Audy

FOR PEOPLE WHO CARE ABOUT THE DETAILS

Look beneath the surfaceof your website.

A professional website goes beyond good looks.
Check its configuration. Know what to refine.

  • HTTPS
  • HTTP headers
  • HTML resources

Free scan. No account or card.

CONFIGURATION. CONTEXT. NEXT STEPS.

Explore what we check

Useful. From the first scan.

ANALYSIS
EVIDENCE
ACTION

For freelancers and small agencies who want a more confident client handoff.

Looks good is a start.
Look beneath the surface.

Audy checks your website’s public configuration and explains what it finds. Every observation comes with context, so you know what to change and why.

HTTPS

The connection

We check the HTTPS response and what happens at the HTTP address. This is not a complete TLS analysis.

HEADERS

The protection layer

We read CSP, HSTS and other security headers. You see the observed value or a clear notice when it is missing.

HTML

Page resources

We look for HTTP references in the initial HTML. We do not execute scripts or run a browser.

Free scan scope: the public homepage. No exploitation, login attempts or load testing.

An address. Evidence.
A next step.

  1. Enter your domain.

    We read the public response and its configuration. No passwords, installation or hosting access needed.

  2. See what we found.

    Each observation includes the value we read, what it means and the limits of the check. No unexplained “72/100” score.

  3. Know what to fix next.

    Go from findings that need attention to practical developer recommendations. Keep the report and compare results after your changes.

INSIDE A FINDING

From a result
to a resolution.

A list of headers only tells half the story. Every finding answers three questions: what did we observe, why does it matter, and what happens next?

Audyexample.com

SAMPLE REPORT · DEMONSTRATION DATA

REVIEW RECOMMENDED

Missing CSP header

ObservedContent-Security-PolicyHeader not found

What does this mean?

No Content-Security-Policy header was detected. This alone does not prove an XSS vulnerability. A policy may also be set in the HTML.

Next step

Map the page’s resource sources and draft a policy tailored to the site. Start with Report-Only mode and review violations before enforcing it.

CLEAR SCOPE. STRAIGHTFORWARD TERMS.

Start with the essentials.
Go further when you need to.

FREE

A first look

0 PLN

no account or card

The homepage’s public configuration, with an explanation for every finding.

  • HTTPS response and HTTP redirect
  • Security headers and HTML resources
  • Evidence and developer recommendations
  • A private report link valid for 7 days
Check website
PRODEVELOPMENT PREVIEW

The bigger picture

149 PLN

PLN incl. tax / one time

Up to 25 public addresses after domain control verification and explicit scope approval.

  • Up to 25 agreed URLs on one website
  • Prioritised findings and a remediation plan
  • One repeat scan within 14 days
  • Scope confirmed before payment

149 PLN is the proposed price. You can prepare a scope and verify domain control. Live sales are disabled; payments can use test mode only.

Good questions.
Straight answers.

Is this a full penetration test?

No. Audy analyses public configuration within the stated scope. It does not test authentication, business logic or source code. A report is not a security certificate and cannot rule out other issues.

Does a missing header mean a vulnerability?

Not necessarily. It is a reason to review the configuration in context. Findings explain their limitations so that a missing layer of protection is not confused with a confirmed exploit.

Can I check a client’s website?

The free scan reads a public response. Make sure you have a legitimate basis for checking the site. The wider Pro scope requires domain control verification and explicit permission for the agreed checks.

How do I return to my report?

Save the private link or download the JSON report. The link works for 7 days in the environment where the scan ran. Anyone you share it with can read the report. Reports are not placed in a public directory.

Why might a scan fail?

A website may block automated requests, fail to respond over HTTPS, or redirect to a different domain. Audy shows an error or an unknown result instead of guessing. For a cross-domain redirect, enter the final domain.

Before you call it done,
take one more look.

Check your website

Audy