SecureKit

SecureKit

Security audits, simplified. Run client-facing security audits and get exportable, AI-augmented reports — all from a single toolkit.

DNS Security Checker

Check a domain's SPF, DKIM, DMARC, DNSSEC, and CAA records against email and DNS security best practices.

Run audit

SSL/TLS Certificate Inspector

Inspect a domain's TLS certificate, chain, protocol version, cipher strength, and HSTS configuration.

Run audit

HTTP Security Headers Auditor

Scan a domain's response headers, get a letter grade, and see AI-generated fixes for any gaps.

Run audit

Cookie Audit Tool

Inspect a site's cookies, flag missing Secure/HttpOnly/SameSite attributes, and detect pre-consent tracking cookies.

Run audit

Dependency Vulnerability Checker

Paste a package.json, requirements.txt, or Gemfile.lock to check for known CVEs via OSV.dev.

Scan dependencies

API Security Checklist

Assess your REST or GraphQL API against the OWASP API Top 10 — authentication, authorization, rate limiting, and more.

Start checklist

Exposed File Checker

Probe a domain for publicly reachable .env files, exposed .git directories, credential files, backups, and admin/debug endpoints.

Run scan

Best Practices Checker

Checks for security.txt (RFC 9116), a well-known password-change URL, MTA-STS/TLS-RPT mail transport security, and robots.txt — process and hygiene signals, not vulnerabilities.

Check

Privacy Policy Analyzer

Paste a vendor's privacy policy URL or text to analyze data collection, third-party sharing, retention periods, and red flags.

Analyze policy

GDPR Compliance Checklist

Answer a guided questionnaire and get a compliance score, risk tier, and AI-generated remediation notes.

Start checklist

Audit Report Builder

Combine your completed audits into a single branded PDF report you can hand off to a client.

Build report