Skip to main content

Low-risk security reports

Browse 2,880 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 1 of 58|Showing 1-50 of 2880
eversheds-sutherland.com favicon

Eversheds Sutherland

eversheds-sutherland.com

79
OtherN/aenterpriseLOW

Eversheds Sutherland is a prominent global law firm offering a wide range of commercial legal services to clients worldwide. The firm positions itself as purposeful and purpose-led, focusing on helping clients, employees, and communities thrive. Their website reflects a mature digital presence with comprehensive service descriptions across multiple sectors including banking, finance, construction, corporate law, and data privacy. The firm targets corporate and business clients seeking international legal expertise. Technically, the website employs modern web technologies such as React and integrates advanced analytics platforms including Piwik PRO, Siteimprove, and Demandbase. The site is well-optimized for mobile devices, accessible, and SEO-friendly, indicating a high level of digital maturity. Security best practices are observed with HTTPS enforcement and robust security headers, though explicit security policy and incident response information are not publicly detailed. From a security perspective, the site demonstrates a strong posture with no visible vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms, aligning with GDPR requirements. However, the absence of WHOIS registration data introduces a slight uncertainty in domain legitimacy, though the professional nature of the site and trust indicators mitigate concerns. Overall, Eversheds Sutherland's website is a secure, professional, and comprehensive platform that effectively supports its global legal services business. Strategic recommendations include publishing explicit security and incident response policies and improving transparency around domain registration details to enhance trust further.

100
88
47
70
62
85
100
globallawyersinternationallawfirmlegalservicesbankingandfinancedataprivacy+1 more
ReactJavaScriptPiwik PRO AnalyticsDemandbase+1
2026-08-18T07:08:12.404Z
bt.com favicon

BT Group plc

bt.com

78
TelecommunicationsUnited KingdomenterpriseLOW

BT Group plc is a leading UK telecommunications company offering a wide range of services including broadband, TV packages, mobile deals, and landline services. The website targets UK families, communities, and businesses, positioning itself as a comprehensive provider of digital connectivity and entertainment solutions. The company's market position is strong, supported by consistent branding and a professional online presence. Technically, the website leverages modern web technologies such as Next.js, Adobe Experience Manager, and integrates advanced analytics and consent management tools like Adobe Analytics, Dynatrace, and OneTrust. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. From a security perspective, the website enforces HTTPS, employs security headers, and uses reCAPTCHA v3 to protect forms. Consent management is robust, indicating compliance with GDPR. However, explicit security policies and incident response contacts are not publicly available, representing an area for improvement. Overall, the website is trustworthy, professionally maintained, and compliant with privacy regulations. The absence of WHOIS data is unusual but does not detract from the site's legitimacy given the brand recognition and content quality.

85
100
2
95
69
85
100
telecommunicationsbroadbandtvmobilesports+5 more
React (Next.js)Adobe Launch (Adobe DTM)Google reCAPTCHA v3Dynatrace+2

Partner Domains:

ee.co.uk
partner
player.ee.co.uk
partner

+1 more partners

2026-08-17T07:01:19.780Z
hds.com favicon

Hitachi Vantara LLC

hds.com

79
TechnologyUnited StatesenterpriseLOW

Hitachi Vantara LLC is a leading enterprise technology company specializing in sustainable IT solutions, data infrastructure, and hybrid cloud services. As a subsidiary of Hitachi Ltd., it holds a strong market position with a focus on green IT and eco-friendly technology offerings. The website reflects a mature digital presence with professional design, clear navigation, and comprehensive content tailored to enterprise clients and IT professionals. Technically, the site leverages Adobe Experience Manager, modern JavaScript libraries, and integrates marketing and analytics tools such as Marketo and Adobe Launch, indicating a high level of digital maturity. Security posture is robust with HTTPS enforcement, security headers, and privacy compliance mechanisms including GDPR-aligned policies and cookie consent banners. No critical vulnerabilities or exposed sensitive data were detected. However, WHOIS data is unavailable, which slightly impacts domain trust verification but does not detract from the overall legitimacy given the brand and technical sophistication. Strategic recommendations include publishing explicit security policies, adding vulnerability disclosure information, and enhancing incident response contact visibility to further strengthen trust and compliance.

75
88
55
85
62
80
100
greenitdatainfrastructurehybridcloudsustainabilityenterprisetechnology
Adobe Experience Manager (AEM)JavaScriptVideoJSMarketo+4

Partner Domains:

hitachi.com
parent
gartner.com
partner
2026-08-16T07:26:29.857Z
ncua.gov favicon

National Credit Union Administration

ncua.gov

81
GovernmentUnited StatesenterpriseLOW

The National Credit Union Administration (NCUA) is an independent U.S. federal government agency responsible for regulating federal credit unions, insuring deposits through the National Credit Union Share Insurance Fund, and protecting credit union members. The agency provides a broad range of services including regulatory supervision, consumer protection, financial data analysis, and support services to maintain the safety and soundness of the credit union system. The website serves as a comprehensive resource for credit unions, consumers, and stakeholders with extensive regulatory guidance, news, tools, and cybersecurity resources. Technically, the website is built on the Drupal CMS platform and employs modern analytics tools such as Google Tag Manager and Microsoft Clarity. The site is well-optimized for mobile devices, accessible, and features a professional design with clear navigation. While HTTPS is enforced and no sensitive data is exposed, the site lacks some security headers and a cookie consent mechanism despite using tracking scripts, which are areas for improvement. From a security perspective, the NCUA website demonstrates a solid posture with publicly available cybersecurity resources and incident reporting channels. The domain is a legitimate .gov domain with a long registration history and appropriate privacy protection. No critical vulnerabilities or suspicious content were detected. Overall, the site is trustworthy, authoritative, and serves its government regulatory function effectively.

80
53
87
85
77
80
100
governmentfinancecreditunionsregulationconsumerprotection+2 more
Google Tag ManagerMicrosoft ClarityDrupal CMSjQuery

Partner Domains:

mycreditunion.gov
partner
mapping.ncua.gov
partner

+2 more partners

2026-08-11T07:08:46.994Z
axway.com favicon

Axway

axway.com

76
TechnologyN/aenterpriseLOW

Axway is an established enterprise technology company specializing in data integration, API management, managed file transfer, and B2B integration solutions. The company targets large enterprises seeking to unlock and manage their data for new digital experiences and market opportunities. Axway positions itself as a key player in the hybrid integration platform market, offering comprehensive services to global customers. Technically, the website is built on Drupal 10, leveraging modern web technologies including Google Tag Manager and Cookiebot for consent management. The site demonstrates good mobile optimization, accessibility, and SEO practices, reflecting a mature digital infrastructure. The presence of extensive third-party marketing and analytics tools indicates a data-driven approach to customer engagement. From a security perspective, the website enforces HTTPS, employs standard security headers, and integrates cookie consent mechanisms aligned with GDPR requirements. However, there is no publicly available dedicated security policy or incident response contact information, which could be improved to enhance transparency and trust. Overall, the website is professional, content-rich, and trustworthy. The main risk factor is the absence of WHOIS data, which limits domain registration verification. This discrepancy should be investigated further to confirm domain legitimacy. Strategic recommendations include publishing explicit security and incident response policies and considering a vulnerability disclosure program to strengthen security posture and stakeholder confidence.

55
100
47
80
62
85
100
apigatewaymftservicesb2bsolutionsenterpriseintegrationhybridintegrationplatform
Drupal 10Google Tag ManagerCookiebotConvertexperiments+1

Partner Domains:

go2.axway.com
partner
74software.com
parent
2026-08-08T07:08:35.450Z
regencycenters.com favicon

Regency Centers

regencycenters.com

77
Real EstateUnited StateslargeLOW

Regency Centers operates as a prominent owner, operator, and developer of commercial real estate, specializing in retail shopping centers across the United States. The website reflects a professional corporate presence targeting investors, retailers, and business partners interested in commercial real estate opportunities. The business model centers on property ownership, management, and development services, positioning Regency Centers as a leader in the retail real estate sector. Technically, the website employs modern web technologies including FontAwesome for icons, Google Tag Manager for analytics, Cookiebot for cookie consent management, and Google reCAPTCHA for bot protection. The site demonstrates good mobile optimization and moderate performance, with a clean and professional design. However, no CMS or hosting provider information was discernible from the provided data. From a security perspective, the site enforces HTTPS and integrates standard security tools, but lacks visible security headers and published security policies such as vulnerability disclosure or incident response contacts. The absence of public WHOIS data and privacy policy reduces transparency and trustworthiness somewhat, though no critical vulnerabilities or exposed sensitive data were detected. Overall, Regency Centers' website is a solid corporate platform with good security fundamentals but could improve transparency and compliance by publishing privacy and security policies and providing clearer contact information. The domain WHOIS data absence warrants caution but does not alone indicate illegitimacy.

80
83
47
85
67
80
100
commercialrealestatepropertymanagementrealestatedevelopmentretailcenterscorporate
FontAwesomeGoogle Tag ManagerCookiebotVoiceflow Widget+1
2026-08-07T07:09:43.314Z
mathematica-mpr.com favicon

Mathematica

mathematica-mpr.com

78
GovernmentUnited StateslargeLOW

Mathematica is a well-established, employee-owned research and advisory firm specializing in evidence-based solutions that integrate data science, policy expertise, and technology to improve public well-being. The company serves a broad audience across public, private, and philanthropic sectors, focusing on analytics, data solutions, and research to support better decision-making and program outcomes. The website reflects a mature digital presence with comprehensive content, clear navigation, and professional branding consistent with its market position. Technically, the site leverages modern web technologies including jQuery, Modernizr, Google Tag Manager, and the Sitecore CMS platform, ensuring good performance, mobile optimization, and accessibility. The integration of Coveo search enhances user experience for content discovery. While performance is moderate, the site is well-structured and SEO optimized. From a security perspective, the site enforces HTTPS and employs domain status locks to protect domain integrity. However, DNSSEC is not enabled, and no explicit security policies or incident response contacts are published, representing areas for improvement. No vulnerabilities or suspicious content were detected. Privacy compliance is strong, with clear privacy and cookie policies and consent mechanisms in place. Overall, Mathematica's website demonstrates a high level of professionalism, trustworthiness, and digital maturity, supporting its role as a credible research and policy advisory organization.

85
85
17
80
82
85
100
employee-ownedresearchpolicydatascienceanalytics+2 more
jQuery 3.5.1Modernizr 3.6.0Google Tag ManagerCoveo Search UI+3
2026-08-07T07:02:35.477Z
manhattan-institute.org favicon

Manhattan Institute For Policy Research Inc

manhattan-institute.org

78
Non-profitUnited StatesmediumLOW

The Manhattan Institute is a well-established nonprofit public policy research organization founded in 1978 and headquartered in New York City. It focuses on advancing free-market policy ideas and the rule of law through research, commentary, and events across multiple policy areas including cities, culture, economics, education, governance, health, public safety, and technology. The organization maintains a strong market position as a respected think tank with a comprehensive digital presence and diverse content offerings such as publications, podcasts, and multimedia. Technically, the website is built on WordPress with a modern tech stack including Yoast SEO, Google Tag Manager, and various analytics and advertising tools. The site is mobile-optimized, accessible, and SEO-friendly, providing a professional user experience. Consent management is implemented via Osano, ensuring compliance with privacy regulations. From a security perspective, the site enforces HTTPS and uses reputable third-party scripts. While explicit security headers are not fully confirmed, the overall posture is good with no visible vulnerabilities or exposed sensitive data. However, the absence of a published security policy or incident response contact is noted as an area for improvement. Overall, the website is trustworthy, professionally maintained, and compliant with privacy standards. The domain WHOIS data is privacy protected but consistent with the organization's legitimacy. Strategic recommendations include enhancing security header implementation, publishing a security policy, and maintaining vigilance on third-party scripts.

95
58
35
85
82
85
100
policynonprofitthinktankpublicpolicyresearch+6 more
WordPressYoast SEOjQueryGoogle Tag Manager+6

Partner Domains:

city-journal.org
partner
adamsmithsociety.com
partner

+1 more partners

2026-08-05T07:10:37.327Z
baincapital.com favicon

Bain Capital

baincapital.com

77
FinanceUnited StatesenterpriseLOW

Bain Capital is a globally recognized private investment firm specializing in multi-asset alternative investments including private equity, credit, real assets, and venture capital. The firm operates on four continents with a strong emphasis on partnering differently to unlock opportunities and create lasting impact. Their market position is that of a leading enterprise in the finance sector, supported by a broad portfolio of subsidiaries and specialized investment platforms. Technically, the website demonstrates a mature digital infrastructure using modern web technologies such as Bootstrap, Font Awesome, and advanced JavaScript libraries. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a high level of digital maturity. Analytics and marketing tools like Google Analytics and Google Tag Manager are implemented responsibly with asynchronous loading. From a security perspective, the site enforces HTTPS and shows signs of good security hygiene, although explicit security headers and incident response policies are not publicly documented. No vulnerabilities or exposed sensitive data were detected. Privacy and cookie policies are present with consent mechanisms, indicating compliance with GDPR and related regulations. Overall, the website presents a low risk profile with strong business credibility and technical robustness. The absence of WHOIS data slightly reduces domain trust but is mitigated by the professional presentation and extensive subsidiary network. Strategic recommendations include enhancing security header implementation, publishing a security policy, and adding vulnerability disclosure information to further strengthen trust and compliance.

85
68
55
85
57
80
100
financeinvestmentprivateequityventurecapitalrealassets+2 more
Bootstrap 5.3.2Font Awesome 6.4.2Slick Carousel 1.8.1LightGallery.js+4

Partner Domains:

baincapitalprivateequity.com
subsidiary
baincapitaldoubleimpact.com
subsidiary

+3 more partners

2026-08-02T07:07:29.353Z
roc-search.com favicon

Roc Search

roc-search.com

79
TechnologyUnited KingdommediumLOW

Roc Search is a specialized recruitment agency focusing on STEM sectors including Technology, Engineering, Life Sciences, Energy, and the Public Sector. The company provides a range of staffing solutions such as contingent recruitment, retained search, embedded talent, and brand marketing services, positioning itself as a leading global partner for talent acquisition in these industries. The website reflects a professional and well-structured digital presence, targeting both candidates and clients with clear navigation and comprehensive resources. Technically, the website employs modern frameworks such as Bootstrap 5 and integrates advanced analytics tools including Google Analytics and Microsoft Clarity. The use of CookieYes for cookie consent demonstrates a commitment to privacy compliance. The site is mobile-optimized and accessible, with good SEO practices evident in metadata and structured navigation. From a security perspective, the site enforces HTTPS and uses cookie consent mechanisms effectively. However, some standard security headers like Content-Security-Policy, X-Frame-Options, and X-Content-Type-Options are missing, which could be improved to enhance protection against common web vulnerabilities. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website presents a low risk profile with strong business credibility and privacy compliance. The main concern lies in the absence of WHOIS data, which raises questions about domain registration transparency. This should be investigated further to ensure full legitimacy. Strategic recommendations include enhancing security headers, verifying domain registration details, and maintaining ongoing compliance with data protection regulations.

90
83
55
70
77
75
100
recruitmenttechnologyengineeringlifesciencesenergy+5 more
Bootstrap 5jQueryGoogle Tag ManagerGoogle Analytics+3
2026-07-26T07:12:42.541Z
C

Cellhire Ltd.

cellhire.co.uk

80
TelecommunicationsUnited KingdommediumLOW

Cellhire Ltd. is a medium-sized UK-based telecommunications company specializing in IoT solutions, mobile communications, eSIM, and data connectivity services targeted primarily at enterprise clients and indirect partners worldwide. The company positions itself as a leading global telecoms provider with a strong focus on innovation and customer-centric connectivity solutions. Their website reflects a professional and modern digital presence, showcasing multiple industry awards and a comprehensive portfolio of services including wholesale connectivity and satellite solutions. Technically, the website is built on modern frameworks such as Next.js and React, leveraging advanced analytics and marketing tools like Google Analytics, Bing Ads, and Demandbase. The site is well-optimized for performance, mobile responsiveness, and accessibility, with a robust cookie consent mechanism ensuring GDPR compliance. Security best practices are observed, including HTTPS enforcement and security headers, though explicit security policy and incident response information are not publicly detailed. The security posture is strong with no visible vulnerabilities or exposed sensitive data. However, the absence of WHOIS data for the domain raises some concerns about domain registration transparency, which slightly impacts the overall trust score. Despite this, the professional business presentation and consistent branding support the legitimacy of the company. Strategic recommendations include publishing a dedicated security policy, vulnerability disclosure program, and incident response contacts to enhance trust and compliance. Overall, Cellhire demonstrates a mature digital infrastructure and a solid market position in the telecommunications and IoT sectors, with room for improvement in transparency and security communication to stakeholders.

95
83
25
95
77
80
100
iottelecommunicationsconnectivityesimmobile+3 more
Next.jsReactFont Awesome 7Google Tag Manager+5

Partner Domains:

partners.cellhire.com
partner
simcontrol.cellhire.com
partner
2026-07-26T07:06:47.703Z
duffandphelps.com favicon

Kroll

duffandphelps.com

78
FinanceUnited StatesenterpriseLOW

Kroll is a leading independent provider of financial and risk advisory solutions, serving a broad range of corporate clients, financial institutions, legal professionals, and government agencies. The company leverages unique insights, data, and technology to address complex demands in financial advisory, risk management, cyber risk, and compliance. Their market position is strong as a trusted enterprise-level consultancy with a global presence. Technically, the website is built on modern frameworks such as Next.js and React, with integration of Google Tag Manager and OneTrust for consent management. The site demonstrates good performance, mobile optimization, and accessibility, reflecting a mature digital infrastructure. The use of structured data and comprehensive metadata supports SEO and content discoverability. From a security perspective, the site enforces HTTPS, implements multiple security headers, and uses consent management tools to comply with privacy regulations. However, the absence of a public security policy, incident response contact, and vulnerability disclosure reduces transparency. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website presents a professional, trustworthy, and compliant digital presence for Kroll. The main risk factor is the lack of WHOIS data, which slightly impacts domain trustworthiness but is mitigated by strong brand signals and content quality. Strategic recommendations include publishing security policies and incident response information to enhance trust and compliance visibility.

85
88
67
65
52
85
100
krollfinancialadvisoryriskadvisorycyberriskcompliance+2 more
Next.jsReactGoogle Tag ManagerjQuery 3.7.1+1
2026-07-23T07:12:48.578Z
nixonpeabody.com favicon

Nixon Peabody LLP

nixonpeabody.com

77
OtherUnited StatesenterpriseLOW

Nixon Peabody LLP is a large, global law firm offering sophisticated legal solutions to businesses across the United States, Europe, and Asia. With over 650 attorneys, the firm provides comprehensive legal services including corporate law, litigation, and regulatory compliance. The website reflects a professional and well-established business with a clear focus on serving corporate clients worldwide. The firm's market position is strong, supported by extensive practice areas and a global presence. Technically, the website is built on modern frameworks such as Next.js and React, ensuring fast performance, mobile responsiveness, and good accessibility. The site employs HTTPS with strong security headers, indicating a mature security posture. Privacy and cookie policies are present and comprehensive, demonstrating compliance with GDPR and other privacy regulations. However, explicit security policies and incident response information are not publicly available, which could be improved. Security-wise, the site shows good practices with no visible vulnerabilities or exposed sensitive data. The lack of WHOIS data is a concern for domain legitimacy and trust but does not detract significantly from the overall professional presentation. The site does not employ advertising or affiliate marketing, focusing solely on professional services. Overall, Nixon Peabody LLP's website is a high-quality, secure, and privacy-conscious platform that effectively supports the firm's business objectives. Strategic recommendations include publishing explicit security and incident response policies, adding vulnerability disclosure mechanisms, and ensuring WHOIS data is accurate and publicly available to enhance trust.

75
88
47
70
69
85
100
lawfirmlegalservicesbusinesscorporatelawglobal+1 more
Next.jsReactJavaScriptCSS
2026-07-22T07:22:46.407Z
B

BSI Group

bsigroup.com

77
OtherUnited KingdomenterpriseLOW

BSI Group, officially known as The British Standards Institution, is a globally recognized leader in standards development, certification, training, and consulting services. The organization focuses on helping businesses improve performance and achieve excellence, with a strong emphasis on sustainability. Their market position is reinforced by a long history of 125 years and a comprehensive portfolio of services including standards, assessment, certification, and software tools. The website reflects a professional and enterprise-grade digital presence, targeting businesses and organizations seeking compliance and quality assurance solutions. Technically, the website employs a modern technology stack including jQuery, Google Tag Manager, Google Analytics, Optimizely, and Salesforce Web-to-Case for customer engagement. The site is well-optimized for mobile devices, has good SEO practices, and integrates multiple marketing and analytics tools with user consent mechanisms. Performance is moderate, with room for optimization. From a security perspective, the site enforces HTTPS, uses CAPTCHA on forms, and implements cookie consent via OneTrust. While explicit security headers are not fully confirmed, the overall posture is strong with no visible vulnerabilities or exposed sensitive data. The absence of a public vulnerability disclosure policy is noted as an area for improvement. Overall, the website is trustworthy, professional, and compliant with privacy regulations such as GDPR. The missing WHOIS data is unusual but does not detract significantly from the site's legitimacy given the organization's reputation and branding. Strategic recommendations include enhancing security header implementation, publishing a vulnerability disclosure policy, and improving incident response contact visibility.

60
85
55
85
57
85
100
iso9001trainingcertificationstandardsuk+4 more
jQuery 3.5.1Google Tag ManagerGoogle Analytics (gtag.js)Optimizely+7
2026-07-21T07:17:15.971Z
O

Ondrives Ltd

ondrives.com

78
ManufacturingUnited KingdommediumLOW

Ondrives Ltd is a well-established UK-based manufacturer specializing in precision gears, gearboxes, and mechanical drive components primarily serving aerospace, defence, robotics, and advanced industrial sectors. The company emphasizes quality and reliability, supported by internationally recognized certifications such as AS9100D and ISO 9001:2015. Their website reflects a mature business with detailed product offerings, engineering capabilities, and a strong focus on technical excellence. Technically, the website is built on the nopCommerce platform with modern frontend technologies including Bootstrap and FontAwesome. It is mobile-optimized and provides a good user experience with clear navigation and comprehensive content. The site integrates external trusted domains for technical references and social media engagement but does not appear to use extensive tracking or advertising technologies. From a security perspective, the site uses HTTPS and implements basic security best practices such as anti-forgery tokens and cookie consent mechanisms. However, it lacks advanced security headers and does not publish a formal security policy or incident response contacts. The domain registration is consistent with the business claims, showing a long registration period and no privacy protection, which supports legitimacy. Overall, Ondrives.com presents as a professional, trustworthy, and technically competent website for a specialized manufacturing business. The security posture is solid but could be enhanced with additional headers and transparency around incident response. Privacy compliance is well addressed with GDPR-aligned policies and consent mechanisms.

90
95
17
85
67
85
100
manufacturingprecisiongearsaerospacedefencerobotics+4 more
nopCommerceBootstrapFontAwesomejQuery UI Autocomplete+2
2026-07-21T07:15:53.482Z
F

FTI Consulting

fticonsulting.com

80
OtherGermanylargeLOW

FTI Consulting is a global professional services firm with a strong presence in Germany, offering a broad range of consulting services including business transformation, restructuring, forensic investigations, compliance, cybersecurity, and ESG advisory. The company leverages over 20 years of global experience and a comprehensive network to support clients in managing complex business challenges. The website is professionally designed, localized for the German market, and provides clear navigation and detailed service descriptions, targeting corporate clients and enterprises. Technically, the website employs modern technologies such as JavaScript frameworks, Coveo search integration, Google Tag Manager, and OneTrust for cookie consent management. The CMS appears to be Sitecore, indicating a mature digital infrastructure. The site is mobile-optimized and accessible, with good SEO practices and performance. From a security perspective, the site uses HTTPS with integrity checks on scripts and includes reCAPTCHA for form protection. Cookie consent mechanisms comply with GDPR requirements. However, explicit security headers and a published security policy or incident response contacts are not evident, suggesting room for improvement in transparency and security posture. Overall, the website presents a trustworthy and professional image with moderate to high security and privacy compliance. The absence of WHOIS data slightly reduces trust but is mitigated by the professional content and company domain email contact. Strategic recommendations include enhancing security headers, publishing security policies, and providing incident response information to strengthen trust and compliance.

62
100
75
80
100
85
55
consultinggermanybusinesstransformationcybersecuritycompliance+2 more
JavaScriptCoveo SearchGoogle Tag ManagerOneTrust Cookie Consent+1
2026-07-17T07:19:29.075Z
elekta.com favicon

Elekta

elekta.com

79
HealthcareN/alargeLOW

Elekta is a leading medical technology company specializing in precision radiation medicine and cancer care solutions. The company offers a broad portfolio of products including adaptive radiotherapy systems, stereotactic radiosurgery, oncology software, brachytherapy, and neurosurgery equipment. With over 50 years of experience, Elekta positions itself as a pioneer in adaptive radiotherapy, aiming to make it the new standard of care in clinical practice. Their target audience primarily includes clinicians, cancer treatment centers, and healthcare professionals worldwide. Technically, the website demonstrates a mature digital infrastructure with modern technologies such as Matomo analytics, SVG graphics, and video content. The site is well-optimized for mobile devices and accessibility, featuring comprehensive metadata and structured data for SEO. The presence of cookie consent mechanisms and privacy policies indicates compliance with GDPR and other privacy regulations. From a security perspective, the site uses HTTPS and implements cookie consent banners, but lacks explicit security headers and a public incident response or vulnerability disclosure page. No vulnerabilities or exposed sensitive data were detected in the HTML content. The absence of WHOIS data reduces transparency but does not detract significantly from the site's legitimacy given the professional presentation and corporate governance disclosures. Overall, Elekta's website reflects a high level of professionalism, technical competence, and compliance awareness, supporting its position as a trusted provider in the healthcare technology sector.

85
82
100
85
95
17
83
healthcareradiotherapycancercaremedicaltechnologyoncology+1 more
Matomo analyticsVidyard video playerWebP imagesCSS with integrity attributes+2

Partner Domains:

community.elekta.com
partner
ir.elekta.com
partner
2026-07-16T07:20:13.582Z
cibc.com favicon

Canadian Imperial Bank of Commerce

cibc.com

77
FinanceUnited StatesenterpriseLOW

CIBC U.S. operates as a subsidiary of the Canadian Imperial Bank of Commerce, providing a comprehensive suite of commercial and personal banking services, wealth management, and small business financial solutions tailored for the U.S. market. The website reflects a strong market position as part of one of Canada's Big Five banks, targeting a broad audience including individuals, businesses, and investors. The business model focuses on client-centric financial services with an emphasis on trust and long-term relationships. Technically, the website leverages modern web technologies including Adobe Experience Manager CMS, Adobe Launch for tag management, and OneTrust for cookie consent, indicating a mature digital infrastructure. The site is hosted on Akamai's CDN, ensuring fast performance and global availability. Accessibility and SEO best practices are well implemented, with responsive design and structured data enhancing user experience and search visibility. From a security perspective, the site enforces HTTPS, employs multiple security headers, and integrates secure sign-on portals for various banking services. While explicit security policies and incident response contacts are not published, the overall posture is strong with no visible vulnerabilities or exposed sensitive data. Privacy compliance is robust, with clear privacy and cookie policies aligned with GDPR requirements. Overall, the website demonstrates a high level of professionalism, security, and compliance suitable for a major financial institution. Strategic recommendations include publishing detailed security policies, vulnerability disclosure information, and incident response contacts to further enhance transparency and trust.

90
85
100
82
80
73
17
bankingfinancecommercialbankingpersonalbankingwealthmanagement+4 more
jQueryAdobe Launch (Adobe DTM)Adobe Helix RUMOneTrust Cookie Consent+1

Partner Domains:

cibc.com
parent
online.us.cibc.com
subsidiary

+2 more partners

2026-07-16T07:17:09.018Z
hsbc.com favicon

HSBC Holdings plc

hsbc.com

78
FinanceUnited KingdomenterpriseLOW

HSBC Holdings plc operates as one of the world's largest banking and financial services organizations, serving millions of customers globally through its four main business lines: Retail Banking and Wealth Management, Commercial Banking, Global Banking and Markets, and Global Private Banking. The company maintains a strong market position with a legacy dating back to 1865 and a significant presence in key financial markets. The website reflects this stature with comprehensive investor relations, corporate governance, and sustainability information targeted at investors, customers, and partners. Technically, the HSBC website employs modern JavaScript libraries such as VideoJS and Tealium for tag management and analytics, indicating a mature digital infrastructure. The site is well-optimized for mobile devices, accessible, and SEO-friendly, with robust privacy and cookie consent mechanisms in place. HTTPS is enforced with security best practices like anti-clickjacking scripts, contributing to a secure user experience. From a security perspective, HSBC demonstrates a strong posture with appropriate security headers, encrypted communications, and compliance with privacy regulations including GDPR. However, explicit incident response and vulnerability disclosure policies are not publicly evident, representing an area for improvement. The WHOIS data is unavailable due to privacy or registry restrictions, which is common for large financial institutions to protect sensitive registration details. Overall, HSBC's website is professional, trustworthy, and secure, reflecting the company's global reputation. Strategic recommendations include enhancing transparency around security incident response and vulnerability reporting to further strengthen trust and compliance.

85
72
80
100
85
17
95
bankingfinancecorporateinvestorsprivacy+2 more
JavaScriptVideoJSTealium Tag Management

Partner Domains:

hangseng.com
subsidiary
about.hsbc.com.hk
partner
2026-07-12T07:11:30.478Z
grayreed.com favicon

Gray Reed

grayreed.com

76
OtherUnited StateslargeLOW

Gray Reed is a well-established Texas-based full-service law firm with offices in Dallas, Houston, and Waco. The firm offers a broad range of legal services including litigation, compliance, transactional law, and family law, targeting businesses and individuals primarily within Texas. Their website reflects a professional and business-oriented approach, emphasizing personalized client service and industry expertise. The firm maintains an active digital presence with embedded multimedia content and social media integration, supporting their market positioning as a trusted regional legal advisor. Technically, the website is built on the Intelliun VE CMS platform and leverages modern web technologies such as jQuery, FontAwesome, and Google Analytics for tracking. The site is mobile-optimized and provides a good user experience with clear navigation and relevant content. However, some technical improvements could be made in accessibility and security headers to enhance overall robustness. From a security perspective, the site uses HTTPS and implements cookie consent mechanisms, indicating awareness of privacy regulations like GDPR. Nonetheless, the absence of visible security headers and lack of explicit security or incident response policies suggest room for improvement in security posture. The WHOIS data is notably missing, which raises questions about domain registration transparency but does not necessarily indicate malicious intent given the professional nature of the site. Overall, Gray Reed's website presents a credible and professional front for their legal services, with moderate technical maturity and a generally good security baseline. Strategic enhancements in security policies, transparency, and contact information visibility would further strengthen trust and compliance.

77
85
85
100
60
73
47
lawfirmlegalservicestexasattorneyslitigationcompliance+4 more
jQuery 3.7.1jQuery UI 1.14.0FontAwesome 5.1.0Google Analytics+1

Partner Domains:

www.grayreedadvisory.com
partner
www.grayreedfoundation.org
partner
2026-07-11T07:22:32.790Z
genesys.com favicon

Genesys

genesys.com

78
TechnologyUnited StatesenterpriseLOW

Genesys is a leading enterprise technology company specializing in omnichannel customer experience and contact center solutions. Trusted by over 10,000 companies worldwide, Genesys offers AI-powered cloud-based platforms designed to enhance customer engagement and operational efficiency. The company positions itself as a market leader with a comprehensive suite of services tailored for large organizations seeking advanced customer experience management. The website reflects a mature digital presence with professional branding and clear communication of its offerings. Technically, the website employs modern web technologies including Bootstrap 5, jQuery, and personalization tools like Intellimize. It is built on WordPress CMS and leverages CDNs for performance optimization. The site demonstrates excellent mobile responsiveness, accessibility, and SEO practices, indicating a high level of digital maturity and user experience focus. From a security perspective, Genesys maintains strong practices including HTTPS enforcement, comprehensive security headers, and adherence to recognized frameworks such as ISO 27001 and SOC 2. The presence of detailed privacy, cookie, and security policies, along with incident response contacts, underscores a robust security posture. No significant vulnerabilities or exposed sensitive data were detected. Overall, Genesys presents a low-risk profile with a professional and trustworthy online presence. The only notable gap is the absence of publicly available WHOIS registration data, which may be due to privacy protection but does not detract from the company's legitimacy given its enterprise stature and compliance indicators.

77
85
100
82
60
47
85
customerexperiencecontactcenteraicloudenterprisesoftware+1 more
JavaScriptBootstrap 5jQueryIntellimize (A/B testing and personalization)+1
2026-07-11T07:14:59.060Z