Free · run by Scout · reviewed by a practitioner

External Exposure Snapshot

What an attacker sees from outside, in plain language. Scout, our reconnaissance agent, performs a bounded, read-only look at one domain: certificate and TLS posture, security headers, cookie flags, obvious version disclosure. No exploitation, no forms submitted, no surprises.

  • Runs only after you attest that you are authorized to have the domain assessed.
  • Read-only and rate-limited: at most a couple of ordinary web requests.
  • A practitioner reviews the draft before anything is sent to you.
  • Not a penetration test and not a statement of safety — a starting point.
Preview mode. This installation runs Scout in dry-run mode: it produces the checklist and the wording without contacting the domain. Set PG_LIVE_SNAPSHOT=true to enable the bounded live check.

Request a snapshot

Send the public domain you are authorized to have assessed, your organization and a work email. We run the external, read-only snapshot and reply with the reviewed result.

Email hello@vzor.ca

Please confirm in your message that you are authorized to request an assessment of the domain on behalf of the organization that owns it.