Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 294 of 294|Showing 14651-14699 of 14699
solarisbank.com favicon

Solarisbank AG

solarisbank.com

0
FinanceGermanylargeMEDIUM

Solarisbank AG operates as a leading embedded finance platform in Europe, offering a comprehensive Banking-as-a-Service solution that enables businesses to integrate digital banking, payment, lending, and identification services via advanced RESTful APIs. The company holds a full German banking license, allowing it to operate seamlessly across EU countries. Solarisbank targets businesses seeking to embed financial services into their products, positioning itself as a neutral B2B2X partner with a strong market presence and trusted by major innovators such as Samsung and American Express. Technically, Solarisbank's website is built on modern frameworks including React and Gatsby, hosted on Netlify, and leverages Contentful as a CMS. The platform demonstrates excellent performance, mobile optimization, and accessibility, with a well-structured navigation and high-quality content. Analytics are implemented via piwik.pro, reflecting a moderate level of user tracking with good privacy compliance. From a security perspective, Solarisbank employs robust HTTP security headers including HSTS with preload, X-Frame-Options, and Content-Security-Policy, although the absence of enabled TLS protocols is a notable gap. The site lacks a cookie consent mechanism and a public vulnerability disclosure page, but provides clear contact channels for incident reporting and names key compliance officers, including a Money Laundering Reporting Officer. Overall, Solarisbank presents a high level of professionalism, trustworthiness, and technical maturity. Strategic recommendations include enabling modern TLS protocols, refining CSP policies, implementing cookie consent, and publishing a vulnerability disclosure policy to further enhance security posture and regulatory compliance.

80
43
25
100
75
85
100
solarisbankbankbankingplatformdigital+5 more
ReactGatsbyNetlify

Partner Domains:

solarisgroup.com
servicepending
whispli.com
servicepending
2025-06-14T12:59:03.944Z
dekra-akademie.de favicon

DEKRA Akademie GmbH

dekra-akademie.de

0
EducationGermanylargeMEDIUM

DEKRA Akademie GmbH is a well-established German education and training provider specializing in professional development, certification, and continuing education across multiple sectors including transportation, healthcare, and technology. The company operates a comprehensive digital platform leveraging Salesforce Visualforce and Azure Search technologies, supported by a robust consent management system via Usercentrics. Their market position is strong with a nationwide presence and a broad portfolio of courses and services tailored to both private individuals and corporate clients. The website demonstrates high content quality, consistent branding, and clear navigation, supporting a positive user experience. Security posture is good with valid SSL certificates, HSTS, and content security policies, though the absence of modern TLS protocols and DNSSEC indicates room for improvement. Privacy and cookie policies are comprehensive and GDPR compliant, reflecting a mature approach to data protection. Overall, the digital infrastructure supports the business model effectively, though enhancements in security protocols and incident response transparency would further strengthen trust and resilience.

70
18
25
85
80
85
100
EducationTrainingCertificationDEKRACompliance+5 more
JavaScriptVisualforce (Salesforce)Azure SearchUsercentrics CMP+4

Partner Domains:

dekra.de
parent69
dekra-neo.com
relatedpending

+1 more partners

2025-06-14T12:47:13.462Z
heyflow.com favicon

Heyflow GmbH

heyflow.com

0
TechnologyGermanymediumMEDIUM

Heyflow GmbH is a technology company specializing in no-code lead generation solutions, offering interactive lead funnels, multi-step forms, and customizable landing pages. Positioned as a user-friendly platform with native analytics and extensive integrations, Heyflow targets performance marketers, designers, agencies, and enterprises seeking to optimize lead conversion. The company is based in Germany and founded in 2020, with a medium-sized operational scale. Technically, Heyflow employs modern web technologies including Eleventy for static site generation, Cloudflare and Netlify for hosting and CDN, and integrates analytics tools like Matomo and Google Analytics. The website demonstrates excellent performance, mobile optimization, and SEO practices. Security-wise, Heyflow maintains a strong posture with ISO 27001 certification, GDPR compliance, robust security headers, and HSTS enabled, though TLS protocols could be updated for enhanced security. The company actively manages user consent and privacy through Usercentrics CMP and provides clear legal documentation. Overall, Heyflow presents a professional, trustworthy, and technically mature digital presence with a focus on security and compliance.

95
43
25
100
75
85
100
lead generationno-codeinteractive formslanding pagesA/B testing+4 more
EleventyCloudflareNetlifyMatomo Analytics+6

Partner Domains:

trust.heyflow.com
service
get.heyflow.com
service

+1 more partners

2025-06-14T12:27:02.555Z
superfund.de favicon

Die neue Dimension der Geldanlage-Investieren in eine digitale Zukunft

superfund.de

0
financeGermanymediumMEDIUM

The website's security posture is currently weak, with significant deficiencies across multiple critical areas including privacy compliance, email authentication, and security policy frameworks. Critical gaps in GDPR adherence expose the business to regulatory penalties and reputational damage, especially given its EU operations without adequate privacy measures. The absence of key HTTP security headers leaves the site vulnerable to common web-based attacks such as clickjacking, content injection, and cross-site scripting. Email infrastructure lacks essential authentication mechanisms, increasing risks of phishing and email spoofing. Additionally, missing incident response and security documentation undermines the organization’s ability to detect, respond to, and recover from security incidents effectively. While SSL/TLS and DNS configurations are relatively stronger, urgent attention is needed to enable HSTS and extend certificate validity. Overall, this assessment reveals a pressing need to implement foundational security controls and compliance policies to safeguard the business and its customers. Failure to address these issues promptly could result in severe operational, financial, and legal consequences.

15
15
17
55
80
85
90
financeinvestmentdigital financecookie consent
JavaScriptCookiebotnginxJavaScript modules

Partner Domains:

superfundgroup.com
subsidiarypending
wirecard.com
paymentpending

+1 more partners

2025-06-13T18:13:49.869Z