What an automated external assessment can assess
Automated assessment works from the outside in, using the same public signals an attacker can gather before ever attempting anything intrusive. That view is genuinely useful because misconfiguration and forgotten exposure are common and visible.
- Whether HTTPS is present and correctly configured, and the state of the public TLS certificate.
- Browser-facing HTTP response headers such as Strict-Transport-Security, Content-Security-Policy, X-Frame-Options and X-Content-Type-Options.
- Public DNS configuration and the email-authentication records SPF, DKIM and DMARC published for the domain.
- Publicly reachable hosts, services and subdomains associated with the domain, including ones the business may have forgotten.
- Publicly visible technology and version signals that indicate software worth reviewing or updating.
- Public reputation and threat-intelligence signals associated with the domain and its hosts.
