Your readiness report — preview
This is the document you’ll hand to a customer’s security review, a vendor onboarding form, or an investor. Understanding and fixing issues is always free — the report is what you share with others.
At a glance
Included free- Target
- https://example.com
- Issues
- 78
- Check type
- Public, passive
Helps prepare for ISO/SOC 2-style security reviews and vendor questionnaires. Pazmo does not certify compliance or guarantee audit results.
checklistFramework readiness
Readiness mapping only — evidence relevant to these controls. Pazmo does not determine, certify, or guarantee compliance. See full framework coverage.
- A.5.7 · Threat intelligenceISO/IEC 27001:2022
1 related finding: security.txt is not visible
- A.8.21 · Security of network servicesISO/IEC 27001:2022
4 related findings: DMARC policy is not enforcing, DMARC record is not visible, SPF record is not visible, No CAA record is visible
- A.8.24 · Use of cryptographyISO/IEC 27001:2022
4 related findings: Strict-Transport-Security is not visible, HTTPS certificate expires soon, Legacy TLS version is negotiated, No CAA record is visible
- A.8.3 · Information access restrictionISO/IEC 27001:2022
1 related finding: Cookie security flags are not visible
- A.8.8 · Management of technical vulnerabilitiesISO/IEC 27001:2022
1 related finding: security.txt is not visible
- A.8.9 · Configuration managementISO/IEC 27001:2022
5 related findings: Content Security Policy is not visible, Frame embedding protection is not visible, X-Content-Type-Options nosniff is not visible, Referrer-Policy is not visible, Permissions-Policy is not visible
- CC6.6 · Logical access — external boundary protectionSOC 2
2 related findings: Content Security Policy is not visible, Frame embedding protection is not visible
- CC6.7 · Transmission and movement of informationSOC 2
4 related findings: Strict-Transport-Security is not visible, HTTPS certificate expires soon, Legacy TLS version is negotiated, Cookie security flags are not visible
- CC7.1 · Detection of vulnerabilities and configuration changesSOC 2
1 related finding: security.txt is not visible
shield_personDeclared security posture
Self-reportedAnswered by you on the results page — Pazmo has not verified these. Reviewers see them as your own declaration, kept separate from scan evidence.
- Is MFA on for email, GitHub, and your cloud console?radio_button_uncheckedNot answered yet
- Does the team use a password manager — no reused passwords?radio_button_uncheckedNot answered yet
- Do you have regular backups — and have you tested a restore?radio_button_uncheckedNot answered yet
- Do you review who has access — and remove people who left?radio_button_uncheckedNot answered yet
- Do you apply dependency and server updates regularly?radio_button_uncheckedNot answered yet
- Does your team know how to report a phishing email?radio_button_uncheckedNot answered yet
- Are secrets kept in a manager, not in code or repos?radio_button_uncheckedNot answered yet
- Are work laptops encrypted with screen lock on?radio_button_uncheckedNot answered yet
- Do you have a written security policy the team can find?radio_button_uncheckedNot answered yet
- Do you keep a list of your systems, domains, and data stores?radio_button_uncheckedNot answered yet
- Do you check the security of vendors/SaaS that handle your data?radio_button_uncheckedNot answered yet
- Do you have a plan for what to do if you're breached?radio_button_uncheckedNot answered yet
- Does the team get basic security awareness training?radio_button_uncheckedNot answered yet
- Do you limit admin / privileged access to only who needs it?radio_button_uncheckedNot answered yet
- Is malware / endpoint protection on company devices?radio_button_uncheckedNot answered yet
In the full report
Unlocks with verificationShareable report link & PDF
Send one link to a customer's security review instead of a screenshot.
Retest history
Every fix re-verified, with dates — proof that issues stayed fixed.
Evidence appendix
The raw observations behind each finding, packaged for reviewers.
Continuous monitoring
Pazmo re-checks weekly and warns you before anything regresses.
Verification proves you own the site. Sharing and monitoring are part of the paid plan — finding and fixing issues stays free.