Hard2bit · Cybersecurity

Hard2bit Scanner

Your public security posture, in 30 seconds.

While classic scanners check 5 things, we check 50+. From HTTP headers to leaked secrets on Lovable-built sites, BIMI, MTA-STS, vulnerable JavaScript libraries, forgotten subdomains, expiring certificates, credentials in public breaches, and much more.

No agents, no internal access. Just your domain. 100% passive analysis.

How Hard2bit Scanner works in 4 steps

100% passive analysis, no agents to install, no internal access. All you need is your domain. Under 60 seconds for most domains.

  1. Enter your domain

    Type your domain (example.com), accept the terms and launch the scan. No registration needed for the first scan. No sensitive data is requested.

  2. Passive analysis in parallel

    The scanner queries DNS, HTTP headers, certificates, threat intel, public sources and Certificate Transparency. Zero impact on your server — equivalent to a regular browser visit.

  3. Results with score and findings

    You receive an A+ to F grade, findings categorised by severity (critical, high, medium, low), and actionable recommendations with reproducible technical evidence.

  4. Share and act

    Export a professional PDF (paid plan), share it with your team or client, integrate it into your audit workflow. History available to track evolution over time.

Methodology: the 26 controls in detail

Each control evaluates a specific aspect of your domain's public posture. Grouped into 6 technical categories plus 1 AI Agent Readiness category (already covered above). What it measures, what evidence it collects and why it matters. This is the public methodology a consultant can show to a client or an auditor can show to their team.

Network and infrastructure

Analysis of the foundation your traffic travels on: TLS/SSL configuration, DNS health and exposed ports. Any weakness here compromises everything built on top — encryption, authenticity, availability.

  • TLS / SSL Free

    Analyzes your certificate configuration and the available encrypted protocols to ensure secure communications and detect known cryptographic weaknesses.

  • DNS health Free

    Evaluates the domain DNS configuration: server redundancy, DNSSEC, presence of sensitive records, and consistency across providers.

  • Exposed ports ⭐ Premium

    Identifies common ports accessible from the Internet that could expose administrative services or management panels without additional protection.

Web and application

HTTP security headers, cookie configuration, mixed content, technology detection (CMS, frameworks) and matching against known CVEs. The layer where the user's browser talks to your application.

  • HTTP security headers Free

    Checks that your site sends the recommended security headers, which protect it against code injection, UI hijacking, and traffic manipulation.

  • Technologies detected Free

    Identifies the technologies and versions running on your site (CMS, frameworks, libraries, servers) to detect outdated components with known vulnerabilities.

  • Known public vulnerabilities (CVE) Free

    Cross-references detected technologies against public vulnerability databases to identify versions affected by documented security flaws.

  • Cookie configuration Free

    Reviews the security attributes of your site cookies to detect configurations that could facilitate user session theft.

  • Mixed content on secure pages Free

    Detects secure pages loading resources over unencrypted channels, a condition that breaks transport protection and exposes user data.

Identity and authenticity

Email security (SPF, DMARC, MTA-STS, BIMI), Certificate Transparency, and public WHOIS information for the domain. They validate that the entity claiming to be your domain actually is.

  • Email security Free

    Evaluates the public mechanisms that authenticate email sent from your domain, reducing the risk of spoofing and phishing in your name.

  • Domain status Free

    Checks expiration date, age, registrar, and administrative status of the domain to anticipate expiry losses or unauthorized transfer risks.

  • Certificate Transparency Free

    Reviews certificates issued for your domain in public Certificate Transparency logs, useful for detecting unauthorized issuance or forgotten subdomains.

Data exposure

Searches for public credentials, misconfigured cloud storage, forgotten subdomains, possible takeovers, Common Crawl exposure, and AI-bot policies. What an attacker would find via OSINT before you do.

  • AI-era security posture ⭐ Premium

    Evaluates your posture against automated AI access: generative-model scrapers, data exposure to training without consent, and common AI-application endpoints left unprotected.

  • Exposed cloud storage ⭐ Premium

    Detects cloud storage and admin panels accessible from the Internet that could leak files, backups, or credentials.

  • Leaks in pastes and repositories ⭐ Premium

    Searches for mentions of your domain or associated credentials in public repositories and paste services, detecting information leaks before attackers do.

  • Subdomain takeover risk ⭐ Premium

    Detects subdomains pointing to abandoned external services that an attacker could claim to impersonate your brand.

  • AI dataset exposure ⭐ Premium

    Checks whether your domain content appears in public archives that feed generative AI models, and whether sensitive pages are indexed that shouldn't be.

  • AI bot blocking Free

    Checks whether your site is configured to block generative-AI model scrapers (GPTBot, ClaudeBot, Google-Extended, etc.) via robots.txt, ai.txt, and meta tags.

  • Certificate Transparency subdomains ⭐ Premium

    Enumerates subdomains visible in public Certificate Transparency logs (crt.sh) and classifies them by name pattern — surfaces non-production environments (dev/staging/admin) exposed to the Internet.

  • Vendor breach exposure ⭐ Premium

    Identifies the third-party vendors you use (CRM, marketing, analytics, CDN) and checks whether any has been involved in a documented public breach — NIS2 supply-chain risk traceability.

Reputation and threat intelligence

Cross-checks against public threat-intel lists: whether your domain or IPs show up in blocklists for phishing, spam or known C2. An external signal of the trust the ecosystem grants you.

  • Threat intelligence Free

    Checks whether your domain, IPs, or mail servers appear in public threat lists (spam, malware, phishing, botnet infrastructure).

Compliance and public signals

Presence and validity of security.txt, robots.txt and compliance signals (NIS2, DORA, ENS, ISO 27001) that an auditor checks before even requesting your internal documentation.

  • security.txt file Free

    Checks that your site publishes a standard channel for security researchers to responsibly report vulnerabilities.

  • Compliance signals ⭐ Premium

    Identifies public signals of best-practice adoption (cookies, privacy policy, GDPR, accessibility) without replacing formal legal audit.

  • robots.txt file Free

    Analyzes the robots.txt file to identify internal paths inadvertently revealed and inconsistent indexing policies.

AI Agent Readiness

The 11 emerging standards (llms.txt, MCP, Content-Signal, Web Bot Auth, etc.) are detailed in the AI Agent Readiness section above. Each is evaluated for both presence and secure configuration.

↑ Jump to AI Agent Readiness

Standards and references we follow: OWASP Secure Headers Project · Mozilla Server-Side TLS · IANA Root DNSSEC · M3AAWG Sender Best Practices · RFC 6962 Certificate Transparency · llmstxt.org · MCP spec · EU NIS2 Directive.

AI Agent Readiness: why it's our unique angle

In 2026, your website no longer competes only on Google. It also competes to be discovered, understood and correctly cited by AI agents: ChatGPT with browsing, Perplexity, Claude search, autonomous agents. These agents read emerging standards (llms.txt, MCP Server Card, Content-Signal, Web Bot Auth and 7 others) to decide whether your site is agent-ready — and if it isn't, you fall out of the new discovery funnel. Hard2bit Scanner is one of the few scanners that evaluates the 11 emerging standards alongside the 14 classic security controls.

But AI Agent Readiness without security is a new kind of risk. A misconfigured llms.txt leaks private routes. An MCP server without authentication is a trivial abuse vector. A robots.txt that is inconsistent across subdomains allows some bots what it forbids to others. That is why we always evaluate both dimensions: that the standard is present AND that it is securely configured.

Use cases by audience

Hard2bit Scanner serves 4 distinct profiles with 4 distinct workflows. Same engine, conclusions applicable to each professional context.

Internal CISO or security team

Continuously audit the public posture of your own domain plus forgotten subdomains (shadow IT). Pre-validate changes before release. When NIS2/ENS lands and you need quick evidence for the technical dimension of Article 21, the scanner produces timestamped, reproducible reports that auditors accept.

Start for free →

Consultant or vCISO

Pre-audit the external posture of a new client in 60 seconds before the first meeting. A professional PDF ready to deliver as a pre-engagement deliverable or as a commercial hook. Standard workflow: scan → report → conversation → proposal for larger services.

See Pro plans →

MSP or MSSP

Continuous inventory of the external posture of your client portfolio. Early detection of changes (new subdomains, expiring certificates, MX changes). History for quarterly reporting. White-label on the 2026 roadmap.

Get in touch →

Development team / DevSecOps

External-posture validation on every release. Catch regressions in HTTP headers, certificate expiration, robots.txt configuration for AI bots. Public API on the roadmap for CI/CD integration.