Hard2bit Scanner
Online cybersecurity scanner: check your domain's exposure in 30 seconds
While classic scanners check 5 things, Hard2bit Scanner evaluates 50+ signals across 25 automated checks: HTTP headers, TLS configuration, email records (SPF/DKIM/DMARC/MTA-STS), DNS exposure, leaks in pastes and public repos, forgotten subdomains, vendor breach exposure, and 11 emerging AI Agent Readiness standards from 2025-2026. No agents, no internal access, fully passive.
25 automated controls per scan — 14 free, 11 Premium
First scanner to measure 11 emerging standards for AI agents
Results in 30 seconds, no install, no card required to start
SaaS product by Hard2bit S.L. · Spanish cybersecurity company headquartered in the Community of Madrid · 13 years in the field.
The full tool — detailed reports, history, PDF export and plans — lives at scan.hard2bit.com. Already have an account? Sign in.
Time per scan
30 s
Full report with score, grade and prioritized findings
Controls per scan
25
14 free + 11 Premium across 6 security categories
Analysis model
100% passive
No agents, no access to private resources of the domain
What is Hard2bit Scanner and what does it check?
Hard2bit Scanner is the SaaS application from Hard2bit that continuously audits the public security posture of any domain — and, in the same scan, measures its readiness for the AI-agent era.
Every scan runs 25 automated controls across six categories — Network, Web, Identity, Data exposure, Reputation and Compliance — and delivers a report with score, grade, prioritized findings and concrete technical recommendations.
The analysis is 100% passive: no agents, no access to private resources, only public sources. Results in 30 seconds, no install, no card required to start.
Hard2bit Scanner stands apart from the market by including a unique AI Agent Readiness module that evaluates up to 11 emerging standards from 2025-2026 — territory most classic scanners do not yet cover.
Why Hard2bit Scanner
While classic scanners check 5 things, we check 50+
Hard2bit Scanner combines the usual EASM (External Attack Surface Management) controls with dedicated modules for leaks in pastes and repositories, supply-chain breaches with NIS2 traceability, AI dataset exposure, and the first commercial Agent Readiness block covering 11 emerging standards from 2025-2026.
Fully passive, no agents
No internal access and no technical authorization required to start. Just the domain. Results in under a minute.
25 controls, not 5
14 free controls across six categories and 11 Premium controls covering advanced exposure and supply chain.
First scanner with Agent Readiness
11 emerging 2025-2026 standards so your domain is ready for AI assistants and agents.
What security controls does the scanner run?
14 free and 11 Premium, grouped in six categories. All passive, no internal access.
Network
3 controlsTLS / SSL
FreeCertificate configuration, available cipher protocols and known cryptographic weaknesses.
DNS health
FreeServer redundancy, DNSSEC, sensitive records and consistency across providers.
Exposed ports
⭐ PremiumCommon ports reachable from the Internet that may expose admin services or management panels.
Web
5 controlsHTTP security headers
FreeRecommended headers against code injection, UI hijacking and traffic manipulation.
Detected technologies
FreeCMS, frameworks, libraries and server stack in use to flag outdated components.
Known public vulnerabilities (CVE)
FreeCross-reference of detected technologies against public CVE databases.
Cookie configuration
FreeCookie security attributes that could facilitate session theft if misconfigured.
Mixed content on secure pages
FreeHTTPS pages loading resources over insecure channels and exposing user data.
Identity
3 controlsEmail security
FreeSPF, DKIM, DMARC, MTA-STS and other public mechanisms that authenticate outbound mail.
Domain status
FreeExpiration date, age, registrar and administrative status of the domain.
Certificate Transparency
FreeCertificates issued in public CT logs to detect unauthorized issuance.
Data exposure
8 controlsAI-era security posture
⭐ PremiumPosture against generative AI scrapers, training-data exposure and common AI-app endpoints left unprotected.
Exposed cloud storage
⭐ PremiumCloud buckets and admin panels reachable from the Internet that could leak files or credentials.
Leaks in pastes and repositories
⭐ PremiumMentions of the domain or associated credentials in public repositories and paste services.
Subdomain takeover risk
⭐ PremiumSubdomains pointing to abandoned external services that an attacker could claim.
AI dataset exposure
⭐ PremiumDomain content present in public archives that feed generative AI models.
AI bot blocking
FreeConfiguration to block generative-AI scrapers (GPTBot, ClaudeBot, Google-Extended) via robots.txt, ai.txt and meta tags.
Certificate Transparency subdomains
⭐ PremiumEnumerates subdomains visible in CT logs and classifies them to surface dev/staging/admin environments.
Vendor breach exposure
⭐ PremiumThird-party vendors in use (CRM, marketing, analytics, CDN) with documented public breaches — NIS2 supply-chain traceability.
Reputation
2 controlsBrand protection and typosquatting
⭐ PremiumDomains impersonating your brand: generates typo variants, discovers lookalikes via Certificate Transparency, probes each candidate over DNS, MX and HTTPS, and flags those with live infrastructure. Returns a Brand Exposure Score where 100 means a clean brand.
Threat intelligence
FreePresence of domain, IPs and mail servers in public spam, malware, phishing and botnet lists.
Compliance
4 controlssecurity.txt file
FreeStandard channel published so security researchers can responsibly report vulnerabilities.
Compliance signals
⭐ PremiumPublic signals of best-practice adoption (cookies, privacy, GDPR, accessibility).
Advanced AI Agent Readiness
⭐ PremiumThe 7 emerging standards for autonomous agents — capability discovery, delegated authentication and interaction protocols — weighted higher in the Agent Readiness Score than the basic variant.
robots.txt file
FreeInternal paths inadvertently revealed and inconsistent indexing policies.
What the scanner checks, control by control
Every control runs passively against public sources: no agents to install, no credentials and no contact with your systems. This is the full list and the plan each one belongs to.
| Area | Control | What it detects | Plan |
|---|---|---|---|
| Network 3 controls | TLS / SSL | Certificate configuration, available cipher protocols and known cryptographic weaknesses. | Free |
| DNS health | Server redundancy, DNSSEC, sensitive records and consistency across providers. | Free | |
| Exposed ports | Common ports reachable from the Internet that may expose admin services or management panels. | Premium | |
| Web 5 controls | HTTP security headers | Recommended headers against code injection, UI hijacking and traffic manipulation. | Free |
| Detected technologies | CMS, frameworks, libraries and server stack in use to flag outdated components. | Free | |
| Known public vulnerabilities (CVE) | Cross-reference of detected technologies against public CVE databases. | Free | |
| Cookie configuration | Cookie security attributes that could facilitate session theft if misconfigured. | Free | |
| Mixed content on secure pages | HTTPS pages loading resources over insecure channels and exposing user data. | Free | |
| Identity 3 controls | Email security | SPF, DKIM, DMARC, MTA-STS and other public mechanisms that authenticate outbound mail. | Free |
| Domain status | Expiration date, age, registrar and administrative status of the domain. | Free | |
| Certificate Transparency | Certificates issued in public CT logs to detect unauthorized issuance. | Free | |
| Data exposure 8 controls | AI-era security posture | Posture against generative AI scrapers, training-data exposure and common AI-app endpoints left unprotected. | Premium |
| Exposed cloud storage | Cloud buckets and admin panels reachable from the Internet that could leak files or credentials. | Premium | |
| Leaks in pastes and repositories | Mentions of the domain or associated credentials in public repositories and paste services. | Premium | |
| Subdomain takeover risk | Subdomains pointing to abandoned external services that an attacker could claim. | Premium | |
| AI dataset exposure | Domain content present in public archives that feed generative AI models. | Premium | |
| AI bot blocking | Configuration to block generative-AI scrapers (GPTBot, ClaudeBot, Google-Extended) via robots.txt, ai.txt and meta tags. | Free | |
| Certificate Transparency subdomains | Enumerates subdomains visible in CT logs and classifies them to surface dev/staging/admin environments. | Premium | |
| Vendor breach exposure | Third-party vendors in use (CRM, marketing, analytics, CDN) with documented public breaches — NIS2 supply-chain traceability. | Premium | |
| Reputation 2 controls | Brand protection and typosquatting | Domains impersonating your brand: generates typo variants, discovers lookalikes via Certificate Transparency, probes each candidate over DNS, MX and HTTPS, and flags those with live infrastructure. Returns a Brand Exposure Score where 100 means a clean brand. | Premium |
| Threat intelligence | Presence of domain, IPs and mail servers in public spam, malware, phishing and botnet lists. | Free | |
| Compliance 4 controls | security.txt file | Standard channel published so security researchers can responsibly report vulnerabilities. | Free |
| Compliance signals | Public signals of best-practice adoption (cookies, privacy, GDPR, accessibility). | Premium | |
| Advanced AI Agent Readiness | The 7 emerging standards for autonomous agents — capability discovery, delegated authentication and interaction protocols — weighted higher in the Agent Readiness Score than the basic variant. | Premium | |
| robots.txt file | Internal paths inadvertently revealed and inconsistent indexing policies. | Free |
Is your domain ready for AI agents?
Hard2bit Scanner is the first commercial scanner that measures the 11 emerging standards companies need so their sites are discoverable, interpretable and operable by AI agents. While competitors stay on classic security, we also prepare you for the next channel shift.
4 basic standards · Starter
What Starter covers
llms.txt
Emerging standard letting language models know which parts of the site they may consume and how.
sitemap.xml for AI
Sitemap useful not only for search engines but also for AI agents and crawlers.
Content-Signal
Signals about content type (informational, transactional, commercial) for generative assistants.
Public Markdown
Clean Markdown versions of content so AI agents consume it without presentation noise.
+7 advanced · Pro
What Pro adds on top
RFC 9727 — Discovery
Standardized discovery of service capabilities for external agents.
RFC 9728 — OAuth for agents
Authentication and authorization built for programmatic and agent-driven access.
MCP Server Cards
Model Context Protocol cards describing the server to a connected assistant.
Agent Skills
Catalogue of operable product capabilities an agent can invoke.
ai.txt and scraping policy
Explicit policy about generative model usage: training, inference, commercial, non-commercial.
Schema.org for AI
Structured markup engineered so agents can interpret entities, products, FAQs and pricing.