
Is smartsurvey.co.uk Safe? Security Analysis for SmartSurvey
Check if smartsurvey.co.uk is a scam or legitimate. Free security scan and reviews.
AI Summary
SmartSurvey is a UK-based enterprise providing advanced online survey software and feedback solutions. Positioned as the UK's leading feedback platform, it serves a broad range of customers including enterprises, public sector organizations, and non-profits. The company offers a comprehensive suite of services including survey creation, AI-powered text and sentiment analysis, dashboards, integrations, and managed services. Their business model is SaaS-based with tiered subscription plans catering to various customer needs. The website reflects a mature digital presence with excellent content quality, clear navigation, and strong branding consistency. Technically, the website leverages modern web technologies such as Webflow CMS, Google Analytics, Facebook Pixel, and LinkedIn Insight Tag, ensuring robust analytics and marketing capabilities. The site is mobile-optimized and performs well, with good accessibility and SEO practices. Security posture is strong, with HTTPS enforced, ISO27001 certification, and compliance with GDPR, HIPAA, and CCPA. Cookie consent mechanisms and privacy policies are comprehensive, supporting privacy compliance. No blocking or WAF challenges were detected, allowing full content access and analysis. The WHOIS lookup failed due to querying the subdomain rather than the registered domain, but this does not detract from the legitimacy of the business as evidenced by the website content and trust signals. Overall, SmartSurvey demonstrates a high level of professionalism, security, and compliance suitable for enterprise customers. Strategic recommendations include enhancing security header visibility, publishing an incident response contact, and adding a vulnerability disclosure policy to further strengthen trust and security posture.
Detected Technologies
🧠AI Business Intelligence
Technology stack, business insights, and market analysis powered by AI.
Business Intelligence
Market & Strategic Analysis
SmartSurvey holds a strong market position in the UK as a leading survey and feedback platform, trusted by over 600,000 customers including government and major brands. Its competitive advantages include AI-powered analysis, enterprise-grade security, and a comprehensive feature set tailored for various industries and functions. The SaaS subscription model with multiple plans allows scalability and affordability. The company targets business customers needing reliable, secure, and compliant survey solutions. Growth indicators include multi-award recognition and a broad partner ecosystem. The website content and structure reflect a mature and well-resourced organization with a clear focus on customer success and data-driven decision making.
Extracted Contact Information
Marketing Intelligence Data
Phone Numbers (1)
Physical Addresses (1)
Security Posture Analysis
Comprehensive Security Assessment
The website and company demonstrate a mature security posture with ISO27001 certification, FSQS accreditation, and compliance with GDPR, HIPAA, and CCPA. HTTPS is enforced site-wide, and cookie consent mechanisms are implemented. No exposed sensitive data or vulnerable libraries were detected. However, explicit security headers like Content-Security-Policy and X-Frame-Options were not visibly confirmed and should be verified. Incident response contact information and vulnerability disclosure policies are not publicly found, representing areas for improvement. Overall, the security culture appears strong with a focus on UK data hosting and enterprise-grade protections.
Strategic Recommendations
Priority Actions for Security Improvement
Verify and explicitly implement security headers such as Content-Security-Policy, X-Frame-Options, and X-Content-Type-Options.
✨Observations
AI-powered comprehensive website and business analysis.
AI-Enhanced Website Analysis
Business Insights
SmartSurvey
SmartSurvey is a UK-based provider of digital survey solutions. Our customers trust our user-friendly yet advanced online survey software to gather the information they need to make smart decisions. All our solutions are GDPR compliant, built for enterprise but affordable for everyone and are backed with exceptional support and secure UK data storage.
excellent
consistent
Technical Stack
fast
excellent
good
good
Security Assessment
- HTTPS enforced
- Cookie consent banner with granular controls
- ISO27001 certified
- GDPR, HIPAA, CCPA compliance stated
- No exposed sensitive data in HTML
- Use of security-focused third party scripts
Analytics & Tracking
Advertising & Marketing
Website Quality Assessment
Key Observations
Website is fully accessible with rich content and no blocking detected
🛡️Security Headers
HTTP security headers analysis and recommendations.
Security Headers
HTTP security headers analysis
Missing Content-Security-Policy header
HIGHControls resources the browser is allowed to load
Weak Referrer-Policy configuration
LOWCurrent value: "no-referrer-when-downgrade"
Sensitive data may be cached
LOWCache-Control header should include "no-store" for sensitive pages
👤GDPR Compliance
Privacy and data protection assessment under GDPR regulations.
GDPR Compliance
Privacy and data protection assessment
No Cookie Policy found
HIGHGDPR requires clear information about cookie usage
No Cookie Consent Banner found
HIGHGDPR requires explicit consent for non-essential cookies
No Data Protection Officer mentioned
LOWLarge organizations may need to designate a DPO under GDPR
GDPR Compliance Analysis
🛡️NIS2 Compliance
Network & Information Security Directive compliance assessment.
NIS2 Compliance
Network & Information Security Directive
No vulnerability disclosure policy
MEDIUMNIS2 encourages coordinated vulnerability disclosure
No incident response procedures found
HIGHNIS2 requires documented incident response and business continuity plans
No business continuity planning found
MEDIUMNIS2 emphasizes operational resilience and business continuity
No security contact information
HIGHNIS2 requires clear incident reporting channels
No vulnerability reporting mechanism
MEDIUMClear vulnerability reporting supports coordinated disclosure
No NIS2 reference found
LOWConsider explicitly mentioning NIS2 compliance efforts
📧Email Security
SPF, DKIM, and DMARC validation and email security assessment.
Email Security
SPF, DKIM, and DMARC validation
DMARC Partial Enforcement
LOWDMARC only applies to 1% of messages
No BIMI Record
LOWBIMI displays brand logos in email clients
No MTA-STS Policy
MEDIUMMTA-STS enforces TLS for email delivery
No TLS-RPT Record
LOWTLS-RPT provides reporting for email TLS issues
SPF Details
DKIM Selectors Found
DMARC Details
🏆SSL/TLS Security
Certificate validity and encryption analysis.
SSL/TLS Security
Certificate validity and encryption analysis
Partial SSL/TLS Assessment
LOWCompleted 2 of 4 security checks due to time constraints
Certificate Details
OCSP Status
📊DNS Health
DNS configuration and security assessment.
DNS Health
DNS configuration and security assessment
DNSSEC Not Enabled
MEDIUMDNSSEC is not configured for this domain
Domain Transfer Lock Not Enabled
MEDIUMDomain can be transferred without authorization
Domain Delete Lock Not Enabled
LOWDomain can be deleted without additional verification
Domain Registration Details
- •No domain protection locks enabled
DNS Records
DNSSEC Status
DNS Performance
SPF Analysis
⚡Network Security
Port scanning and network exposure analysis.
Network Security
Port scanning and network exposure analysis
High-Risk Service Exposed: FTP
HIGHPort 21 (FTP) is publicly accessible - FTP - Often unencrypted file transfer
Service Exposed: SSH
MEDIUMPort 22 (SSH) is publicly accessible - SSH - Secure but can be brute-forced
Critical Service Exposed: Telnet
CRITICALPort 23 (Telnet) is publicly accessible - Telnet - Unencrypted remote access
High-Risk Service Exposed: RPC
HIGHPort 135 (RPC) is publicly accessible - RPC - Windows RPC endpoint
High-Risk Service Exposed: NetBIOS
HIGHPort 139 (NetBIOS) is publicly accessible - NetBIOS - Windows file sharing
Critical Service Exposed: SMB
CRITICALPort 445 (SMB) is publicly accessible - SMB - Windows file sharing, high risk
Critical Service Exposed: MSSQL
CRITICALPort 1433 (MSSQL) is publicly accessible - MSSQL - Database server
Critical Service Exposed: Oracle
CRITICALPort 1521 (Oracle) is publicly accessible - Oracle - Database server
Critical Service Exposed: MySQL
CRITICALPort 3306 (MySQL) is publicly accessible - MySQL - Database server
Critical Service Exposed: RDP
CRITICALPort 3389 (RDP) is publicly accessible - RDP - Remote Desktop, prime ransomware target
Critical Service Exposed: PostgreSQL
CRITICALPort 5432 (PostgreSQL) is publicly accessible - PostgreSQL - Database server
Critical Service Exposed: Redis
CRITICALPort 6379 (Redis) is publicly accessible - Redis - In-memory database
High-Risk Service Exposed: Elasticsearch
HIGHPort 9200 (Elasticsearch) is publicly accessible - Elasticsearch - Search engine
Critical Service Exposed: MongoDB
CRITICALPort 27017 (MongoDB) is publicly accessible - MongoDB - NoSQL database
🔧Technical Analysis
Detailed technical findings and analysis from AI assessment.
Technical Analysis
Comprehensive security assessment findings