Company31 emblem: the numerals 31 over blue waves with circuit node dots Company31
Company31 · CyberSafe

See your exposure clearly.
Then harden it.

CyberSafe runs a consent-based, non-intrusive security check against a website you own. It reads only what any browser can already see — no attacks, no break-ins — and returns a graded report, aligned with recognised standards, that tells you exactly what to fix first.

Why this one, out of all the free scanners? Most free scanners are lead-generation bait: they will scan anyone’s site, tease the grade, then gate the fixes behind a sales call and put your inbox on a list. CyberSafe is built the opposite way — it only scans a site you can show is yours, gives you the whole report on the spot, explains every fix in plain English mapped to OWASP, NIST CSF and the ACSC Essential Eight, and its code is public at github.com/c31labs. No account, no paywall, no mailing list — unless you ask for one.

Run a security check

Enter a site you own or are authorised to test. The scan is passive: it inspects publicly visible configuration only.

We check the site at this address over HTTPS. Enter the domain only — e.g. example.com or www.example.com.

Before your first scan we email you a 6-digit code to confirm this address is real. Security first: your email is used to verify who runs a scan and to keep the consent audit trail. It is never shared with anyone, and there is no marketing — unless you tick the optional box below, which is entirely up to you.

By starting, a consent record (time, domain, your verified email, your IP) is logged.
What CyberSafe inspects

Eight lenses on your exposure.

01 · Transport

HTTPS enforcement, redirects and HSTS — is traffic encrypted end to end?

02 · Certificate

TLS certificate validity, issuer, hostname match and time to expiry.

03 · Headers

CSP, X-Content-Type-Options, frame protection, Referrer- and Permissions-Policy.

04 · Cookies

Secure, HttpOnly and SameSite flags on any cookies the site sets.

05 · Exposure

Server banners, directory listing, and common sensitive files left reachable.

06 · Email auth

SPF, DMARC and DKIM signals that stop your domain being spoofed.

07 · Content

Mixed content, leaked software versions and a published security contact.

08 · Scoring

A 0–100 score and A–F grade, mapped to recognised standards.

Findings are assessed against the OWASP Secure Headers Project and OWASP Top 10, Mozilla Web Security Guidelines, and mapped to NIST CSF 2.0 and the ACSC Essential Eight. CyberSafe is an automated, non-intrusive posture assessment — it is not, and does not replace, a certified penetration test.

Before you scan.

Is this legal to run?

Only scan sites you own or are authorised to test — that is what the consent step is for. CyberSafe is deliberately non-intrusive: it reads publicly visible configuration the same way a normal browser does, and sends no attack traffic. Scanning systems without authorisation may still be unlawful in your jurisdiction, so the responsibility for authorisation rests with you.

Do you actually attack my site?

No. There is no fuzzing, no brute force, no exploitation and no denial-of-service. CyberSafe requests your homepage and a short list of common paths (like /robots.txt), inspects the TLS certificate, and looks up public DNS records. Everything it sees, anyone with a browser could see.

What is the score based on?

Each finding carries a weight by severity. The score starts at 100 and deductions are applied for gaps, following the methodology of the OWASP Secure Headers Project and Mozilla's Web Security Guidelines. Findings are also mapped to NIST CSF 2.0 functions and, where relevant, the Australian Signals Directorate's Essential Eight so you can talk to auditors in their language.

What does it not cover?

Plenty — and that is by design. It does not test application logic, authentication flows, access controls, injection, business logic, or anything requiring an account or payload. Those need an authorised penetration test with a human in the loop. If your report surfaces serious gaps, that is the conversation to have. Company31 can help.

What's the difference between the standard and deep scan?

Any verified email can run the standard scan — the passive posture check described above. The deep scan is unlocked only for a domain you've proven you control, and it goes further: it samples several internal pages, checks a much longer list of commonly-exposed files, inspects form security, probes which TLS versions your server still accepts, and reviews mail-transport (MTA-STS/TLS-RPT) and DNS resilience. It is still strictly non-intrusive — ordinary GET/OPTIONS requests and TLS handshakes only, never any attack.

How do I prove I own the domain?

Two ways. If your verification email is on the same domain you're scanning (say you@acme.com scanning acme.com), ownership is automatic. Otherwise we give you a one-off file to drop at your site's root — the same idea as verifying a site with Google Search Console. Once we fetch it and it matches, the deep scan is unlocked for that domain for 30 days. Nobody who can't place a file on your server, or receive mail at your domain, can run the deep scan against you.

Why do you need my email?

To keep the tool from being abused. Before your first scan we send a one-time code to your address and you type it back — proof that a real, reachable person authorised the scan, which becomes part of the consent record. By default that is its only purpose: your email is never shared or sold, and never used for marketing unless you explicitly tick the optional updates box — which you can leave empty and still scan. A verification lasts 24 hours; after that we simply ask again.

Where does my data go?

The scan runs on Company31's server and results are shown only to you in this browser. A minimal consent record — timestamp, the domain you entered, your verified email address, and your IP address — is logged so there is an audit trail of authorised scans. If you ticked the optional updates box, your address (with the time and IP of that consent) is also stored on Company31's server so we can send occasional update emails — unsubscribe any time via the link in any update, or write to connect@company31.com and it is deleted. No report contents are sold or shared.