Scan & grade
Point Aegis at a domain. It maps the outward surface, runs every check, and returns a graded report — one letter, one score, every finding ranked by severity.
Aegis scans your outward web attack surface from Swiss infrastructure — transport security, headers, mail authentication, exposed services, known vulnerabilities — and grades the posture in seconds. Then it helps you close the gaps, and keeps watching. Built for businesses, websites, enterprises, and individuals.
Everything an attacker can reach without credentials is in scope: transport security, application headers, mail authentication, exposed infrastructure, and the fingerprints of known vulnerabilities.
Protocol versions, cipher suites, forward secrecy, HSTS — the transport layer, verified from the outside.
Security headers graded against current guidance: frame ancestors, content-type sniffing, referrer policy, permissions policy.
CSP presence, strictness, and bypassable directives — the one control that decides what a compromised page can load.
SPF, DKIM, and DMARC alignment, plus DNS hygiene — so spoofing of your domain gets rejected by enforcing receivers, and your records leak nothing they shouldn't.
Forgotten subdomains, staging environments, admin panels, and open services that answer on the public internet.
Version fingerprints of servers, frameworks, and plugins matched against published vulnerabilities — before someone else matches them.
Expiry, chain integrity, weak keys, and forgotten certificates across every hostname you own.
Secure, HttpOnly, and SameSite attributes on every cookie that matters — the difference between a session and a stolen one.
Server banners, verbose errors, directory listings, and metadata that map your stack for anyone who asks.
Aegis scans from Swiss infrastructure, under Swiss jurisdiction. No agents to install, no code to change — the scan sees exactly what an attacker sees.
Point Aegis at a domain. It maps the outward surface, runs every check, and returns a graded report — one letter, one score, every finding ranked by severity.
Every finding ships with a concrete remediation path. Your team closes the gaps — or ours works through them with you, configuration by configuration — and Aegis re-scans until the grade holds.
Surfaces drift: certificates expire, headers regress, subdomains appear. Aegis re-scans on a schedule and alerts on any regression from your accepted baseline.
Aegis and Shield answer different questions. Aegis looks outward, at what an attacker can reach. Shield looks inward, at what your compliance perimeter must contain.
The view from outside your walls: every host, header, record, and certificate an attacker can probe without credentials.
Designed to govern the inside of the perimeter: where data lives, who touches it, and how that is proven to a regulator.
Every engagement is scoped and quoted before work begins — the scope is the site, the estate, or the portfolio. No tiers, no per-seat mathematics.
One domain, one graded report, every finding with a remediation path. The fastest way to know where you stand. Scoped per engagement.
We close the gaps with your team — headers, DNS, certificates, configuration — and re-scan until the grade holds. Scoped per engagement.
Scheduled re-scans across your estate, alerts on regression, and a posture report your leadership can read. Scoped per estate.
Tell us what you run — a single site or a full estate — and we reply within two Swiss business days.