Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 239 of 241|Showing 11901-11950 of 12038
johnsoncontrols.com favicon

Johnson Controls

johnsoncontrols.com

68
Building Automation and ControlsUnited StatesenterpriseMEDIUM

The website demonstrates a moderate security posture with no critical vulnerabilities found; however, several high and medium-risk issues significantly impact compliance and risk management. Key deficiencies exist in GDPR compliance, including the absence of privacy and cookie policies and lack of user consent mechanisms, exposing the business to regulatory penalties and reputational damage. The absence of a documented information security framework, incident response procedures, and security policies under NIS2 guidance further increases organizational risk and may hinder regulatory adherence. Security headers are inconsistently implemented, reducing protection against common web threats like XSS and content sniffing. SSL/TLS configurations are generally strong but require timely certificate renewal and elimination of mixed content to maintain secure communications. DNS settings are mostly healthy but can be improved by enabling DNSSEC to prevent domain spoofing. Positively, email and network security postures are robust, mitigating some external attack vectors. Overall, urgent attention to compliance and governance-related controls is critical to safeguard the business and maintain trust with users and regulators.

60
25
25
100
80
85
100
OpenBlueArtificial IntelligenceHealthy BuildingsAI in Building ManagementNet Zero Buildings+4 more
jQueryBootstrap 4Coveo SearchGoogle Maps API+15
2025-06-13T18:10:48.990Z
safinco.com favicon

SAFINCO

safinco.com

60
property management and legal servicesSpainmediumMEDIUM

The website's overall security posture reveals significant gaps, particularly in governance, privacy compliance, and essential security headers, exposing the business to regulatory risks and potential cyber threats. While there are no critical vulnerabilities, the presence of 11 high and 9 medium severity issues highlights urgent areas for remediation. Notably, missing privacy policies and consent mechanisms put the organization at risk of GDPR non-compliance, which could lead to costly fines and reputational damage. The absence of a formal information security framework, incident response procedures, and security policies under NIS2 requirements further exposes the business to operational disruptions and regulatory scrutiny. Security headers are inadequately configured, increasing exposure to web-based attacks like clickjacking and cross-site scripting. Additionally, the exposure of an FTP service represents a high-risk attack vector that could enable unauthorized access or data leakage. Overall, this assessment underscores the need for immediate governance improvements, privacy compliance actions, and technical hardening to safeguard the business and its customers.

35
25
17
80
87
85
85
property managementlegal servicesarchitectureSevillaadministradores de fincas+2 more
jQueryBootstrapFontAwesomeGoogle Analytics+4

Partner Domains:

megafincas-sevilla.com
partnerpending
tucomunidad.com
partnerpending
2025-06-13T18:10:48.927Z
andbank.com favicon

GROUP Andbank

andbank.com

45
bankingAndorralargeHIGH

The website's overall security posture is currently poor, with critical vulnerabilities that pose significant risks to both the business and its users. The absence of HTTPS encryption is a severe issue, exposing data in transit to interception and undermining compliance with GDPR and NIS2 regulations. Key security headers are either missing or weakly configured, increasing susceptibility to common web attacks such as clickjacking and content injection. Privacy compliance is lacking, with no privacy or cookie policies and no consent mechanisms, risking regulatory penalties and reputational damage. Additionally, the organization lacks foundational security governance, including incident response, security policies, and vulnerability disclosure procedures, which impairs its ability to manage and respond to threats effectively. Email security is moderately strong but could be improved with stricter DMARC enforcement and reporting. DNS security measures like DNSSEC are not enabled, reducing protection against DNS spoofing. Network security itself is well managed, indicating some internal controls are in place. Immediate remediation is critical to prevent data breaches, regulatory fines, and erosion of customer trust.

50
-
5
85
-
85
100
bankingprivate bankingasset managementfinancial servicesinvestment+1 more
WordPressYoast SEO PremiumSimple Google reCAPTCHAjQuery+12

Partner Domains:

andbank.com.br
subsidiarypending
andbank.es
subsidiarypending

+2 more partners

2025-06-13T18:10:48.109Z