Security Maturity Score

Security Maturity Score

5-domain maturity score (NIST CSF style).

Privacy: answers stay in your browser. We do not record your responses.
Identify function — if you don't know what you have, you can't protect it.
Identify function — the governing document.
Protect function — the single highest-impact control.
Protect function — modern equivalent of antivirus.
Recover function — only real measure of resilience.
Detect function — no logs, no detection.
Respond function — rehearse before the real thing.
Human layer — often the weakest.
Protect function — dormant accounts are the top attacker pivot.
Protect function — blast radius reduction.
Protect function — 90% of exploits target known CVEs.
Respond function — don't improvise during a breach.
Score
Answer the questions above to see your score.

Vendor Risk Analyzer

Vendor Risk Analyzer

SOC 2 / data-handling / breach-history checklist for any vendor.

Privacy: answers stay in your browser. We do not record your responses.
Non-negotiable for anyone handling your data.
GDPR/CCPA compliance relies on this.
TLS in transit + AES-256 at rest is table stakes.
GDPR requirement; asks whether they will tell you fast.
Asks whether YOUR data sits behind their MFA.
EU customers need EU data residency typically.
Their vendors are your vendors too.
Signals they take breach risk seriously financially.
Reassurance they plan for the bad days.
Data portability = escape hatch if things go wrong.
Google them; check FTC complaints and court records.
A past breach isn't automatically disqualifying but demands extra care.
Score
Answer the questions above to see your score.

IP Reputation Checker

IP Reputation Checker

Cross-reference an IP against simple reputation heuristics.

Privacy: the message text is sent to our server only for this analysis — we do not store it.
Include the whole message — subject line, sender, body.

Malware Redirect Detector

Malware Redirect Detector

User-agent / referer based redirect traps used by malware operators.

Privacy: the message text is sent to our server only for this analysis — we do not store it.
Include the whole message — subject line, sender, body.

Gig Job Scam Detector

Gig Job Scam Detector

TikTok / Upwork / Fiverr easy-money gig red flags.

Privacy: the message text is sent to our server only for this analysis — we do not store it.
Include the whole message — subject line, sender, body.

College Scam Detector

College Scam Detector

Diploma mills, fake online programs, prepaid tuition scams.

Privacy: the message text is sent to our server only for this analysis — we do not store it.
Include the whole message — subject line, sender, body.

Scholarship Scam Checker

Scholarship Scam Checker

You won a scholarship — pay this fee patterns.

Privacy: the message text is sent to our server only for this analysis — we do not store it.
Include the whole message — subject line, sender, body.

Sender Reputation Checker

Sender Reputation Checker

IP / domain reputation for any From address — red flag patterns.

Privacy: the message text is sent to our server only for this analysis — we do not store it.
Include the whole message — subject line, sender, body.

Fake Recruiter Email Checker

Fake Recruiter Email Checker

LinkedIn-style recruiter emails analysed for fake-job tells.

Privacy: the message text is sent to our server only for this analysis — we do not store it.
Include the whole message — subject line, sender, body.