Ithildin
Aegis · Web security Scanned from Switzerland

Sovereign web security. Scanned from Switzerland.

Aegis scans your outward web attack surface from Swiss infrastructure — transport security, headers, mail authentication, exposed services, known vulnerabilities — and grades the posture in seconds. Then it helps you close the gaps, and keeps watching. Built for businesses, websites, enterprises, and individuals.

Aegis scan · example example-company.ch B 78 / 100 · 24 checks · 3 findings
TLS 1.3 · HSTSPass
Security headersPass
Content-Security-PolicyMediumPolicy permits inline scripts. Tighten to nonce- or hash-based sources.
SPF · DKIM · DMARCLowDMARC policy is p=none. Move to quarantine, then reject.
Exposed surfacesInfoA staging subdomain answers on the public internet.
Certificate hygienePass
01 — What Aegis scans

The whole outward surface. Not just the homepage.

Everything an attacker can reach without credentials is in scope: transport security, application headers, mail authentication, exposed infrastructure, and the fingerprints of known vulnerabilities.

A-01

TLS posture

Protocol versions, cipher suites, forward secrecy, HSTS — the transport layer, verified from the outside.

A-02

Header hardening

Security headers graded against current guidance: frame ancestors, content-type sniffing, referrer policy, permissions policy.

A-03

Content Security Policy

CSP presence, strictness, and bypassable directives — the one control that decides what a compromised page can load.

A-04

DNS & email authentication

SPF, DKIM, and DMARC alignment, plus DNS hygiene — so spoofing of your domain gets rejected by enforcing receivers, and your records leak nothing they shouldn't.

A-05

Exposed surfaces

Forgotten subdomains, staging environments, admin panels, and open services that answer on the public internet.

A-06

Known-CVE fingerprints

Version fingerprints of servers, frameworks, and plugins matched against published vulnerabilities — before someone else matches them.

A-07

Certificate hygiene

Expiry, chain integrity, weak keys, and forgotten certificates across every hostname you own.

A-08

Cookie & session flags

Secure, HttpOnly, and SameSite attributes on every cookie that matters — the difference between a session and a stolen one.

A-09

Information leakage

Server banners, verbose errors, directory listings, and metadata that map your stack for anyone who asks.

02 — How it works

Scan. Harden. Keep watching.

Aegis scans from Swiss infrastructure, under Swiss jurisdiction. No agents to install, no code to change — the scan sees exactly what an attacker sees.

Seconds Step 01

Scan & grade

Point Aegis at a domain. It maps the outward surface, runs every check, and returns a graded report — one letter, one score, every finding ranked by severity.

Days Step 02

Harden

Every finding ships with a concrete remediation path. Your team closes the gaps — or ours works through them with you, configuration by configuration — and Aegis re-scans until the grade holds.

Continuous Step 03

Monitor

Surfaces drift: certificates expire, headers regress, subdomains appear. Aegis re-scans on a schedule and alerts on any regression from your accepted baseline.

03 — Aegis vs Shield

Two perimeters. One posture.

Aegis and Shield answer different questions. Aegis looks outward, at what an attacker can reach. Shield looks inward, at what your compliance perimeter must contain.

Ithildin Aegis Outward · Attack surface · Live

What can they reach?

The view from outside your walls: every host, header, record, and certificate an attacker can probe without credentials.

  • Scans the public attack surface from Swiss infrastructure
  • Grades posture in seconds; ranks findings by severity
  • Hardening guidance and continuous regression monitoring
  • No agents, no code changes, no access required
Ithildin Shield Inward · Compliance perimeter · Pipeline

What must stay inside?

Designed to govern the inside of the perimeter: where data lives, who touches it, and how that is proven to a regulator.

  • Inward-facing compliance and data-boundary controls
  • Engineered to FADP, FINMA-circular, and ISG requirements
  • Audit evidence generated where the data lives
  • In the platform pipeline — not yet generally available
Shield in the pipeline
04 — Engagement

From a single scan to a standing watch.

Every engagement is scoped and quoted before work begins — the scope is the site, the estate, or the portfolio. No tiers, no per-seat mathematics.

E-01

Single scan

One domain, one graded report, every finding with a remediation path. The fastest way to know where you stand. Scoped per engagement.

E-02

Hardening sprint

We close the gaps with your team — headers, DNS, certificates, configuration — and re-scan until the grade holds. Scoped per engagement.

E-03

Continuous monitoring

Scheduled re-scans across your estate, alerts on regression, and a posture report your leadership can read. Scoped per estate.

Grade your posture. Then close the gaps.

Tell us what you run — a single site or a full estate — and we reply within two Swiss business days.