The connection
We check the HTTPS response and what happens at the HTTP address. This is not a complete TLS analysis.
FOR PEOPLE WHO CARE ABOUT THE DETAILS
A professional website goes beyond good looks.
Check its configuration. Know what to refine.
CONFIGURATION. CONTEXT. NEXT STEPS.
Explore what we checkFor freelancers and small agencies who want a more confident client handoff.
Audy checks your website’s public configuration and explains what it finds. Every observation comes with context, so you know what to change and why.
We check the HTTPS response and what happens at the HTTP address. This is not a complete TLS analysis.
We read CSP, HSTS and other security headers. You see the observed value or a clear notice when it is missing.
We look for HTTP references in the initial HTML. We do not execute scripts or run a browser.
Free scan scope: the public homepage. No exploitation, login attempts or load testing.
We read the public response and its configuration. No passwords, installation or hosting access needed.
Each observation includes the value we read, what it means and the limits of the check. No unexplained “72/100” score.
Go from findings that need attention to practical developer recommendations. Keep the report and compare results after your changes.
INSIDE A FINDING
A list of headers only tells half the story. Every finding answers three questions: what did we observe, why does it matter, and what happens next?
SAMPLE REPORT · DEMONSTRATION DATA
REVIEW RECOMMENDED
Content-Security-PolicyHeader not foundNo Content-Security-Policy header was detected. This alone does not prove an XSS vulnerability. A policy may also be set in the HTML.
Map the page’s resource sources and draft a policy tailored to the site. Start with Report-Only mode and review violations before enforcing it.
CLEAR SCOPE. STRAIGHTFORWARD TERMS.
0 PLN
no account or card
The homepage’s public configuration, with an explanation for every finding.
149 PLN
PLN incl. tax / one time
Up to 25 public addresses after domain control verification and explicit scope approval.
149 PLN is the proposed price. You can prepare a scope and verify domain control. Live sales are disabled; payments can use test mode only.
No. Audy analyses public configuration within the stated scope. It does not test authentication, business logic or source code. A report is not a security certificate and cannot rule out other issues.
Not necessarily. It is a reason to review the configuration in context. Findings explain their limitations so that a missing layer of protection is not confused with a confirmed exploit.
The free scan reads a public response. Make sure you have a legitimate basis for checking the site. The wider Pro scope requires domain control verification and explicit permission for the agreed checks.
Save the private link or download the JSON report. The link works for 7 days in the environment where the scan ran. Anyone you share it with can read the report. Reports are not placed in a public directory.
A website may block automated requests, fail to respond over HTTPS, or redirect to a different domain. Audy shows an error or an unknown result instead of guessing. For a cross-domain redirect, enter the final domain.