Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 52 of 166|Showing 2551-2600 of 8293
lamborghini.com favicon

Automobili Lamborghini S.p.A.

lamborghini.com

75
TransportationGermanylargeMEDIUM

Automobili Lamborghini S.p.A. is a globally recognized luxury automotive manufacturer specializing in high-performance sports cars and supercars. The official website serves as a comprehensive platform showcasing their product lineup, latest news, events, and dealer information, targeting affluent customers and automotive enthusiasts worldwide. The brand holds a premium market position under the Volkswagen Group umbrella, emphasizing exclusivity and innovation. Technically, the website leverages modern web technologies including React and Next.js frameworks, integrated with Google Tag Manager and New Relic for analytics and performance monitoring. The site demonstrates excellent mobile optimization, accessibility, and SEO practices, ensuring a smooth user experience across devices. Privacy compliance is robust, with clear cookie consent mechanisms and GDPR-aligned policies implemented via OneTrust. From a security perspective, the site enforces HTTPS with strong SSL configurations and employs standard security headers. While no explicit security policy or incident response details are publicly disclosed, no vulnerabilities or exposed sensitive data were detected. The WHOIS data is unavailable or privacy protected, which is typical for high-profile brands to mitigate spam and abuse risks. Overall, the website presents a secure, professional, and trustworthy digital presence aligned with Lamborghini's luxury brand image. Strategic recommendations include publishing detailed security policies, establishing a vulnerability disclosure program, and enhancing transparency around data protection officer contacts to further strengthen trust and compliance.

70
88
2
100
67
85
100
luxuryautomotivesportscarssupercarsbrand+4 more
ReactNext.jsGoogle Tag ManagerNew Relic+1
2025-10-11T08:28:51.798Z
zara.com favicon

ZARA

zara.com

67
RetailSpainenterpriseMEDIUM

ZARA is a leading global fashion retailer specializing in fast-fashion clothing, footwear, and accessories for men, women, and children. The website reflects a mature e-commerce platform with extensive international reach, supporting multiple languages and currencies. The brand is part of the Inditex group, a major player in the retail industry. The site is professionally designed with excellent content quality and user experience, targeting a broad general audience interested in fashion products. Technically, the website employs modern web technologies including React, JavaScript, and CSS, supported by analytics and marketing tools such as Google Tag Manager, Riskified, and OneTrust for cookie consent. The site is optimized for performance and mobile responsiveness, with good SEO and accessibility features. Security best practices are observed, including HTTPS enforcement, security headers, and obfuscation tools like Jscrambler. From a security perspective, the site demonstrates a strong posture with no visible vulnerabilities or exposed sensitive data. Privacy compliance is robust, featuring comprehensive privacy and cookie policies with consent mechanisms aligned with GDPR. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not publicly available, representing areas for improvement. Overall, the website presents a low-risk profile with high trustworthiness and professionalism. The absence of WHOIS data is noted but likely due to privacy protection common among large brands. Strategic recommendations include enhancing transparency around security policies and incident response to further strengthen user trust and compliance.

35
65
17
72
80
85
100
fashionretaile-commerceclothingfootwear+3 more
ReactJavaScriptCSSGoogle Tag Manager+3
2025-10-11T08:27:31.492Z
streamable.com favicon

Streamable Inc.

streamable.com

70
TechnologyN/amediumMEDIUM

Streamable Inc. operates a mature and well-established online video hosting and sharing platform, founded in 2003. The company targets a broad audience including businesses, content creators, and individuals, offering a freemium business model with advanced video editing and sharing tools. The platform supports multiple video formats and provides seamless upload and streaming experiences, positioning itself as a reliable and user-friendly service in the competitive video hosting market. Technically, the website is built on modern web technologies including React, integrates with major third-party services for analytics, marketing, and payments, and is hosted on Amazon AWS infrastructure, ensuring scalability and performance. Security posture is strong with HTTPS enforced, domain transfer protections, and bot mitigation via reCAPTCHA, although some security headers could be more explicitly implemented. Privacy compliance is well addressed with accessible privacy and cookie policies, and GDPR compliance indicators are present. However, explicit security policies and incident response contacts are not publicly disclosed. Overall, the website demonstrates high professionalism, trustworthiness, and technical maturity, with minor areas for security and compliance enhancement.

40
68
25
75
82
85
100
videohostingvideosharingvideoeditingonlinevideostreaming+2 more
ReactGoogle reCAPTCHAFacebook SDKStripe payment integration+3

Partner Domains:

streamyard.com
partner
streamable-support.zendesk.com
service
2025-10-11T08:24:55.776Z
caradvisor.at favicon

car.advisor

caradvisor.at

62
TransportationAustriamediumMEDIUM

car.advisor is an Austrian online review platform specializing in customer feedback and ratings for car dealerships representing major automotive brands such as Volkswagen, Audi, SEAT, CUPRA, Škoda, Volkswagen Nutzfahrzeuge, and Das WeltAuto. The platform targets both car dealerships and customers seeking trustworthy reviews to inform their purchasing decisions. The website demonstrates a solid market position within the Austrian automotive sector, focusing on transparency and customer satisfaction. Technically, the website is built using modern web technologies including React and Next.js, hosted on Azure CDN, ensuring fast performance and good mobile optimization. The site features structured data for SEO and brand consistency. However, there is room for improvement in accessibility and security headers implementation. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. Nonetheless, it lacks explicit privacy and cookie policies, security headers, and incident response contact information, which are critical for GDPR compliance and user trust. No vulnerability disclosure or security.txt files were found, indicating limited transparency in security practices. Overall, the website is professional and functional with a good business credibility score. Strategic enhancements in privacy compliance, security policies, and contact transparency would significantly improve its security posture and user trust.

15
68
2
70
82
80
100
automotivereviewscardealershipaustriavolkswagen+6 more
ReactNext.jsJavaScriptCSS+1
2025-10-11T08:24:25.525Z
tally.so favicon

Tally BV

tally.so

64
TechnologyBelgiummediumMEDIUM

Tally BV operates a modern, privacy-conscious online form builder platform accessible globally. Founded in 2020 and headquartered in Belgium, Tally offers a freemium SaaS model with a strong emphasis on unlimited free forms and submissions, advanced features like conditional logic, e-signatures, payments, and extensive integrations with popular productivity tools. The company positions itself as a user-friendly and GDPR-compliant alternative to traditional form builders, targeting creators, product teams, marketers, HR, and office users. The website is professionally designed, mobile-optimized, and rich in content, including testimonials and social proof, reinforcing its market credibility. Technically, the platform leverages modern web technologies including React and Next.js, hosted with Cloudflare DNS and integrated with Stripe for payments and automation platforms like Zapier, Make, and Pipedream. The site demonstrates good SEO, accessibility, and performance characteristics. Security practices are robust with HTTPS enforced, data encryption in transit and at rest, and hosting within the EU to comply with GDPR. However, there is room for improvement in publishing explicit security policies, incident response information, and enabling DNSSEC. The security posture is strong with standard security headers and privacy-friendly design, but lacks a dedicated vulnerability disclosure program and cookie consent mechanism. The WHOIS data aligns well with the business claims, showing consistent domain registration and no privacy protection, indicating transparency. Overall, the risk profile is low with no detected vulnerabilities or suspicious patterns. Strategic recommendations include enabling DNSSEC, publishing a formal security policy and incident response page, implementing a cookie consent banner, and establishing a vulnerability disclosure program to further enhance trust and compliance.

45
85
25
85
-
85
100
onlineformsformbuilderno-codefreeformsgdprcompliant+4 more
ReactNext.jsCloudflare DNSStripe+3

Partner Domains:

stripe.com
partner
zapier.com
partner

+3 more partners

2025-10-11T06:41:30.689Z
skoda-connect.com favicon

Škoda Auto a.s.

skoda-connect.com

9
TransportationUnited KingdomlargeCRITICAL

Škoda Connect is a digital platform operated by Škoda Auto a.s., a well-established automotive manufacturer under the Volkswagen Group umbrella. The website serves as a portal for connected car services and promotes the transition to the new MyŠkoda mobile app, enhancing the driving experience for Škoda vehicle owners. The platform targets Škoda customers primarily in the United Kingdom and provides access to service purchases via the Škoda Connect Shop and official retailer links. Technically, the website is built using modern web technologies including React and Next.js, ensuring a responsive and user-friendly experience. The site is moderately optimized for performance and mobile devices, with a clean design and clear navigation. However, some accessibility and SEO optimizations could be improved. No CMS or hosting provider details were explicitly identified. From a security perspective, the site uses HTTPS but lacks visible security headers and explicit incident response or vulnerability disclosure information. No WHOIS data was found for the domain, which is unusual and may indicate privacy protection or registration issues. Despite this, the website content and branding strongly suggest legitimacy as an official Škoda service portal. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website presents a professional and trustworthy front for Škoda's connected car services, though improvements in security transparency and domain registration clarity are recommended to enhance trust and compliance.

-
-
-
-
-
-
-
automotiveconnectedcarkodamobileappvehicleservices+1 more
ReactNext.jsJavaScriptWeb fonts (woff2)

Partner Domains:

shop.skoda-connect.com
partner
retailers.skoda-auto.com
partner

+2 more partners

2025-10-11T06:41:00.474Z
autohaus.at favicon

Autohaus Austria (implied from domain and content)

autohaus.at

10
TransportationAustriamediumCRITICAL

The website 'Suche Autohaus' serves as a comprehensive online directory for authorized car dealerships across Austria, representing multiple prestigious automotive brands including Volkswagen, Audi, Seat, Skoda, Cupra, Bentley, Lamborghini, Porsche, and Weltauto. It targets consumers seeking dealership locations, contact details, and brand-specific services, positioning itself as a niche regional platform within the automotive retail sector. The platform offers map-based search functionality and detailed listings, enhancing user convenience and market reach for dealerships. Technically, the site is built on modern web technologies such as React and Next.js, integrating Google Maps for location services and OneTrust for cookie management, indicating a moderate level of digital maturity. Performance and mobile optimization are adequate, though accessibility and SEO could be improved. Security-wise, the site enforces HTTPS and uses asynchronous script loading, but lacks explicit security headers and formal security policies, which are areas for enhancement. Privacy compliance is minimal, with no explicit privacy or cookie policies found, and no incident response or vulnerability disclosure mechanisms present. Overall, the site is professional and trustworthy but would benefit from improved privacy and security transparency to align with best practices.

-
-
-
-
-
-
-
automotivedirectorycardealershipaustriavolkswagen+7 more
ReactNext.jsJavaScriptGoogle Maps API+2
2025-10-11T06:40:30.322Z
porsche-holding.com favicon

Porsche Holding Salzburg

porsche-holding.com

69
TransportationAustriaenterpriseMEDIUM

Porsche Holding Salzburg is Europe's largest and most successful automobile trading company, founded in 1947 and operating in 29 countries across three continents. As a wholly owned subsidiary of Volkswagen AG, it focuses on distributing Volkswagen Group brands including Volkswagen, Škoda, SEAT, CUPRA, Audi, Lamborghini, Bentley, Ducati, and Porsche. The company offers a comprehensive range of services including automobile wholesale, retail, financial services, and IT systems, positioning itself as a key player in the automotive distribution sector. Technically, the website employs modern web technologies such as React and Next.js, with integrations for privacy management (OneTrust) and analytics (Google Tag Manager). The site is well-optimized for SEO and mobile devices, featuring a professional design and clear navigation. Security best practices are observed with HTTPS enforcement and appropriate security headers, although explicit security policies and incident response contacts are not published. The security posture is strong with no visible vulnerabilities or blocking mechanisms. Privacy compliance is robust, with comprehensive privacy and cookie policies and consent mechanisms in place. However, the absence of WHOIS data for the domain introduces some uncertainty regarding domain registration legitimacy, though the website content and external references strongly support its authenticity. Overall, Porsche Holding Salzburg's digital presence reflects a mature, professional, and secure corporate environment. Strategic recommendations include publishing explicit security policies, establishing a vulnerability disclosure program, and enhancing accessibility features to further strengthen trust and compliance.

75
80
17
70
52
75
100
automobilecorporatetransportationfinanceitsystems+2 more
ReactNext.jsOneTrustGoogle Tag Manager

Partner Domains:

porscheholding-newsroom.at
partner
2025-10-11T06:40:25.310Z
equally.ai favicon

Equally AI

equally.ai

61
TechnologyN/asmallMEDIUM

Equally AI is a technology company specializing in web accessibility compliance solutions, offering an all-in-one SaaS platform that helps businesses meet ADA, EAA, and WCAG standards. The company positions itself as a leader in accessibility compliance with a strong focus on AI-driven tools and services, including accessibility widgets, audits, VPAT documentation, and compliance verification. Their market presence is supported by positive user reviews and industry recognition badges, indicating a trusted and professional service provider. Technically, the website is built using modern frameworks such as Next.js and Material UI, with integrations of popular analytics and marketing tools like Google Tag Manager and Facebook Pixel. The site demonstrates excellent performance, mobile optimization, and accessibility features, reflecting a mature digital infrastructure. Security best practices are observed with HTTPS enforcement and security headers, although explicit security policies and incident response information are not publicly available. From a security perspective, the site shows a strong posture with no visible vulnerabilities or exposed sensitive data. However, the absence of a vulnerability disclosure policy and direct security contacts suggests room for improvement in transparency and incident readiness. The domain WHOIS data is privacy protected, which is typical for SaaS companies, and no suspicious patterns were detected, supporting the legitimacy of the business. Overall, Equally AI presents a professional, secure, and trustworthy web presence with a clear business focus on accessibility compliance. Strategic recommendations include publishing detailed security policies, adding vulnerability disclosure mechanisms, and providing direct security contact information to enhance trust and compliance further.

30
68
2
75
72
55
100
accessibilityadacompliancewcageaawebaccessibility+3 more
ReactNext.jsMaterial UIGoogle Tag Manager+3
2025-10-11T05:32:39.911Z
chase.com favicon

Chase

chase.com

56
FinanceUnited StatesenterpriseMEDIUM

Chase is a leading financial institution providing a wide range of banking and financial services including credit cards, mortgages, auto loans, investing, and business banking. The website serves both personal and business customers with a comprehensive digital platform that supports account management, payments, and financial planning. The brand is well-established with a strong market position as part of JPMorgan Chase & Co., one of the largest banking organizations in the United States. Technically, the website employs modern web technologies such as React and Next.js, ensuring a fast, responsive, and accessible user experience across devices. The site is well-optimized for SEO and includes comprehensive metadata and structured data to enhance search visibility. Security is robust with HTTPS enforcement, secure login forms, and multiple security headers implemented to protect users and data. From a security perspective, the site demonstrates strong best practices including secure forms, no exposed sensitive data, and use of security headers. However, the absence of a publicly visible vulnerability disclosure program and incident response contact details suggests areas for improvement. Privacy compliance is well addressed with clear privacy and cookie policies, including GDPR considerations. Overall, the website is professional, trustworthy, and secure, reflecting the stature of a major financial services provider. The WHOIS data anomaly does not detract from the legitimacy but should be further investigated to ensure domain registration transparency. Strategic recommendations include enhancing vulnerability disclosure visibility, maintaining security certifications, and continuous monitoring of third-party scripts.

-
-
-
85
82
90
100
bankingfinancecreditcardsmortgageautoloans+2 more
ReactJavaScriptWebpackNext.js+2

Partner Domains:

www.jpmorgan.com
parent
autofinance.chase.com
subsidiary

+2 more partners

2025-10-11T05:32:34.902Z
T

Thuisbezorgd

thuisbezorgd.nl

76
E-commerceNetherlandslargeLOW

Thuisbezorgd.nl is a leading Dutch online food and grocery delivery platform, founded in 2000 and operating under the parent company Just Eat Takeaway.com. The website offers a comprehensive range of services including takeaway food ordering, grocery deliveries, corporate ordering, and courier recruitment. It targets consumers in the Netherlands seeking convenient delivery options from over 15,000 restaurants and stores. The platform is well-positioned in the market with a strong brand presence and extensive service offerings. Technically, the website employs modern web technologies such as React and Next.js, supported by robust infrastructure likely hosted on cloud platforms. It integrates advanced analytics and marketing tools including Google Tag Manager, Snowplow, and Braze, reflecting a mature digital ecosystem. The site is optimized for performance, mobile responsiveness, accessibility, and SEO, providing an excellent user experience. From a security perspective, the site enforces HTTPS, implements key security headers, and follows best practices in form security and data protection. While no critical vulnerabilities were detected, the absence of a dedicated security policy page and security.txt file suggests room for improvement in transparency and incident response readiness. Privacy compliance is strong, with clear privacy and cookie policies and GDPR adherence. Overall, Thuisbezorgd.nl demonstrates a high level of professionalism, security, and compliance, making it a trustworthy platform for users. Strategic recommendations include enhancing security transparency, publishing a security.txt file, and maintaining vigilant third-party script management to sustain its strong security posture.

70
88
35
72
82
70
100
fooddeliverygrocerydeliverye-commercenetherlandsthuisbezorgd+1 more
ReactNext.jsJavaScriptCloudinary+5

Partner Domains:

justeattakeaway.com
parent
convercent.com
partner

+2 more partners

2025-10-11T04:25:42.097Z
getstream.io favicon

Stream

getstream.io

71
TechnologyN/aenterpriseMEDIUM

Stream is a technology company specializing in scalable APIs and SDKs for building in-app chat messaging, video, and activity feeds. Established in 2014, it serves a large enterprise market with over 1 billion end users and 2000+ apps relying on its platform. The company positions itself as a leader in developer experience and enterprise-grade infrastructure, offering high availability and compliance certifications such as HIPAA, GDPR, ISO 27001, and SOC 2. The website reflects a mature digital presence with modern frameworks and a strong focus on developer tools and integrations. Technically, the website is built using Next.js and React, hosted on AWS infrastructure, and leverages Prismic CMS for content management. It demonstrates fast performance, mobile optimization, and good SEO practices. The presence of Cookiebot indicates a commitment to cookie consent and privacy compliance, although explicit privacy and terms of service documents are not found in the provided content. From a security perspective, the site uses HTTPS with strong SSL configuration and displays multiple compliance certifications, indicating a robust security posture. However, there is room for improvement in publishing explicit security policies, incident response contacts, and vulnerability disclosure mechanisms. No critical vulnerabilities or suspicious patterns were detected. Overall, Stream presents a professional, trustworthy, and technically advanced platform with a strong market position in the developer tools space. Strategic recommendations include enhancing transparency around privacy and security policies and adding direct contact information to improve user trust and compliance.

65
65
17
85
77
75
100
chatvideoactivityfeedssdkapi+5 more
ReactNext.jsPrismic CMSAWS DNS+4
2025-10-11T04:21:55.869Z
libertyspecialtymarkets.com favicon

Liberty Specialty Markets

libertyspecialtymarkets.com

71
FinanceNetherlandslargeMEDIUM

Liberty Specialty Markets is a global specialty and commercial insurance and reinsurance provider operating across multiple key markets including the UK, Europe, Middle East, US, Bermuda, Asia Pacific, and Latin America. The company is part of the Liberty Mutual Insurance Group, a well-established insurance conglomerate. Their website reflects a professional and consistent brand image, targeting insurance brokers, corporate clients, and reinsurance partners. The business model focuses on underwriting specialty insurance products and reinsurance solutions, positioning itself as a significant player in the finance and insurance sectors. Technically, the website leverages modern web technologies such as React and Next.js, hosted on Akamai's CDN infrastructure, ensuring moderate to good performance and mobile optimization. The presence of multiple analytics and tracking tools like Google Tag Manager, Microsoft Clarity, and LinkedIn Insight indicates a mature digital marketing and analytics strategy. Accessibility and SEO are implemented at a basic to good level, with room for improvement. From a security perspective, the site enforces HTTPS with strong SSL configuration and implements key security headers, reflecting good security hygiene. The cookie consent mechanism demonstrates GDPR compliance awareness. However, the absence of explicit privacy policy, terms of service, security policy, and incident response contact information represents gaps in transparency and compliance documentation. Overall, the website is trustworthy and professional, with a strong business credibility score. The main risks relate to incomplete privacy and security policy disclosures, which should be addressed to enhance compliance and user trust.

80
88
2
40
100
75
100
insurancespecialtyinsurancecommercialinsurancereinsurancelibertymutual+2 more
ReactNext.jsGoogle Tag ManagerMicrosoft Clarity+2

Partner Domains:

libertymutual1.avature.net
partner
2025-10-11T03:16:55.181Z
D

Diligent Corporation

diligent.com

77
TechnologyN/aenterpriseLOW

Diligent Corporation is a leading enterprise software provider specializing in governance, risk management, and compliance (GRC) solutions. Positioned as a leader in the 2025 GRC MarketScape by IDC, Diligent offers a comprehensive AI-powered platform that centralizes board management, risk, audit, and compliance reporting. Their target audience includes corporate boards, governance professionals, and enterprise leaders seeking to elevate governance and clarify risk through modern technology. The company operates a sophisticated SaaS business model with a strong emphasis on security, privacy, and customer trust. Technically, the website is built on a modern stack including React, Next.js, and Material UI, hosted on Netlify. It integrates multiple analytics and marketing tools such as Google Tag Manager, Facebook Pixel, RudderStack, and Marketo, reflecting a mature digital marketing and data collection strategy. The site is well-optimized for performance, mobile responsiveness, accessibility, and SEO, providing an excellent user experience. From a security perspective, the site enforces HTTPS and maintains dedicated trust and security pages, including a vulnerability disclosure program. However, explicit security headers and a security.txt file are not detected, representing areas for improvement. The absence of WHOIS data is unusual but does not detract from the overall legitimacy given the professional presentation and trust signals. Overall, Diligent demonstrates a strong security posture and business credibility with comprehensive privacy compliance. The risk assessment indicates a low risk profile with recommendations to enhance transparency and security best practices further.

70
68
43
85
75
90
100
governanceriskmanagementcompliancegrcai+4 more
ReactNext.jsMaterial UIGoogle Tag Manager+6
2025-10-11T03:13:58.537Z