SaaSFort
Results in under 60 seconds

How secure is your web app?

Get your security grade in seconds -- free, no account needed.

Raw evidence and timestamp per finding OWASP, NIS2, ISO 27001 and DORA mapping 66 checks across 25 categories

No account required · Free forever · No data stored

Not sure what to scan?

  1. 1 Enter your domain No login, no card.
  2. 2 66 checks run live Streamed in under 60s.
  3. 3 A-F grade + PDF Auditor-ready, NIS2 mapped.
OWASP Top 10 SSL/TLS DNS Security NIS2 Mapping ISO 27001
66
Controls
25
Categories
<60s
Full scan
A-F
Letter grade

Automated external-surface analysis. Complementary to a manual penetration test, not a replacement for one.

Computed per SaaSFort Check-Spec v0.1 · open methodology, versioned, MIT-licensed

Deterministic

66 controls, 25 categories, reproducible

Evidence

Raw evidence and a timestamp on every finding

Auditor-ready

Every finding tagged with its OWASP / NIS2 / ISO 27001 / DORA control

Evidence standard

What a security department gets, check by check

  • 66 controls across 25 categories

    A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared.

  • Raw evidence and a timestamp on every finding

    Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.

  • Mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA

    Mapping happens in the engine, so the export goes to the auditor without re-formatting.

  • Exposure confirmed by content signature

    Any exposed file or sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s.

SaaSFort performs automated external-surface analysis. It is complementary to a manual penetration test, not a replacement for one, and it does not detect business-logic flaws.