Skip to main content

Is sandoz.com a Scam? Security Check Results - Sandoz Reviews

sandoz.com favicon

Is sandoz.com Safe? Security Analysis for Sandoz

Check if sandoz.com is a scam or legitimate. Free security scan and reviews.

HealthcareN/aenterprise
ReactNext.jsGoogle Tag Manager
Analyzed 9/7/2025Completed 9:21:21 AM
74
Security Score
MEDIUM RISK

AI Summary

Sandoz is a global leader in generic and biosimilar medicines, dedicated to pioneering access to medicines for patients worldwide. The website reflects a mature enterprise with a comprehensive corporate structure, including sections for business, people and culture, impact, media, investors, careers, and contact information. The company targets patients, healthcare professionals, investors, and business partners, offering generics, biosimilars, manufacturing, and B2B services. Technically, the website is built on modern frameworks such as Next.js and React, hosted on Amazee.io infrastructure, and integrates Google Tag Manager for analytics. The site is well-optimized for mobile and SEO, with good accessibility features. Security posture is strong with HTTPS enforced and no visible vulnerabilities, though security headers could be improved. Privacy compliance is good with a comprehensive privacy policy and GDPR adherence, but lacks a visible cookie consent mechanism. WHOIS data is unavailable, which slightly impacts trust but the website's professional presentation and content quality support legitimacy. Overall, the site is a robust digital asset for a large healthcare enterprise.

Detected Technologies

ReactNext.jsGoogle Tag Manager

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

Sandoz operates in the healthcare sector focusing on generics and biosimilars, positioning itself as a global leader. The business model revolves around pharmaceutical manufacturing and distribution, targeting multiple stakeholders including patients, healthcare providers, investors, and partners. The company emphasizes corporate governance, ethics, sustainability, and innovation. The website content highlights recent news, corporate assurance, and investor relations, indicating a transparent and well-structured organization. The absence of WHOIS data is a minor concern but does not detract from the company's established market presence. The digital ecosystem includes modern web technologies and analytics tools, supporting data-driven decision-making and marketing efforts.

Security Posture Analysis

Comprehensive Security Assessment

The website demonstrates a mature security posture with HTTPS enabled and no exposed sensitive information. However, the absence of key security headers such as Content-Security-Policy and X-Frame-Options suggests room for improvement. No vulnerability disclosures or incident response contacts are publicly available, which could be enhanced to improve transparency and readiness. Privacy policies are comprehensive and GDPR compliant, but cookie consent mechanisms are not evident, potentially impacting compliance. Overall, the security measures are adequate for a corporate website but could be strengthened to align with best practices and regulatory expectations.

Strategic Recommendations

Priority Actions for Security Improvement

1

Implement and publish a security.txt file or vulnerability disclosure policy to facilitate responsible reporting.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

Sandoz

Description:

Sandoz is the global leader in generic and biosimilar medicines. Our Purpose is to pioneer access to medicines for patients globally.

Key Services:
Generic medicinesBiosimilar medicinesManufacturing, quality and supplyBusiness-to-business services
Content Quality:

excellent

Branding:

consistent

Technical Stack

Technologies:
ReactNext.jsGoogle Tag Manager
Frameworks:
Next.js
Performance:

moderate

Mobile:

good

Accessibility:

good

SEO:

good

Security Assessment

Security Score:
85/100
Best Practices:
  • HTTPS enforced
  • No exposed sensitive data in HTML
  • Use of Google Tag Manager for analytics

Analytics & Tracking

Services:
Google Tag Manager
Tracking Level:moderate
Privacy Compliance:good

Advertising & Marketing

Transparency Level:basic

Website Quality Assessment

Design Quality:excellent
User Experience:excellent
Content Relevance:excellent
Navigation Clarity:excellent
Professionalism:excellent
Trustworthiness:high

Key Observations

1

Website is fully accessible with rich content and navigation

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

55/100
Score

Weak X-Frame-Options configuration

LOW

Current value: ""SAMEORIGIN" always"

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing Referrer-Policy header

LOW

Controls referrer information sent with requests

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

53/100
Score

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

No Data Protection Officer mentioned

LOW

Large organizations may need to designate a DPO under GDPR

Privacy policy may not be GDPR compliant

MEDIUM

Privacy policy lacks explicit GDPR compliance elements

GDPR Compliance Analysis

Privacy Policy85% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
phone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

25/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

100/100
Score
No issues found
SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
SPF Details
Record:
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:spf-0019ad02.pphosted.com include:spf.protection.outlook.com -all
DNS Lookups:3/10
Policy:-all
DKIM Selectors Found
Selector:selector1(1416-bit rsa)
Selector:selector2(1416-bit rsa)
Selector:s1(1440-bit rsa)
DMARC Details
Policy:reject
Subdomain Policy:reject
Aggregate Reports:dmarc_rua@emaildefense.proofpoint.com
Forensic Reports:dmarc_ruf@emaildefense.proofpoint.com
MTA-STS Details

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

95/100
Score

SSL Certificate Expires Within 90 Days

MEDIUM

SSL certificate expires in 71 days

Partial SSL/TLS Assessment

LOW

Completed 2 of 4 security checks due to time constraints

Certificate Details

Subject:www.sandoz.com
Issuer:R10
Valid Until:11/17/2025 (71 days)
SANs:www.sandoz.com

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

85/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

Domain Registration Details

Domain Age
32 years(mature)
Expiry Risk
low(119 days)
Protection Level
strongDNSSEC OFF

DNS Records

A Records:151.101.194.191, 151.101.130.191, 151.101.66.191, 151.101.2.191
Name Servers:
ha1.markmonitor.zone
ha2.markmonitor.zone
ha3.markmonitor.zone
ha4.markmonitor.zone
MX Records:
0: sandoz-com.mail.protection.outlook.com
SOA:Serial: 2025080907, TTL: 3600s

DNSSEC Status

DNSSEC Not Enabled

DNS Performance

Resolution Time:149ms

SPF Analysis

SPF Record:
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:spf-0019ad02.pphosted.com include:spf.protection.outlook.com -all

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website uses a modern tech stack including React and Next.js, providing server-side rendering and good performance. Hosting is managed via Amazee.io, a known CMS and hosting provider for enterprise clients. Google Tag Manager is integrated for analytics and marketing. The site is mobile optimized with responsive design and good accessibility features. Performance is moderate with room for optimization in asset loading and caching. No deprecated or vulnerable libraries were detected in the HTML content. The site structure is clear and well-organized, supporting good SEO and user experience. Technical risks are minimal but could be further reduced by enhancing security headers and privacy controls.
Analyze Another Website