How secure is your web app?
Get your security grade in seconds -- free, no account needed.
No account required · Free forever · No data stored
Not sure what to scan?
- 1 Enter your domain No login, no card.
- 2 66 checks run live Streamed in under 60s.
- 3 A-F grade + PDF Auditor-ready, NIS2 mapped.
Automated external-surface analysis. Complementary to a manual penetration test, not a replacement for one.
Computed per SaaSFort Check-Spec v0.1 · open methodology, versioned, MIT-licensed
66 controls, 25 categories, reproducible
Raw evidence and a timestamp on every finding
Every finding tagged with its OWASP / NIS2 / ISO 27001 / DORA control
While you are here: SaaS Security Leaderboard: public NIS2 grades ·Security scan by use case ·NIS2 supplier questionnaire ·Prove SaaS security to enterprise buyers ·NIS2 audit evidence requirements ·NIS2 supply chain Article 21 ·How to answer a security questionnaire fast ·Vendor security assessment guide ·What a NIS2 audit costs
Evidence standard
What a security department gets, check by check
66 controls across 25 categories
A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared.
Raw evidence and a timestamp on every finding
Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.
Mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA
Mapping happens in the engine, so the export goes to the auditor without re-formatting.
Exposure confirmed by content signature
Any exposed file or sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s.
SaaSFort performs automated external-surface analysis. It is complementary to a manual penetration test, not a replacement for one, and it does not detect business-logic flaws.