Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 63 of 65|Showing 3101-3150 of 3226
smartstream-stp.com favicon

SmartStream Technologies ltd.

smartstream-stp.com

0
FinanceUnited KingdomlargeHIGH

SmartStream Technologies ltd. is a well-established leader in financial data solutions, serving banks, capital markets, buy-side firms, and corporations. Their offerings focus on operational control, cost reduction, risk mitigation, regulatory compliance, and new revenue streams. The company maintains a strong market position with a comprehensive portfolio of services including data transformation, regulatory alignment, managed services, and innovation labs. The website reflects a professional and consistent brand image targeting financial institutions and related sectors. Technically, the website is built on WordPress using Elementor and Slider Revolution, hosted behind Cloudflare for security and performance. It integrates multiple marketing and analytics tools such as Google Analytics 4, Google Tag Manager, Pardot, LinkedIn Insight Tag, and various media embedding services. Mobile optimization and SEO practices are good, though accessibility is basic. Security posture is weakened by the absence of a valid SSL certificate and lack of HTTPS enforcement, despite Cloudflare protection and Wordfence plugin usage. Security headers are present but could be enhanced with HSTS and OCSP stapling. Privacy compliance is strong with clear GDPR-aligned policies, cookie consent mechanisms, and a data protection officer contact. Overall, the website presents a credible and professional front for SmartStream Technologies but requires urgent SSL/TLS remediation to improve security and trustworthiness. Strategic recommendations include SSL installation, enhanced security headers, and continuous monitoring of third-party integrations.

40
33
5
50
-
85
100
financetechnologydatasolutionsregulatorycompliancemarketingautomation+2 more
WordPressElementorSlider RevolutionCloudflare CDN and security+12

Partner Domains:

salesforce.com
partner67
2025-06-15T21:48:58.577Z
ethicalworkforce.co.uk favicon

Ethical Workforce

ethicalworkforce.co.uk

0
HospitalityUnited KingdomsmallHIGH

Ethical Workforce is a specialist hospitality recruitment agency based in London, offering permanent and temporary staffing solutions with an international reach. The company targets both employers seeking hospitality staff and jobseekers looking for roles in the hospitality sector. Their website presents a professional image with clear service offerings and client testimonials from notable hospitality figures, positioning them as a trusted niche player in the recruitment market. Technically, the website is built on WordPress using PHP 7.4 and Apache, with common plugins such as Yoast SEO and WPBakery Page Builder. Google Tag Manager is used for analytics and marketing tracking. The site is mobile optimized and SEO friendly, but lacks performance metrics data. The hosting provider is not explicitly identified but uses hdodns.com nameservers. From a security perspective, the site has critical weaknesses: it does not have an SSL/TLS certificate installed, serving content over HTTP only, which severely impacts user trust and data security. No modern TLS protocols or security headers are present. Cookie consent is implemented, but no privacy policy or terms of service pages were found, indicating compliance gaps. Contact information is clearly provided, enhancing business credibility. Overall, the website is functional and professional but requires urgent security improvements, especially implementing HTTPS and enhancing privacy compliance. Strategic recommendations include obtaining a valid SSL certificate, adding comprehensive privacy and terms pages, and improving security headers to protect users and build trust.

15
-
-
50
-
85
100
hospitalityrecruitmentlondonjobseekersemployers+3 more
PHP 7.4.33ApacheWordPress 6.8.1Yoast SEO plugin+5
2025-06-15T21:48:55.560Z
c-tec.co.uk favicon

C-TEC

c-tec.co.uk

0
OtherUnited KingdomsmallCRITICAL

The website c-tec.co.uk serves primarily as a minimal landing page that redirects visitors to the main corporate website c-tec.com. It lacks substantive content about the business, its services, or contact information. The site is built on WordPress using the Divi theme and includes jQuery libraries. However, it suffers from significant security and compliance shortcomings, including the absence of an SSL certificate, no privacy or cookie policies, and no visible contact or security incident response information. Performance is slow, and SEO and accessibility features are minimal. Overall, the site appears to be a placeholder rather than a fully developed business portal. From a technical perspective, the site is hosted on Google Cloud infrastructure and uses standard WordPress technologies. The lack of HTTPS and security headers exposes it to potential risks and undermines user trust. No analytics or tracking tools are detected, indicating minimal user data collection. The DNS configuration is standard but lacks advanced security features like DNSSEC or DMARC. Security posture is weak due to missing HTTPS, lack of security headers, and no visible security or incident response policies. The absence of privacy and cookie policies also indicates non-compliance with GDPR and related regulations. No vulnerability disclosure or security.txt files are present to guide security researchers. The domain registration data is consistent with the UK presence and business identity, supporting legitimacy, but the website itself lacks professionalism and trust signals. Strategically, the site should prioritize implementing HTTPS, adding comprehensive privacy and cookie policies, and providing clear contact and security incident response information. Improving site performance, SEO, and accessibility would also enhance user experience and trust. These steps are critical to align the website with modern security and compliance standards and to support the business's digital credibility.

35
-
5
50
-
75
-
wordpressdiviplaceholderminimalnossl+1 more
WordPressDivi ThemejQueryDivi
2025-06-15T21:47:20.787Z
slipcase.com favicon

Slipcase

slipcase.com

0
FinanceUnited KingdomsmallMEDIUM

Slipcase is a specialized content platform serving the global (re)insurance industry by aggregating and curating relevant news, insights, and thought leadership. The platform targets industry professionals and organizations, offering personalized dashboards, mobile app access, and organizational content distribution with reporting. The business is UK-based, established in 2000, and operates a niche service model focused on finance and insurance sectors. Technically, the website employs modern JavaScript modules, external libraries like Animate.css, and integrates marketing and analytics tools such as HubSpot and LinkedIn. Hosting is on Amazon AWS infrastructure. However, the website suffers from slow load times and lacks a valid SSL certificate, which significantly impacts security and user trust. From a security perspective, the absence of HTTPS, security headers, and domain protection measures exposes the site to risks and undermines compliance with modern security standards. Privacy compliance is basic, with policies present but lacking explicit consent mechanisms. Contact information is available, but no phone numbers are provided. Overall, Slipcase presents a professional and content-rich platform with good business credibility but requires urgent improvements in security posture and technical performance to enhance trust and compliance.

90
25
25
50
50
70
100
insurancereinsuranceindustrynewscontentcurationfinance
JavaScript ES ModulesAnimate.cssGoogle Fonts (Roboto)HubSpot scripts+4
2025-06-15T13:15:10.077Z
try.be favicon

Five Nines Digital Ltd

try.be

0
HospitalityUnited KingdomsmallHIGH

Trybe is a specialized SaaS provider offering next-generation bookings and business management software tailored for the spa and leisure industry. The platform targets spa businesses seeking to streamline their booking processes, inventory management, team scheduling, and payment processing. Positioned as a cloud-based, open-API solution, Trybe emphasizes ease of use, integration capabilities, and operational efficiency. The company is UK-based, operating under Five Nines Digital Ltd, and holds ISO27001 certification, reinforcing its commitment to security standards. Technically, the website is built using modern web technologies including React and Gatsby, with Tailwind CSS for styling. Hosting appears to be on AWS infrastructure. While the site is well-designed, mobile-optimized, and rich in content, performance is hindered by slow load times and a high number of resources. SEO and accessibility features are well implemented, contributing to a positive user experience. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability impacting user trust and data protection. No major vulnerabilities or exposed sensitive data were detected, and the presence of ISO27001 certification and GDPR-compliant privacy policies indicate a mature security posture. However, improvements in SSL/TLS configuration and security headers are urgently recommended. Overall, Trybe presents a professional and credible business offering with strong market positioning in the hospitality sector. The main risk lies in its current SSL/TLS configuration, which should be addressed promptly to ensure secure communications and maintain customer trust.

15
-
25
75
50
85
100
spabookingsbusinessmanagementsoftwarecloud+2 more
ReactGatsbyTailwind CSSStripe+3
2025-06-15T13:11:16.135Z
aviva.com favicon

Aviva plc

aviva.com

0
FinanceUnited KingdomenterpriseHIGH

Aviva plc is a leading diversified insurer headquartered in the United Kingdom, offering a broad range of insurance, wealth management, and retirement services primarily across the UK, Ireland, and Canada. The company targets investors, shareholders, career seekers, and socially conscious individuals, positioning itself as a trusted financial services provider with a strong market presence and extensive subsidiary network. The website reflects a professional and comprehensive corporate portal with rich investor relations content, leadership profiles, and sustainability initiatives. Technically, the website leverages modern JavaScript frameworks, Adobe Experience Manager CMS, and Akamai CDN for content delivery. It integrates advanced analytics and marketing tools such as Adobe Helix RUM and OneTrust for privacy compliance. The site is mobile-optimized, accessible, and SEO-friendly, providing a high-quality user experience. From a security perspective, while several best practices are implemented including CSP, X-Content-Type-Options, and HSTS headers, the SSL certificate is invalid and no TLS protocols are enabled, representing a critical vulnerability that undermines secure communications. No WAF or blocking mechanisms are detected, and privacy policies are comprehensive and GDPR compliant. The domain registration data aligns well with the business claims, indicating high legitimacy. Overall, the website is professional and credible but requires urgent remediation of SSL and TLS issues to ensure secure user interactions and maintain trust.

65
33
5
50
-
85
100
insurancefinancecorporateinvestorrelationssustainability+2 more
JavaScriptReact componentsHandlebarsRequireJS+6

Partner Domains:

marsh.com
partner66
slipcase.com
partnerpending
2025-06-15T13:07:55.360Z
phscompliance.co.uk favicon

phs Compliance Limited

phscompliance.co.uk

0
EnergyUnited KingdomlargeHIGH

phs Compliance Limited is a well-established UK-based company specializing in statutory electrical and fire safety testing and remedial services. With a large workforce and nationwide coverage, it holds a leading market position in the energy and facilities management sectors. The company offers a broad range of compliance and maintenance services, including electrical inspections, mechanical maintenance, fire and security projects, and electric vehicle charging solutions. Their website reflects a professional business model targeting commercial and public sector clients across the UK. Technically, the website employs modern web technologies such as Google Tag Manager, Bootstrap, and a CMS platform (DuoCMS). However, performance is hindered by slow load times and a large page size. Mobile optimization and SEO are adequately addressed, but accessibility is basic. The site lacks a valid SSL certificate and HTTPS support, which is a critical security deficiency. No security headers or incident response policies are publicly available, indicating gaps in security posture. Security-wise, the absence of HTTPS and security headers significantly lowers the site's security score. While no active vulnerabilities or WAF blocks are detected, the lack of encryption exposes users to risks. Privacy compliance is moderate, with cookie consent implemented and GDPR policies present, but tracking scripts raise privacy considerations. Business credibility is strong, supported by clear contact information, accreditations, and consistent branding. Overall, the website is functional and professional but requires urgent security improvements, especially SSL implementation, to protect users and enhance trust. Strategic recommendations include enabling HTTPS, adding security headers, publishing security policies, and optimizing performance to improve user experience and compliance.

60
33
5
50
-
70
40
electricalinspectionfiresafetystatutorycompliancemaintenanceserviceselectricvehiclecharging+1 more
Google Tag ManagerjQuery (implied by Bootstrap classes)Bootstrap CSSGoogle Fonts (Ubuntu)+2
2025-06-15T13:07:47.339Z
I

Identity Protection Service

dnsspy.io

0
TechnologyUnited KingdomsmallMEDIUM

DNS Spy is a specialized technology company offering DNS monitoring, alerting, and backup services primarily targeting organizations and individuals responsible for DNS management. The company provides a SaaS platform that enables users to monitor DNS changes, receive alerts, validate DNS configurations, and maintain DNS backups with advanced features such as AXFR zone transfer support. The website content is professionally presented with clear navigation and relevant information about the services offered. The technical infrastructure leverages modern frontend technologies including Bootstrap, Font Awesome, jQuery, and Laravel Livewire, hosted behind Cloudflare with domain registration via Amazon Registrar. However, the website currently lacks a valid SSL/TLS certificate and does not enforce HTTPS, which is a critical security vulnerability. Additionally, security headers and advanced TLS features are missing, reducing the overall security posture. Privacy compliance is partial, with a privacy policy present but no cookie policy or consent mechanism detected. Contact information is available via email and contact forms, supporting user engagement. The domain registration is mature and consistent with the business, enhancing trustworthiness. Overall, DNS Spy demonstrates a solid business and technical foundation but requires urgent improvements in security practices to protect users and data effectively.

60
43
25
55
85
80
100
dnsmonitoringdnssecuritydnsbackupdnsalertstechnology+1 more
BootstrapFont AwesomejQueryGoogle Analytics+2
2025-06-15T12:00:02.540Z
katapult.io favicon

Krystal Hosting Ltd

katapult.io

0
TechnologyUnited KingdommediumMEDIUM

Katapult, operated by Krystal Hosting Ltd, is a cloud infrastructure provider focused on delivering high-speed, reliable, and scalable virtual infrastructure solutions tailored for developers and teams. The company emphasizes ease of use, transparency, and sustainability, positioning itself as a competitive player in the cloud technology sector with a strong commitment to renewable energy and certified business practices. The website presents a professional and comprehensive overview of its services, targeting technology professionals and businesses seeking cloud infrastructure with pay-as-you-go pricing. Technically, the website is built on modern frameworks such as Next.js and React, with good mobile optimization and accessibility features. However, the site suffers from a critical security shortfall due to the absence of a valid SSL certificate, resulting in no HTTPS support. This significantly impacts the security posture and user trust. Privacy and cookie policies are well implemented with consent mechanisms, and the site uses Google Tag Manager for analytics and marketing. Security-wise, while no major vulnerabilities or exposed sensitive data were detected, the lack of HTTPS and security headers is a major concern. No explicit security or incident response policies are published, and no vulnerability disclosure or security.txt files are present. The domain registration data is consistent and mature, supporting the legitimacy of the business. Overall, Katapult demonstrates strong business credibility and technical maturity but must urgently address its SSL/TLS configuration to improve security and trust. Strategic recommendations include installing a valid SSL certificate, enabling security headers, and publishing security policies to enhance compliance and incident readiness.

90
25
25
50
100
85
100
cloudvirtualmachinesinfrastructuredeveloperspubliccloud+2 more
Next.jsReactGoogle Tag ManagerSVG icons+1
2025-06-15T11:49:43.430Z
bristol.ac.uk favicon

University of Bristol

bristol.ac.uk

0
EducationUnited KingdomlargeHIGH

The University of Bristol operates a comprehensive and professional website serving prospective and current students, staff, alumni, and the wider community. The site provides detailed information on undergraduate and postgraduate courses, research activities, and community engagement, positioning the university as a leading educational institution in the UK and globally. The website content is well-structured, accessible, and rich in relevant information, reflecting a strong digital presence. Technically, the website employs modern JavaScript frameworks such as StencilJS and integrates tracking and analytics tools like Google Tag Manager and TrackedWeb. However, the site suffers from significant performance issues, including a slow load time and a large page size, which could impact user experience. Mobile optimization and accessibility are well addressed, contributing positively to overall usability. From a security perspective, the website exhibits critical weaknesses, notably the absence of a valid SSL certificate and HTTPS support, exposing users to potential data interception risks. Additionally, no security headers or advanced TLS protocols are enabled, and no incident response or vulnerability disclosure policies are publicly available. Privacy compliance is strong, with comprehensive privacy and cookie policies aligned with GDPR requirements. Overall, while the University of Bristol's website excels in content quality and business credibility, urgent improvements in security infrastructure and performance optimization are necessary to enhance trust and protect users. Strategic recommendations include implementing HTTPS, enabling security headers, optimizing performance, and publishing clear security policies.

15
15
5
50
-
85
100
educationuniversityresearchcoursesstudents+1 more
JavaScriptGoogle Tag ManagerTrackedWebTermly+1
2025-06-15T08:35:24.132Z
flexport.org favicon

Flexport Inc

flexport.org

0
TransportationUnited KingdomlargeHIGH

Flexport.org is a non-profit initiative under Flexport Inc that leverages logistics to facilitate global aid delivery and promote sustainability. The organization supports humanitarian relief efforts, discounted shipping for NGOs, and climate programs to reduce transport emissions. Their market position is strong within the humanitarian logistics sector, supported by partnerships with reputable NGOs and a clear mission to improve aid delivery efficiency. Technically, the website is built on modern frameworks like React and Gatsby, hosted on Amazon AWS, and employs advanced technologies such as Google reCAPTCHA and Mapbox GL JS. The site demonstrates good performance, mobile optimization, and accessibility, reflecting a mature digital infrastructure. Security posture is solid with HTTPS enforced using TLS 1.3 and strong cipher suites, absence of known vulnerabilities, and security headers that protect domain registration. However, improvements such as enabling HSTS, OCSP stapling, and DMARC records could enhance security further. Overall, the website is trustworthy, professional, and compliant with privacy regulations including GDPR. No blocking or WAF interference was detected, allowing full content access and analysis. Strategic recommendations include enhancing security headers and transparency measures to maintain and improve trust.

65
43
25
40
87
75
100
non-profitlogisticshumanitariansustainabilityaid+2 more
ReactGatsbyGoogle reCAPTCHAKetch (consent management)+1

Partner Domains:

flexport.com
parent68
2025-06-15T06:13:32.317Z
17capital.com favicon

17Capital

17capital.com

0
FinanceUnited KingdommediumMEDIUM

17Capital is a specialized private credit manager focused on providing NAV finance solutions to private equity investors and management companies globally. Founded in 2008 and headquartered primarily in the UK and US, the firm has established itself as a leading player in the private equity finance sector, offering a range of financing products tailored to portfolio growth and liquidity needs. The website reflects a professional and content-rich digital presence, leveraging WordPress and WP Engine hosting, with strong SEO and structured data implementations to enhance discoverability and user engagement. However, the technical infrastructure shows gaps in SSL certificate validity and HTTPS enforcement, which undermines security posture despite well-configured security headers. The site integrates multiple marketing and analytics tools, including Google Analytics and HubSpot, but lacks a cookie consent mechanism, indicating partial privacy compliance. Contact mechanisms rely on forms and partner emails, with no direct phone or physical address details prominently displayed. Overall, the website demonstrates high business credibility and professionalism but requires urgent remediation of SSL issues and enhanced privacy compliance to improve security and user trust.

80
25
25
50
50
85
100
privateequitynavfinancefinanceinvestmentprivatecredit+3 more
jQueryVimeo PlayerYoast SEOHubSpot Forms+4

Partner Domains:

prosek.com
partnerpending
h-advisors.global
partnerpending
2025-06-14T22:40:16.587Z