Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157325
Websites
130
Industries
113
Countries
52
Avg Score
Page 97 of 101|Showing 4801-4850 of 5032
katapult.io favicon

Krystal Hosting Ltd

katapult.io

63
TechnologyUnited KingdommediumMEDIUM

Katapult, operated by Krystal Hosting Ltd, is a cloud infrastructure provider focused on delivering high-speed, reliable, and scalable virtual infrastructure solutions tailored for developers and teams. The company emphasizes ease of use, transparency, and sustainability, positioning itself as a competitive player in the cloud technology sector with a strong commitment to renewable energy and certified business practices. The website presents a professional and comprehensive overview of its services, targeting technology professionals and businesses seeking cloud infrastructure with pay-as-you-go pricing. Technically, the website is built on modern frameworks such as Next.js and React, with good mobile optimization and accessibility features. However, the site suffers from a critical security shortfall due to the absence of a valid SSL certificate, resulting in no HTTPS support. This significantly impacts the security posture and user trust. Privacy and cookie policies are well implemented with consent mechanisms, and the site uses Google Tag Manager for analytics and marketing. Security-wise, while no major vulnerabilities or exposed sensitive data were detected, the lack of HTTPS and security headers is a major concern. No explicit security or incident response policies are published, and no vulnerability disclosure or security.txt files are present. The domain registration data is consistent and mature, supporting the legitimacy of the business. Overall, Katapult demonstrates strong business credibility and technical maturity but must urgently address its SSL/TLS configuration to improve security and trust. Strategic recommendations include installing a valid SSL certificate, enabling security headers, and publishing security policies to enhance compliance and incident readiness.

90
25
25
50
100
85
100
cloudvirtualmachinesinfrastructuredeveloperspubliccloud+2 more
Next.jsReactGoogle Tag ManagerSVG icons+1
2025-06-15T11:49:43.430Z
guarantee.money favicon

ООО «Айкюсофт»

guarantee.money

65
FinanceRussiamediumMEDIUM

The website guarantee.money operates as an escrow service platform primarily targeting Russian-speaking users. It facilitates secure transactions between buyers and sellers by acting as a trusted third party holding funds in escrow until transaction conditions are met. The business is positioned as a medium-sized technology and finance service founded in 2017, with a focus on online marketplaces, arbitration, and payment link generation. The company behind the service is ООО «Айкюсофт», based in Russia. Technically, the site is built on a modern React and Next.js stack with Material-UI for UI components, indicating a contemporary digital infrastructure. However, the site suffers from a critical security shortcoming: the absence of a valid SSL certificate and proper HTTPS support, which undermines user trust and data security. While HSTS headers are configured, they are ineffective without valid SSL. Privacy and terms of service pages exist but cookie consent mechanisms are missing, indicating partial privacy compliance. Contact information is limited to an email address at iqsoft.company, with no phone or physical address provided. Overall, the site is functional and content-rich but requires urgent security improvements to meet industry standards and user expectations.

70
40
25
70
100
70
100
escrowsafetransactionssecurepaymentsarbitrationpaymentlinks+1 more
ReactNext.jsMaterial-UIJavaScript+1

Partner Domains:

iqsoft.company
partnerpending
2025-06-15T10:26:32.553Z
banqup.com favicon

Banqup Group

banqup.com

65
FinanceBelgiumenterpriseMEDIUM

Banqup Group operates a sophisticated digital platform focused on streamlining invoicing, payments, and compliance for a wide range of business customers including professionals, accountants, SMEs, and large enterprises. The company holds a strong market position in Europe, supported by its parent company Unifiedpost Group, and offers key services such as e-invoicing, compliance management, and integration with existing business software. The platform is designed to reduce administrative overhead and accelerate financial workflows. Technically, the website leverages modern web technologies including React and Next.js, with content managed via Storyblok CMS and hosted through a combination of Webflow and cloud services. While the site is content-rich and well-structured with good SEO and accessibility practices, performance is somewhat slow, and the SSL/TLS configuration is currently invalid, which poses a significant security risk. Security posture is moderate; the site employs HSTS and DMARC policies but lacks a valid SSL certificate and modern TLS support, which are critical for secure communications. Privacy compliance is strong, with a comprehensive privacy policy and cookie consent mechanism in place. Business credibility is high, supported by clear contact information, leadership announcements, and investor relations presence. Overall, Banqup presents a professional and trustworthy digital presence with room for improvement in security infrastructure. Addressing SSL/TLS issues and enhancing security headers would significantly improve the security posture and user trust.

50
25
25
85
97
80
100
financee-invoicingcompliancedigitalpaymentspeppol+1 more
ReactNext.jsWebflow (proxy-ssl.webflow.com TXT record)Google Tag Manager+2
2025-06-15T10:07:15.360Z
guggenheim-bilbao.eus favicon

FUNDACION DEL MUSEO GUGGENHEIM BILBAO

guggenheim-bilbao.eus

31
Non-profitSpainlargeHIGH

The Museo Guggenheim Bilbao is a prominent non-profit cultural institution based in Bilbao, Spain, managed by the FUNDACION DEL MUSEO GUGGENHEIM BILBAO. The website serves as a comprehensive portal for visitors to plan their visits, explore exhibitions, and access educational resources. It targets a broad audience interested in art, culture, and museum experiences. The museum holds a strong market position as an internationally recognized art venue with strategic partnerships and sponsorships from government and corporate entities. Technically, the website leverages modern web technologies including Next.js and React, with a headless WordPress CMS backend. It integrates accessibility tools and multimedia content hosted on Vimeo. The site is mobile-optimized and SEO-friendly, providing a good user experience and navigation clarity. From a security perspective, the site currently lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability impacting user trust and data security. Other security headers and best practices are partially implemented, but the absence of HTTPS significantly lowers the security posture. Overall, the website is professionally designed and content-rich, but the lack of HTTPS is a major risk. Strategic recommendations include immediate SSL/TLS deployment, enabling HSTS, and improving certificate management to enhance security and user trust.

15
25
25
50
50
70
-
museumartcultureeducationnon-profit+2 more
Next.jsReactJavaScriptVimeo (video hosting)+2

Partner Domains:

guggenheim.org
parentpending
guggenheim-venice.it
sisterpending
2025-06-15T09:03:17.984Z
sailpoint.com favicon

SailPoint Technologies, Inc.

sailpoint.com

71
TechnologyUnited StatesenterpriseMEDIUM

SailPoint Technologies, Inc. is a leading enterprise software company specializing in identity security solutions that help organizations manage and protect all types of enterprise identities. The company holds a strong market position with recognition from Gartner, KuppingerCole, and Frost & Sullivan, serving a global enterprise audience including many Fortune 500 companies. Their core offerings include Identity Security Cloud, IdentityIQ software, and advanced capabilities such as machine identity security and AI-driven automation through Harbor Pilot. The website reflects a mature digital presence with comprehensive content, multilingual support, and a professional design that targets security leaders and IT professionals. Technically, the website is built on modern frameworks such as Next.js and React, hosted on Vercel with Cloudflare CDN integration. It employs a variety of third-party marketing, analytics, and security tools including Google Analytics, Hotjar, Marketo, and Bugcrowd. While the site is mobile optimized and accessible, performance is moderate and could benefit from further optimization. The SSL configuration is currently invalid or missing, which is a critical security concern that impacts the overall security posture. From a security perspective, the site implements a robust Content Security Policy and several security headers but lacks full HSTS enforcement and OCSP stapling. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is well addressed with clear privacy and cookie policies and GDPR compliance indicators. Contact information is primarily provided via forms and external portals, with security-related contact emails identified. Overall, the website demonstrates a high level of professionalism and trustworthiness, supported by strong business credibility and industry recognition. However, the invalid SSL certificate is a significant risk that should be addressed promptly to maintain user trust and security integrity.

45
40
35
85
90
90
100
identitysecurityenterprisesecurityidentitygovernancecloudsecurityai-drivensecurity+2 more
ReactNext.jsVercel hostingCloudflare CDN+10
2025-06-15T07:17:28.725Z
cursor.io favicon

Cursor Inc.

cursor.io

53
TechnologyCanadasmallMEDIUM

Cursor Inc. is a Canadian-based web design and development company founded in 2018, specializing in delivering comprehensive digital services including strategy, design, development, marketing, and analytics. The company targets future-focused brands seeking innovative and transformative technology solutions. Their market position is that of a full-service digital agency with a focus on modern web technologies and user experience. The website content reflects a professional and consistent brand image with clear service offerings and a moderate social media presence. Technically, the site is built on modern frameworks such as React and Next.js, hosted on DigitalOcean, and uses Builder.io as a CMS. However, the website suffers from slow load times and lacks some accessibility features. From a security perspective, the site has critical issues including the absence of a valid SSL certificate, no HTTPS enforcement, and missing security headers, which significantly lowers its security posture. Privacy compliance is poor, with no visible privacy or cookie policies and no GDPR indicators. Contact information is limited to a contact form with no explicit emails or phone numbers. Overall, the site is functional and professional but requires urgent security and privacy improvements to enhance trust and compliance.

20
40
25
55
85
65
100
webdesignwebdevelopmentdigitalstrategymarketinganalytics+1 more
ReactNext.jsGoogle AnalyticsHelpScout Beacon+2
2025-06-15T07:13:12.858Z
spacelift.io favicon

Spacelift, Inc.

spacelift.io

62
TechnologyUnited StatesmediumMEDIUM

Spacelift, Inc. operates a mature and reputable infrastructure orchestration platform that integrates with popular infrastructure as code tools such as Terraform, OpenTofu, Ansible, and others. The company targets DevOps and platform engineering teams, offering a SaaS and self-hosted solution to streamline infrastructure provisioning, configuration, governance, and collaboration. The website reflects a strong market position with endorsements from notable customers and partners, emphasizing secure, cost-effective, and high-performance infrastructure delivery. Technically, the website is built on modern frameworks including Next.js and React, hosted on Vercel, and employs a variety of analytics and marketing tools such as Segment, Google Analytics, and HubSpot. The site is well-optimized for SEO, mobile responsiveness, and accessibility, providing an excellent user experience. However, the SSL certificate is currently invalid or misconfigured, and modern TLS protocols are not enabled, which impacts the security posture. Security-wise, the site implements several best practices including strict transport security headers, content security policies, and XSS protections. Despite this, the lack of a valid SSL certificate and absence of OCSP stapling are notable weaknesses. Privacy compliance is well addressed with clear privacy and cookie policies, including consent mechanisms, and GDPR compliance indicators. Overall, Spacelift demonstrates a strong business and technical foundation with minor security and compliance gaps. Addressing SSL issues and enhancing security configurations will further strengthen trust and protect user data.

75
43
25
50
50
85
100
infrastructureascodedevopsautomationterraformansible+4 more
ReactNext.jsVercelSegment+3

Partner Domains:

checkout.com
partner71
1password.com
partnerpending

+3 more partners

2025-06-15T07:09:40.464Z
grammarly.com favicon

Grammarly, Inc.

grammarly.com

76
TechnologyUnited StatesenterpriseLOW

Grammarly, Inc. is a leading technology company specializing in AI-powered writing assistance tools designed to improve clarity, tone, and correctness across multiple platforms and applications. With a strong market position serving over 40 million users and 50,000 organizations worldwide, Grammarly offers a subscription-based SaaS model with free and premium tiers tailored for individuals, teams, enterprises, and educational institutions. The company emphasizes responsible AI usage, data privacy, and security, positioning itself as a trusted partner in digital communication enhancement. Technically, Grammarly employs a modern web infrastructure leveraging Next.js, React, and Contentful CMS, hosted on AWS with robust multimedia content delivery. The website demonstrates good performance, mobile optimization, and accessibility, supported by comprehensive SEO and privacy compliance mechanisms including GDPR adherence and cookie consent management via OneTrust. From a security perspective, Grammarly maintains a strong posture with HTTPS enforced, OCSP stapling enabled, and no detected SSL vulnerabilities. However, improvements such as enabling HSTS, DNSSEC, and CAA records could further enhance domain security. The absence of exposed sensitive data and secure form handling practices contribute positively to the overall security maturity. Overall, Grammarly presents a low-risk profile with high business credibility, excellent content quality, and a well-implemented technical stack. Strategic recommendations include enhancing security headers, expanding incident response transparency, and continuous monitoring of privacy compliance to maintain trust and regulatory alignment.

70
43
25
80
97
85
100
protectedcontentaiwritingproductivityeducationenterprise
React (implied by _next.js chunks)Next.jsGoogle Tag ManagerOneTrust (cookie consent)+4

Partner Domains:

coda.io
subsidiary70
2025-06-15T06:07:33.094Z
k-auto.fi favicon

K-Auto Oy

k-auto.fi

40
TransportationFinlandlargeHIGH

K-Auto Oy is a prominent automotive company in Finland offering a comprehensive range of services including new and used car sales, leasing, financing, maintenance, and repair services. The company operates multiple dealerships across Finland and represents several major automotive brands such as Volkswagen, Audi, Porsche, SEAT, CUPRA, and Bentley. Their business model focuses on providing a seamless customer experience from vehicle acquisition to after-sales services, supported by digital tools and loyalty programs like Plussa. K-Auto is part of the larger Kesko Group, enhancing its market position and operational capabilities. Technically, the website is built on modern frameworks including Next.js and React, hosted via Cloudflare, and managed through the Contentful CMS. The site demonstrates good mobile optimization, accessibility, and SEO practices, although performance metrics are moderate. The presence of comprehensive legal and privacy documentation indicates a mature approach to compliance and customer trust. From a security perspective, while the site employs some security headers and uses HTTPS, the SSL certificate is currently invalid or missing, which is a critical vulnerability. The absence of DNSSEC and CAA records further indicates potential areas for security enhancement. No explicit incident response or vulnerability disclosure policies were found. Overall, K-Auto presents a professional and trustworthy digital presence with strong business credibility and customer focus. However, addressing the SSL certificate issues and enhancing security configurations are essential to maintain user trust and comply with best practices.

45
-
25
50
50
85
100
automotivecarsalesleasingfinancingcarmaintenance+1 more
Next.jsReactCloudflareWeb

Partner Domains:

kesko.fi
parent40
k-lataus.fi
partnerpending

+1 more partners

2025-06-14T22:44:37.875Z
cinfin.com favicon

Cincinnati Financial Corporation

cinfin.com

56
FinanceUnited StateslargeMEDIUM

Cincinnati Financial Corporation operates the website cinfin.com, providing a comprehensive range of personal and business insurance products through a network of independent agents. The company emphasizes personalized service, financial strength, and a relationship-driven business model. The website content is rich, professionally designed, and targets individuals, families, and businesses seeking tailored insurance solutions. The company has a strong market presence in the finance and insurance sector in the United States, with a history dating back to 1950 and multiple subsidiaries offering various insurance products. Technically, the website is built on a modern stack including React and Next.js, integrated with Sitecore CMS and OneTrust for cookie consent management. The site is mobile-optimized and SEO-friendly, though performance metrics were not available. However, the SSL/TLS configuration is critically deficient, with no valid certificate detected and no modern TLS protocols enabled, posing significant security risks. Security posture is weak due to the lack of HTTPS, which undermines user trust and data protection. While security headers are present, the absence of a valid SSL certificate and modern encryption protocols is a major vulnerability. Privacy compliance is well addressed with clear privacy and cookie policies, including GDPR considerations. Business credibility is high, supported by detailed company information, contact options, and trust signals such as testimonials and financial strength references. Overall, the website is a strong business asset but requires urgent remediation of its SSL/TLS security to protect users and maintain compliance. Strategic improvements in security and ongoing technical enhancements will strengthen the company's digital presence and trustworthiness.

70
43
25
50
50
85
100
insurancefinanceindependentagentsclaimsbusinessinsurance+1 more
ReactNext.jsSitecore Experience Accelerator (SXA)OneTrust (cookie consent)+4

Partner Domains:

taleo.net
partnerpending
2025-06-14T22:22:38.867Z
bluevine.com favicon

Bluevine Inc.

bluevine.com

59
FinanceUnited StateslargeMEDIUM

Bluevine Inc. operates a comprehensive business banking platform targeting small and medium-sized businesses, startups, and self-employed professionals in the United States. The company offers integrated financial products including business checking accounts, various types of business loans, credit cards, and invoicing/payment link solutions. Positioned as one of the largest small business banking platforms in the U.S., Bluevine emphasizes ease of use, lower fees, and access to working capital through partnerships with FDIC-insured banks and lending institutions. The website content is professionally designed, well-structured, and rich in relevant business information, targeting business owners seeking modern financial solutions. Technically, the site is built on a modern stack using Next.js and React, hosted on Netlify, and integrates multiple analytics and marketing tools. However, the security posture is weakened by the absence of a valid SSL certificate and disabled TLS protocols, which are critical for secure communications. Privacy compliance is well addressed with clear policies and consent mechanisms. Overall, Bluevine presents a credible and trustworthy business platform but must urgently address SSL/TLS issues to ensure secure user interactions.

80
43
25
50
50
90
100
businessbankingsmallbusinessfinancialtechnologybusinessloansbusinesschecking+3 more
Next.jsReactNetlifyStripe+5

Partner Domains:

coastalbank.com
partner59
celticbank.com
partneranalyzing...

+2 more partners

2025-06-14T22:16:37.654Z