Research
A polished security report ≠ a formal certificate — Site Security in plain language
Why we show certificate-style reports, what we scan, and what gets better — without calling it official certification.

One line: A good-looking report and a formal certificate are not the same words. We build the first and refuse to call it the second.
Why we built this
People want a simple answer: “Is it safe? What’s the score? Do you have a certificate?”
A pretty PDF does not mean “unhackable” or “authority-approved.”
We publish re-runnable reports and keep the naming honest.
How we built it
Site Security reads a domain’s public web state: HTTPS/TLS, HSTS, CSP, and other security headers.
Run → preview → download HTML → re-check later for point-in-time differences.
Observatory A+ means a strong header profile — not zero app bugs and not zero incidents.
What gets better
Users get answers they can re-check. Press can re-scan. Ops keep web-header status separate from CA/C2PA status.
Open: Site Security
Limits
Not a formal security certificate. Does not prove privacy program completeness or replace C2PA Trust List review.