Public endpoint identity
Domain, scan time, public endpoint context and a saved URL you can return to after fixes.
The report is intentionally focused on evidence a public scanner can observe. It gives a repeatable baseline for the website, then points to the broader migration work that a full cryptographic inventory must cover.
Domain, scan time, public endpoint context and a saved URL you can return to after fixes.
Visible TLS version signals, downgrade exposure and whether the endpoint has the foundation for PQC migration.
External evidence around hybrid post-quantum key exchange visibility and practical next checks.
A short path from public scan evidence to inventory, supplier questions, badge eligibility or deeper assessment.
Creates the first repeatable evidence record.
Shows whether the public endpoint needs immediate cleanup.
Captures visible controls that affect browser-facing risk.
Highlights whether the endpoint shows public PQC readiness signals.
Lets the same team return after TLS, CDN or provider changes.
Keeps the report tied to an email-owned free account.
Example report
Endpoint
example.com
Visible posture
TLS foundation present, PQC visibility not confirmed, follow-up inventory needed.
Next action
Rescan after CDN/TLS changes, then map APIs, certificates, signing systems and suppliers.
A public website report is a useful first record, not a full audit. NCSC migration guidance puts discovery, assessment and planning before migration work, and NIST NCCoE treats PQC migration as a broader inventory and system-change problem.
Internal applications and private APIs
Data-at-rest encryption and database keys
Code signing, firmware signing and HSM configuration
VPNs, managed devices and non-public services
Supplier contracts and cryptographic SBOMs
Formal compliance attestation
One scan is only a snapshot. Saving the result gives you a baseline to compare after TLS, CDN, security-header or provider changes.
It also creates an email-owned record, which is more useful for follow-up than an anonymous browser result that disappears when the session ends.
Yes. The free path creates a public website scan report and lets you save it in a free account. Paid work is only needed for deeper manual assessment, inventory or implementation support.
No. You can scan first, then save the result. This page also lets you enter an email and domain first so the account flow can take you straight to the scanner.
No. A public scan is evidence for one visible endpoint. A full PQC readiness position also needs inventory, data-lifetime analysis, supplier review and migration planning.
It is useful for founders, CTOs, security leads and compliance owners who need a first record before deciding whether to clean up TLS, build an inventory or commission a deeper assessment.