HTTP/HTTPS and headers
Checks HTTPS, redirects, and defensive headers that help reduce unnecessary exposure.
Security Inspector performs an authorized passive assessment of a website's public surface, turns technical findings into a clear score, and prioritizes what should be fixed first.
Security Inspector combines web, TLS, DNS, email, and browser-facing controls into one assessment with scoring, context, and remediation.
Checks HTTPS, redirects, and defensive headers that help reduce unnecessary exposure.
Reviews protocol, encryption, certificate dates, and key strength from the public service perspective.
Evaluates DNS configuration signals and the presence of DNSSEC as part of the domain's public posture.
Checks SPF, DMARC, MTA-STS, and TLS-RPT to highlight domain email hardening opportunities.
Analyzes visible browser policies, cookie attributes, and redirect behavior.
Detects security.txt and performs lightweight technology identification without exploitation or intrusive enumeration.
Enter the domain and confirm your organization owns or manages the target and is authorized to assess it.
Kairoseth processes passive checks against the public surface under operational safety limits.
Review score, findings, remediation, history and, on Pro, generate a clean PDF or email the report.
The report explains what was observed, why it matters, and what action is recommended. Free lets you evaluate the product with a clearly identified preview PDF; Pro generates clean reports ready for clients or internal teams.
The assessment keeps the technical context while presenting results so they can be reviewed, prioritized, and shared.
Quotas are enforced server-side and Pro capacity belongs to the organization that activates Security Inspector.
For trying the assessment and maintaining a basic security reference.
For organizations that need more capacity and client-ready results.
Security Inspector is designed for public targets the organization owns, manages, or is authorized to assess. The product does not perform exploitation, credential attacks, private scanning, or destructive testing. Target authorization is recorded before an assessment can run.
Kairoseth separates identity, organization scope, product roles and product capabilities. A login route, browser state or AI response never becomes an authorization boundary by itself.
Customer resources and access are resolved inside an active organization context rather than treated as global account state.
Owner, Admin and Member authority is assigned per product. Organization membership alone does not automatically grant every product.
Sensitive access, policy and capability decisions remain authoritative on the server instead of trusting client UI state or model output.
Capabilities that can act are introduced behind explicit grants, staged gates and audit rather than implied autonomy.
Review the customer-facing policies that define privacy, security reporting, acceptable use and the current legal operating framework.
No. Commercial v1 is passive and limited to authorized public signals. It does not perform exploitation, password attacks, or destructive testing.
Not for the current assessment. Add the authorized domain in Kairoseth and the analysis runs against the accessible public surface.
Free includes 1 site, 3 monthly assessments, and a watermarked PDF. Pro expands to 10 sites and 50 monthly assessments, adds clean PDF, complete history/comparisons, and report email.
Yes. Pro can generate a clean PDF. Product Owner and Product Admin can also email the report from the assessment result.
No. The report reflects observable public signals at that time. It helps prioritize improvements but does not replace a full audit, penetration test, or code review when those are required.
Users need product access within an organization and must confirm target authorization. Kairoseth applies organization- and product-scoped permissions.
Create your account, activate Security Inspector for your organization, and add an authorized site.