11
GovernmentGermanylargeCRITICAL

The Bundesamt für Justiz (BfJ) is a large German federal government agency operating under the Federal Ministry of Justice. It serves as a central service provider for the justice system and international legal cooperation, offering a wide range of services including issuance of criminal records certificates, management of various legal registers, consumer protection, and judicial training. The website is professionally designed, accessible, and provides comprehensive information targeted at citizens, consumers, companies, courts, and authorities. Multilingual support and clear navigation enhance user experience. Technically, the site is built on the Government Site Builder CMS, uses modern web technologies including SVG graphics and JavaScript bundles, and is optimized for mobile devices. The presence of Matomo analytics indicates a privacy-conscious approach to user tracking. However, explicit security headers and cookie consent mechanisms are not evident, suggesting areas for improvement in security and privacy compliance. From a security perspective, the site uses HTTPS and does not expose sensitive data or vulnerable libraries. There is no visible incident response or vulnerability disclosure information, which could be enhanced to improve transparency and trust. The WHOIS data shows partial consistency with the official nature of the domain, and no suspicious patterns were detected. Overall, the website demonstrates a high level of professionalism, trustworthiness, and compliance with government standards, though it could benefit from enhanced security headers and explicit privacy consent mechanisms.

-
-
-
-
-
-
-
governmentjusticelegalgermanypublicservice+3 more
Government Site Builder CMSSVG graphicsResponsive CSS stylesheetsMatomo Analytics
2025-10-31T22:54:29.046Z
island.is favicon

Stafrænt Ísland

island.is

11
GovernmentIcelandlargeCRITICAL

Ísland.is is the official digital service portal for public entities in Iceland, providing citizens and businesses with centralized access to a wide range of government services and information. Established in 2002, it serves as the primary gateway for digital public services, offering life event management, user account services, and comprehensive information about various public sectors. The website is well-branded with consistent government identity and targets Icelandic residents and businesses seeking official services online. Technically, the site leverages modern web technologies including React and Next.js, hosted on AWS infrastructure, ensuring fast performance and excellent mobile optimization. Security posture is strong with HTTPS enforced and secure form practices, though some security headers are missing and cookie consent mechanisms are not implemented. Privacy policies are comprehensive and GDPR compliant, and minimal user tracking is performed via privacy-focused analytics. Overall, the domain registration and WHOIS data confirm the site's legitimacy as a government service portal. Strategic improvements include enhancing security headers, adding cookie consent, and publishing incident response contacts to further strengthen trust and compliance.

-
-
-
-
-
-
-
governmentpublicservicesdigitalportalicelandreact+3 more
ReactNext.jsToastifyAWS DNS

Partner Domains:

opnirreikningar.is
partner
tekjusagan.is
partner

+1 more partners

2025-10-31T21:25:49.791Z
vinnumalastofnun.is favicon

Vinnumálastofnun

vinnumalastofnun.is

67
GovernmentIcelandmediumMEDIUM

Vinnumálastofnun is an Icelandic government agency responsible for administering unemployment and parental leave benefits, as well as providing labor market information and advisory services to immigrants. The website serves as an official portal for these services, targeting individuals, employers, and immigrants within Iceland. It holds a strong market position as the official authority in its domain, with a history dating back to 2002. Technically, the website is built using modern web technologies including React and Next.js, hosted on AWS infrastructure. The site demonstrates good mobile optimization, accessibility, and SEO practices, although some minor improvements could be made in performance and security headers. Analytics are implemented via plausible.io, indicating a privacy-conscious approach to user tracking. From a security perspective, the site uses HTTPS and avoids exposing sensitive data in the HTML content. However, DNSSEC is not enabled, and no explicit security policies or vulnerability disclosure mechanisms are found. The WHOIS data confirms the domain's legitimacy and consistency with the claimed government entity. Overall, the website is professional, trustworthy, and serves its purpose effectively. Strategic recommendations include enhancing privacy compliance by publishing clear privacy and cookie policies, enabling DNSSEC, and adding security headers and incident response information to strengthen security posture.

75
50
17
65
72
80
100
governmentsocialwelfareunemploymentbenefitsparentalleaveiceland+1 more
ReactNext.jsAWS DNS hostingReadSpeaker webReader
2025-10-31T21:03:13.357Z
mesto-klimkovice.cz favicon

Město Klimkovice

mesto-klimkovice.cz

9
GovernmentCzech RepublicsmallCRITICAL

Město Klimkovice operates an official municipal website serving the local community in the Czech Republic. The site provides comprehensive information about city governance, public services, events, and practical information for residents and visitors. It maintains a clear and consistent brand presence with active social media links on Facebook and YouTube. The website is built on a CMS platform, likely Ocelot, and uses modern web technologies including jQuery and Bootstrap for responsive design. Navigation is well-structured, facilitating user access to a wide range of municipal resources. From a technical perspective, the site demonstrates moderate performance and good mobile optimization. However, there is no evidence of advanced security headers or detailed privacy policies, which are important for compliance and user trust. The cookie consent banner is implemented, indicating some level of privacy compliance. The absence of WHOIS data limits the ability to fully verify domain legitimacy, though the website content and official domain usage strongly suggest it is a legitimate municipal resource. Security posture is moderate; HTTPS is implied but no security headers were detected in the provided data. No vulnerabilities or exposed sensitive data were found, but improvements are recommended in security best practices and privacy disclosures. Overall, the website is functional and professional but would benefit from enhanced security and compliance documentation to strengthen trust and regulatory adherence.

-
-
-
-
-
-
-
municipalgovernmentczechrepubliclocalservicespublicadministration+2 more
jQueryBootstrap 4.4.1Highslide JSmmenu.js+1
2025-10-31T21:00:37.748Z
eiam.swiss favicon

Federal Office of Information Technology, Systems and Telecommunication FOITT

eiam.swiss

50
GovernmentSwitzerlandenterpriseMEDIUM

The website www.eiam.swiss serves as the official portal for the Swiss Federal Administration's central identity and access management system, eIAM. It provides a unified login infrastructure for federal web applications and native mobile apps, streamlining authentication processes and reducing costs. The site targets federal employees, IT specialists, application officers, integration managers, as well as citizens and business representatives via the CH-LOGIN service. The business model is a government service focused on secure, centralized identity management within the Swiss federal ecosystem. Technically, the website employs a traditional tech stack including jQuery and JavaScript, hosted likely on government infrastructure with a CMS identified as U5 CMS. The site is moderately optimized for performance and mobile use, with basic accessibility and SEO features. Security practices include HTTPS usage and no visible vulnerabilities, though security headers and explicit privacy/cookie policies are absent. From a security standpoint, the site demonstrates a solid posture consistent with government standards but lacks some modern security headers and explicit privacy compliance disclosures. The WHOIS data is privacy protected, which is typical for Swiss government domains, and does not detract from the site's legitimacy. No signs of malicious activity or vulnerabilities were detected. Overall, the site is trustworthy, professionally maintained, and serves a critical government function. Recommendations include enhancing privacy and cookie policy transparency, implementing security headers, and improving mobile and accessibility features to align with best practices.

30
35
17
55
72
75
40
governmentidentitymanagementaccessmanagementfederalswiss+3 more
jQueryjQuery FancyboxJavaScriptHTML5+1

Partner Domains:

www.bit.admin.ch
partner
www.bk.admin.ch
partner
2025-10-31T19:56:18.976Z
A

Ausgleichskasse Appenzell I.Rh.

akai.ch

53
GovernmentSwitzerlandsmallMEDIUM

The website www.akai.ch represents the Ausgleichskasse Appenzell Innerrhoden, a regional government social insurance institution in Switzerland. It provides essential social security services including old-age, disability, unemployment insurance, and family allowances. The site targets residents and businesses in the Appenzell Innerrhoden canton, offering information, forms, and e-portals related to social insurance. The business model is public sector focused, serving as a trusted intermediary for social insurance administration. Technically, the website is built on the Contao Open Source CMS platform, utilizing modern JavaScript libraries such as jQuery, Swiper, and Lottie for enhanced user experience. The site is mobile optimized with good navigation and SEO practices, though accessibility features are basic. Performance is moderate with no critical technical issues detected. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks important security headers and does not provide a privacy or cookie policy, which are compliance gaps. There is no visible incident response or vulnerability disclosure information. The WHOIS data aligns well with the website’s claims, indicating legitimacy and trustworthiness. Overall, the website is professional, trustworthy, and serves its public sector function well. Strategic improvements include adding privacy and cookie policies, implementing security headers, and publishing incident response contacts to enhance compliance and security posture.

80
35
2
55
72
80
20
socialinsurancegovernmentahvivalv+2 more
Contao Open Source CMSjQuery 3.7.1Swiper.jsFancybox+1

Partner Domains:

www.ahv-iv.ch
partner
www.arbeit.swiss
partner

+1 more partners

2025-10-31T19:56:03.942Z
vois.org favicon

VOIS

vois.org

10
GovernmentGermanymediumCRITICAL

VOIS is a German software provider specializing in modular solutions for municipal administration, focusing on integrating various specialized procedures into a unified platform. Their software targets a wide range of municipalities, from small villages to large data centers, aiming to improve citizen services and administrative efficiency. The website is professionally designed, primarily in German, and demonstrates a clear focus on government and public sector clients. Technically, the website is built on WordPress using the Elementor page builder, incorporating modern JavaScript libraries such as jQuery and Swiper.js. It employs Matomo analytics with a cookie consent mechanism, reflecting a privacy-conscious approach. The site is mobile-optimized and shows good SEO and accessibility practices, though some security headers are missing. From a security perspective, the site uses HTTPS with a good SSL configuration and no visible vulnerabilities or exposed sensitive data. However, the absence of explicit security policies, incident response contacts, and vulnerability disclosure mechanisms suggests room for improvement in transparency and security maturity. Overall, the domain WHOIS data is unavailable or privacy-protected, which is common for this business type but limits registration transparency. The website content and structure indicate a legitimate and professional operation with a moderate to good security posture. Strategic recommendations include enhancing security headers, publishing security and privacy policies, and improving contact transparency to strengthen trust and compliance.

-
-
-
-
-
-
-
municipalsoftwaregovernmentpublicadministrationintegrationonlineservices+3 more
WordPressElementorjQueryMatomo Analytics+2
2025-10-31T19:54:28.656Z
L

lutrija.hr

lutrija.hr

3
GovernmentCroatiamediumCRITICAL

The website www.lutrija.hr represents a Croatian government-related lottery entity, as indicated by the domain and WHOIS data. The domain is registered to S.H.O.P. CENTAR d.o.o. in Croatia since 2012, which aligns with the expected business age and legitimacy. However, the website content is currently inaccessible due to Incapsula Web Application Firewall (WAF) blocking, preventing any direct content or metadata analysis. This limits the ability to assess the website's privacy policies, contact information, or technical infrastructure in detail. From a technical perspective, the presence of Incapsula WAF suggests a focus on security and protection against attacks, but also restricts external analysis. No scripts, forms, or external links were extractable, and no security headers or SSL configuration details were available from the provided data. The domain's WHOIS data is consistent and transparent, supporting trustworthiness. Security posture cannot be fully evaluated due to the blocked content, but the use of a reputable WAF provider is a positive indicator. No vulnerabilities or compliance gaps could be identified. The website is presumed safe with no adult or questionable content based on the business sector and domain. Overall, the site appears legitimate and professionally managed but currently inaccessible for detailed analysis. Strategic recommendations include reviewing WAF settings to allow external security and compliance audits, publishing clear privacy and cookie policies, and providing accessible contact and incident response information to enhance transparency and trust.

-
-
-
-
-
-
-
2025-10-31T19:47:09.300Z