PUBLIC WEBSITE EXPOSURE, EXPLAINED
Know what
your website
reveals.
A focused check of your public website, with a private report explaining what we observed, what to fix first and what remains unknown.
In development. Explore the experience before launch.
# fictional agent session · example.test agent> look for a way into the website $ curl -I https://example.test HTTP/2 200 X-Powered-By: ExampleServer agent> fingerprint found. inspect public source $ curl -s https://example.test/ <!-- build: demo-42 --> agent> next: attempt a login bypass? [not run] login tests are outside this check [observed] public software details exposed [unknown] no exploitable weakness established
Scripted illustration of an attacker’s reasoning. No commands execute. Saltpin’s proposed checks are bounded and owner-authorised.
Evidence you can understand.
Next steps you can act on.
LESS GUESSWORK.
A little visibility.
A better next step.
Understand the exposure
See what your public website makes visible, within a clearly defined scope.
Look at the evidence
Connect each observation to an understandable, redacted excerpt.
Know where to start
Separate the priorities from the unknowns, so you can make a useful next move.
A CONSIDERED PROCESS
One website.
Three clear steps.
The intended journey starts with your authority.
And ends with something useful.
- 01
Request a check
Choose the exact public website you are authorised to have checked.
- 02
Verify authority
Confirm mailbox control and separately record your authority for the agreed scope.
- 03
Receive your report
Review the observations, priorities and limits in a private, understandable report.
Planned service journey. This prototype does not accept requests or run checks.
INSIDE YOUR REPORT
Clarity, in
four parts.
No mysterious security score. Just what we checked, what we observed, what deserves attention and what we cannot tell you.
02 / OBSERVATIONS
Evidence first. Plain language second.
An observation tells you what was seen. The explanation tells you why it may matter, without claiming an exploit was tested.
A browser protection header is absent
Synthetic response: Content-Security-Policy was not present on the homepage. This may leave fewer browser-side protections against injected content.
A response reveals a software detail
Synthetic response: X-Powered-By: ExampleServer. This exposes an implementation detail; it does not prove a vulnerability.
HTTPS redirect observed
Synthetic response: HTTP homepage returned a redirect to HTTPS on the same host. Other routes were not checked.
FOCUSED BY DESIGN
Public-facing.
Precisely bounded.
The proposed checks look at what one authorised public host reveals. A useful view of the surface, with the limits kept visible.
Connection security · Security headers · Cookie settings · Same-host redirects · Publicly linked pages · Visible error and debug text
Signed-in areas, form submissions, other hosts and subdomains, intrusive testing and a review of your application’s source code.
A blocked or incomplete check stays visible. It never becomes a clean result.
BEFORE YOU BEGIN
Good questions.
Straight answers.
Who can request a check?
The intended service is for owners authorised to request the agreed checks on one exact public host. Control of an email address alone does not prove authority. Verification and authorisation rules are still being finalised.
Will my report be public?
The planned report is private and requester-scoped. Access, expiry and retention controls must be implemented and reviewed before launch. This preview contains synthetic examples only; the demo form sends and saves nothing.
What will Saltpin check?
The proposed scope includes connection security, security headers, cookie settings, same-host redirects, publicly linked pages and visible error or debug text. The final check set will be agreed before any real check.
Does a clean result mean my website is secure?
No. A result can only describe the checks that were completed. Blocked, failed or untested areas remain unknown. Saltpin will not provide certification or a security guarantee.
MAKE THE FIRST STEP CLEAR
Your website.
A clearer
perspective.
Explore how a request could work.
The real service is still in development.
TRY THE REQUEST FLOW
A clearer starting point.
Interactive preview only. Details stay in this page’s memory and are cleared when you finish. Nothing is sent or saved, and no scan starts.