arrow_backBack to results

Your readiness report — preview

This is the document you’ll hand to a customer’s security review, a vendor onboarding form, or an investor. Understanding and fixing issues is always free — the report is what you share with others.

At a glance

Included free
Target
https://example.com
Issues
78
Check type
Public, passive

Helps prepare for ISO/SOC 2-style security reviews and vendor questionnaires. Pazmo does not certify compliance or guarantee audit results.

checklistFramework readiness

Readiness mapping only — evidence relevant to these controls. Pazmo does not determine, certify, or guarantee compliance. See full framework coverage.

  • A.5.7 · Threat intelligenceISO/IEC 27001:2022

    1 related finding: security.txt is not visible

  • A.8.21 · Security of network servicesISO/IEC 27001:2022

    4 related findings: DMARC policy is not enforcing, DMARC record is not visible, SPF record is not visible, No CAA record is visible

  • A.8.24 · Use of cryptographyISO/IEC 27001:2022

    4 related findings: Strict-Transport-Security is not visible, HTTPS certificate expires soon, Legacy TLS version is negotiated, No CAA record is visible

  • A.8.3 · Information access restrictionISO/IEC 27001:2022

    1 related finding: Cookie security flags are not visible

  • A.8.8 · Management of technical vulnerabilitiesISO/IEC 27001:2022

    1 related finding: security.txt is not visible

  • A.8.9 · Configuration managementISO/IEC 27001:2022

    5 related findings: Content Security Policy is not visible, Frame embedding protection is not visible, X-Content-Type-Options nosniff is not visible, Referrer-Policy is not visible, Permissions-Policy is not visible

  • CC6.6 · Logical access — external boundary protectionSOC 2

    2 related findings: Content Security Policy is not visible, Frame embedding protection is not visible

  • CC6.7 · Transmission and movement of informationSOC 2

    4 related findings: Strict-Transport-Security is not visible, HTTPS certificate expires soon, Legacy TLS version is negotiated, Cookie security flags are not visible

  • CC7.1 · Detection of vulnerabilities and configuration changesSOC 2

    1 related finding: security.txt is not visible

shield_personDeclared security posture

Self-reported

Answered by you on the results page — Pazmo has not verified these. Reviewers see them as your own declaration, kept separate from scan evidence.

  • Is MFA on for email, GitHub, and your cloud console?radio_button_uncheckedNot answered yet
  • Does the team use a password manager — no reused passwords?radio_button_uncheckedNot answered yet
  • Do you have regular backups — and have you tested a restore?radio_button_uncheckedNot answered yet
  • Do you review who has access — and remove people who left?radio_button_uncheckedNot answered yet
  • Do you apply dependency and server updates regularly?radio_button_uncheckedNot answered yet
  • Does your team know how to report a phishing email?radio_button_uncheckedNot answered yet
  • Are secrets kept in a manager, not in code or repos?radio_button_uncheckedNot answered yet
  • Are work laptops encrypted with screen lock on?radio_button_uncheckedNot answered yet
  • Do you have a written security policy the team can find?radio_button_uncheckedNot answered yet
  • Do you keep a list of your systems, domains, and data stores?radio_button_uncheckedNot answered yet
  • Do you check the security of vendors/SaaS that handle your data?radio_button_uncheckedNot answered yet
  • Do you have a plan for what to do if you're breached?radio_button_uncheckedNot answered yet
  • Does the team get basic security awareness training?radio_button_uncheckedNot answered yet
  • Do you limit admin / privileged access to only who needs it?radio_button_uncheckedNot answered yet
  • Is malware / endpoint protection on company devices?radio_button_uncheckedNot answered yet

In the full report

Unlocks with verification
ios_sharelock

Shareable report link & PDF

Send one link to a customer's security review instead of a screenshot.

historylock

Retest history

Every fix re-verified, with dates — proof that issues stayed fixed.

folder_ziplock

Evidence appendix

The raw observations behind each finding, packaged for reviewers.

monitor_heartlock

Continuous monitoring

Pazmo re-checks weekly and warns you before anything regresses.

verified_userVerify https://example.com to unlock the full report

Verification proves you own the site. Sharing and monitoring are part of the paid plan — finding and fixing issues stays free.