Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157326
Websites
130
Industries
113
Countries
52
Avg Score
Page 103 of 103|Showing 5101-5140 of 5140
sosafe-awareness.com favicon

SoSafe

sosafe-awareness.com

70
TechnologyGermanylargeMEDIUM

SoSafe is a leading European provider specializing in security awareness training and human risk management solutions. The company offers a behavioral science-based platform that empowers organizations to enhance their cybersecurity posture by educating employees and managing human-related risks. Positioned as Europe's largest provider in this niche, SoSafe delivers personalized, gamified training, phishing simulations, an AI-powered chatbot, and a comprehensive human risk management platform. Their market presence is reinforced by multiple certifications including ISO 27001, TISAX, and GDPR compliance, alongside strong customer testimonials and industry recognitions. Technically, SoSafe's website is built on WordPress and integrates a robust set of analytics and marketing tools such as Google Analytics, Matomo, Cookiebot for consent management, HubSpot forms, and Visual Website Optimizer for A/B testing. The infrastructure is hosted on Amazon AWS with DNS managed via Route53. While the site supports modern TLS protocols and has valid SPF and DMARC records, it lacks DNSSEC, CAA records, and HSTS, which are recommended for enhanced security. The website performance is moderate to slow, with room for optimization. From a security perspective, SoSafe demonstrates good practices including strong SSL configuration, OCSP stapling, and comprehensive cookie consent mechanisms. However, there is no public vulnerability disclosure or security.txt file, and incident response contact details are not explicitly provided. The company maintains a strong security posture with certifications and compliance but could improve transparency and DNS security. Overall, SoSafe presents a mature digital presence with a focus on privacy and compliance, extensive integration with enterprise platforms, and a clear commitment to security awareness. Strategic improvements in DNS security and incident response transparency would further strengthen their security posture and trustworthiness.

75
43
25
87
72
85
100
securityawarenesshumanriskmanagementcybersecuritytrainingphishingsimulationsaichatbot+6 more
jQueryGoogle Tag ManagerGoogle AnalyticsMatomo Analytics+5

Partner Domains:

sosafe.de
servicepending
humanfirewallconference.com
partnerpending
2025-06-14T18:38:27.371Z
formalize.com favicon

Formalize ApS

formalize.com

79
TechnologyDenmarkmediumLOW

Formalize ApS is a Denmark-based technology company specializing in compliance software solutions designed to streamline governance, risk, and compliance operations for organizations. Their platform supports compliance with major regulatory frameworks such as NIS2, DORA, ISO 27001, and GDPR, offering customizable dashboards, automation, and a Trust Center for sharing compliance documentation. The company is positioned as a trusted provider with over 8,000 customers and strong partnerships with leading law and accounting firms. Technically, Formalize leverages modern web technologies including Alpine.js, AWS hosting, and integrates marketing and analytics tools such as Hubspot, Google Tag Manager, and Cookiebot for consent management. However, the website currently suffers from an invalid SSL certificate and lacks modern TLS protocol support, which poses a significant security risk. Despite this, the company demonstrates strong security practices with SPF, DMARC, and HSTS configurations, alongside certifications like ISO 27001 and ISAE 3000. Overall, Formalize presents a mature compliance platform with excellent user experience and comprehensive content, but should urgently address SSL and TLS issues to maintain trust and security.

95
58
30
85
100
85
100
compliancegovernanceriskmanagementprivacysecurity+6 more
Alpine.jsCloudflareAmazon SESGoogle Tag Manager+3

Partner Domains:

whistleblowersoftware.com
partner72
bdo.com
partnerpending

+3 more partners

2025-06-14T18:33:42.029Z
finstar.ch favicon

Finstar AG

finstar.ch

69
FinanceSwitzerlandmediumMEDIUM

Finstar AG is a Swiss-based company specializing in integrated IT solutions for private and universal banks as well as fintechs. With over 40 years of experience, the company offers customized and cost-effective banking software and services, positioning itself as a trusted partner in the financial technology sector. Their offerings include a broad range of products and services such as APIs, digital onboarding, and digital asset platforms, supported by a strong ecosystem of partner banks and financial institutions. The company is a subsidiary of Hypothekarbank Lenzburg AG and holds the prestigious 'swiss made software' label, underscoring its commitment to quality and reliability. Technically, the website is built on the Umbraco CMS and leverages modern JavaScript libraries including GSAP and ScrollMagic for enhanced user experience. It integrates Cookiebot for GDPR-compliant cookie consent management and Google Tag Manager for analytics and marketing. However, the website currently lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical security gap. Performance is slow, likely due to the large page size and resource count, but mobile optimization and accessibility are rated good. From a security perspective, the domain has well-configured SPF and DMARC records with a strict reject policy, reducing email spoofing risks. Despite this, the absence of HTTPS and security headers significantly lowers the security posture. No explicit security policy, incident response contacts, or vulnerability disclosure mechanisms were found. The cookie consent mechanism is comprehensive and transparent, supporting GDPR compliance. Overall, Finstar AG presents a professional and trustworthy digital presence with strong business credentials and compliance in privacy and cookie management. The primary risk lies in the lack of HTTPS, which should be addressed urgently to protect user data and maintain trust. Strategic improvements in security infrastructure and transparency around security policies would enhance the company's risk profile and customer confidence.

45
43
25
95
75
85
100
openbankingbankingsolutionsfintechintegrateditsolutionsswissmadesoftware+2 more
JavaScriptGoogle Tag ManagerCookiebotPhotoswipe+2

Partner Domains:

ersparniskassespeicher.ch
partnerpending
slwynigen.ch
partnerpending

+2 more partners

2025-06-14T18:32:03.834Z
foccolojas.com.br favicon

FoccoLOJAS

foccolojas.com.br

51
RetailBrazilmediumMEDIUM

FoccoLOJAS is a specialized software-as-a-service platform focused on providing comprehensive management solutions for furniture retail stores in Brazil. The company offers a 100% web-based system that integrates all store processes from customer entry to product delivery, aiming to increase sales efficiency and profitability. Their key services include sales management, budgeting and negotiation tools, client portfolio management, mobile applications for remote management, and business intelligence analytics. The business is positioned as a trusted partner for over 2,000 furniture stores nationwide, supported by a strong brand presence and customer testimonials. Technically, the website is built on WordPress with the Elementor framework, utilizing a variety of modern web technologies and third-party integrations such as Cloudflare for DNS and CDN services, Cookiebot for cookie consent management, and multiple analytics and marketing tools including Google Analytics, Hotjar, and Microsoft Application Insights. Despite a rich technology stack, the website suffers from performance issues due to a large number of resources and lacks a valid SSL certificate, which impacts security and user trust. From a security perspective, the site has implemented SPF for email protection but lacks DMARC, DNSSEC, and CAA records, and does not have a valid SSL certificate or HSTS enabled. The extensive use of third-party tracking and marketing scripts indicates a high level of user data collection, though managed through Cookiebot's consent mechanism. No explicit security policy, incident response, or data protection officer information is found, indicating potential gaps in formal security governance. Overall, FoccoLOJAS presents a mature business with a specialized market focus and a comprehensive digital presence. However, its security posture requires significant improvements, particularly in SSL/TLS configuration and formal security policies, to enhance trust and compliance. Performance optimization and clearer contact information would also benefit user experience and credibility.

30
25
17
85
50
75
60
furnitureretailmanagementsaasbrazil+5 more
WordPressElementorjQueryCloudflare+9

Partner Domains:

promob.com
partnerpending
compusoftgroup.com
partnerpending

+3 more partners

2025-06-14T18:30:14.673Z
hbl.ch favicon

Hypothekarbank Lenzburg AG

hbl.ch

67
FinanceSwitzerlandmediumMEDIUM

Hypothekarbank Lenzburg AG is a Swiss regional bank offering a hybrid model of digital and personal banking services targeting private and corporate customers. The website reflects a mature digital presence with comprehensive service offerings including e-banking, mortgages, savings, investments, and financial planning. The bank positions itself as a trusted regional financial institution with a focus on customer-centric solutions. Technically, the website is built on Umbraco CMS and leverages modern frontend libraries such as Swiper, GSAP, and Cookiebot for consent management. However, the current SSL/TLS configuration is invalid, which poses a significant security risk and undermines user trust. Security headers like SPF and DMARC are properly configured, but the absence of DNSSEC, CAA, and HSTS reduces the overall security posture. The site employs extensive tracking and advertising technologies including Google Analytics, TikTok, and Meta Platforms, with a robust cookie consent mechanism ensuring GDPR compliance. Overall, the bank demonstrates a strong market position with a professional and user-friendly website but must urgently address SSL/TLS issues to maintain security and trust.

45
43
25
70
100
85
100
bankingfinancedigitalbankinghypothekarbankswitzerland+3 more
Umbraco CMSGoogle Tag ManagerCookiebotjQuery (implied by plugins)+5

Partner Domains:

hblasset.ch
partnerpending
finstar.ch
partnerpending

+1 more partners

2025-06-14T18:22:14.104Z
saulesspektras.lt favicon

Saulės spektras, UAB

saulesspektras.lt

54
TechnologyLithuaniasmallMEDIUM

Saulės spektras, UAB is a Lithuanian digital marketing company specializing in providing digital marketing solutions for small and medium-sized businesses. Their offerings include website creation, SEO, SEM, and social media marketing services, supported by a network of business information portals. The company positions itself as a trusted partner in the Lithuanian market with certifications such as Google Partner and Duda Expert badges, indicating a strong commitment to quality and professionalism. Their target audience primarily consists of small and medium enterprises seeking to enhance their online presence and marketing effectiveness. Technically, the website is built on the Duda CMS platform, leveraging modern web technologies including Google Analytics, Google Tag Manager, and Cookiebot for privacy compliance. While the site demonstrates good mobile optimization and SEO practices, performance is somewhat slow due to a large page size and numerous resources. Security-wise, the site employs strong TLS protocols and has a valid SPF record, but lacks advanced security headers, HSTS, OCSP stapling, and DMARC, which are recommended for enhanced protection. Privacy and cookie policies are comprehensive and GDPR compliant, with an effective consent mechanism in place. Overall, the company maintains a solid digital infrastructure with room for security enhancements and performance optimization to further strengthen trust and compliance.

15
-
25
85
77
75
100
digitalmarketingseogoogleadsfacebookmarketingcookieconsent+3 more
Google AnalyticsGoogle Tag ManagerCookiebotjQuery+4

Partner Domains:

info.lt
partner47
statyba.lt
partnerpending

+3 more partners

2025-06-14T18:22:06.295Z
qwist.com favicon

Qwist GmbH

qwist.com

63
FinanceGermanymediumMEDIUM

Qwist GmbH is a leading open finance platform operating primarily in the DACH and Iberian markets, offering a comprehensive suite of B2B2X financial technology products. Their key offerings include digital account and portfolio switching, open banking compliance solutions, financial data analytics, and digital lending integration. The company positions itself as the #1 open finance company in its region, serving major banks and financial institutions with a strong investor backing from Finch Capital and Finleap. Technically, the website is built on WordPress with the Divi theme and leverages modern marketing and analytics tools such as HubSpot, Matomo, and SalesLoft. The site employs GDPR-compliant cookie consent via Cookiebot and maintains a valid SSL certificate, although some security enhancements like HSTS and DNSSEC are absent. Performance is moderate with good mobile optimization and SEO practices. From a security perspective, Qwist demonstrates solid foundational practices including SPF and DMARC email protections and encrypted communications. However, the absence of advanced DNS security measures and a public security or incident response policy suggests room for improvement. No critical vulnerabilities were detected in the current analysis. Overall, Qwist presents a professional and trustworthy digital presence aligned with its market leadership in open finance. Strategic security enhancements and transparency in incident response would further strengthen its risk posture and customer confidence.

30
43
25
80
67
85
100
openfinanceb2b2xapiplatformpsd2digitallending+5 more
WordPressDivi ThemeYoast SEOCookiebot+8

Partner Domains:

finchcapital.com
partnerpending
finleap.com
partnerpending

+3 more partners

2025-06-14T18:16:42.373Z
superfund.de favicon

Die neue Dimension der Geldanlage-Investieren in eine digitale Zukunft

superfund.de

51
financeGermanymediumMEDIUM

The website's security posture is currently weak, with significant deficiencies across multiple critical areas including privacy compliance, email authentication, and security policy frameworks. Critical gaps in GDPR adherence expose the business to regulatory penalties and reputational damage, especially given its EU operations without adequate privacy measures. The absence of key HTTP security headers leaves the site vulnerable to common web-based attacks such as clickjacking, content injection, and cross-site scripting. Email infrastructure lacks essential authentication mechanisms, increasing risks of phishing and email spoofing. Additionally, missing incident response and security documentation undermines the organization’s ability to detect, respond to, and recover from security incidents effectively. While SSL/TLS and DNS configurations are relatively stronger, urgent attention is needed to enable HSTS and extend certificate validity. Overall, this assessment reveals a pressing need to implement foundational security controls and compliance policies to safeguard the business and its customers. Failure to address these issues promptly could result in severe operational, financial, and legal consequences.

15
15
17
55
80
85
90
financeinvestmentdigital financecookie consent
JavaScriptCookiebotnginxJavaScript modules

Partner Domains:

superfundgroup.com
subsidiarypending
wirecard.com
paymentpending

+1 more partners

2025-06-13T18:13:49.869Z
edmond-de-rothschild.fr favicon

Edmond de Rothschild

edmond-de-rothschild.fr

49
banking and financial servicesFrancelargeHIGH

The website's overall security posture is critically deficient, primarily due to the complete lack of HTTPS encryption, which exposes all data transmissions to interception and undermines user trust. Compliance with GDPR is severely lacking, with missing privacy and cookie policies, absence of a consent banner, and inadequate privacy measures for EU users, creating significant legal and reputational risks. The NIS2 compliance score is extremely low, indicating insufficient organizational security frameworks, policies, and incident response readiness, which heightens vulnerability to cyber incidents and regulatory penalties. While network security and DNS health show relatively strong results, essential protections like DNSSEC are not fully implemented. Security headers are mostly present but missing critical components such as the X-XSS-Protection header. Email security has gaps with missing DKIM records, potentially impacting email deliverability and phishing protections. Immediate remediation is needed to address encryption, privacy compliance, and governance frameworks to safeguard user data, maintain regulatory compliance, and protect business continuity. Without urgent action, the organization risks data breaches, regulatory fines, and loss of customer trust.

85
-
5
85
-
85
100
bankingprivate bankingwealth managementinvestmentasset management+3 more
Google Tag ManagerCookiebotUmbraco EngageSVG graphics+3

Partner Domains:

edram.com
partnerpending
edmondderothschildheritage.com
subsidiarypending

+2 more partners

2025-06-13T18:10:48.117Z