flagNeeds attentionhttps://example.comvisibilityDemo evidence · Medium confidence
workspace_premiumLevel 215 cards on your run map.
Clear a card to advance the run — each fix levels up your security.
check_circle6/21 checks clearedstars300 XP
infoReadiness guidance: This helps prepare for reviews, but it is not a formal audit.
styleYour run· 15 to play
routeRun map· tap an area to focus its cards
Showing
Browser protectionsyncHow to clear it
- Add a Content-Security-Policy header.
- Start in Report-Only mode.
- Retest for a CSP or CSP-Report-Only header.
After fixing
Pazmo checks for CSP or CSP-Report-Only on the target.
SOC 2 SecurityISO/IEC 27001 evidenceVendor review
Scammers can embed your sitesyncHow to clear it
- Decide whether the service should allow any third-party embedding.
- Add X-Frame-Options: DENY or SAMEORIGIN, or add a CSP frame-ancestors directive.
- Collect fresh response-header evidence showing frame protection.
After fixing
Sanitized response headers showing X-Frame-Options or CSP frame-ancestors on the public target.
Browser hardeningVendor readiness
Logins can travel over plain HTTPsyncHow to clear it
- Confirm the production domain and required subdomains serve HTTPS correctly.
- Start with an HSTS max-age appropriate for the rollout risk.
- Increase max-age and consider includeSubDomains only after validating subdomain readiness.
After fixing
Sanitized response headers showing Strict-Transport-Security on the public target.
Transport securityVendor readiness
To protect site owners, deeper findings stay face-down until you prove you own — or are authorized to check — this target.
- category2 items in publicly exposed files
verified_userVerify to revealThese are the breach paths a scan can’t check — and they matter most. Your answers are self-reported, not verified by Pazmo, and stay on this device.
Is MFA on for email, GitHub, and your cloud console?
Account takeover is the most common way small companies get breached — and MFA stops almost all of it.
- Turn on 2-step / MFA in your email provider (Google, Microsoft).
- Enable 2FA in GitHub org settings and require it for members.
- Enable MFA in your cloud console (AWS, GCP, Azure) for all admins.
Your answer — Pazmo can’t verify this.
These aren’t problems — they’re relics that make your run stronger. Tap one to see how to equip it.
verified1 already equipped
assignment_turned_inPreview the shareable readiness report for https://example.com.arrow_forward