SecureFlow
What can your visitors see?
One page load, the one every visitor makes, and what it says about your setup. No sign-up.
The address your customers type. We look at the home page and nothing else.
What this scan does
What we do:
- We requested your home page once, the way a visitor’s browser does.
- We read the certificate, the response headers and any cookies that response set.
- We read your public DNS records — the same ones anybody can look up.
What we do not do:
- We did not request any other page or file, including the ones free scanners usually try.
- We did not send any input, payload or test traffic to your application.
- We did not attempt to sign in, and we sent no cookie or credential of our own.
- We did not scan a port, enumerate a subdomain, or look at anything behind a login.
What it cannot tell you:
- Whether your application has an injection, a broken access control or an exposed file — none of those are visible from outside a page load.
- Whether your dependencies have known vulnerabilities, which needs your code.
- Whether your cloud configuration is sound, which needs your account.
- Anything at all about the parts of your product behind a login, which is most of it.
A clean result here means the part your visitors can see is in order. It is not a security assessment and should not be shown to anybody as one.
SecureFlow — a product built by Ruah Tech Solutions, Australia