flagNeeds attentionhttps://example.comvisibilityDemo evidence · Medium confidence
workspace_premiumLevel 2

15 cards on your run map.

Clear a card to advance the run — each fix levels up your security.

check_circle6/21 checks clearedstars300 XP

infoReadiness guidance: This helps prepare for reviews, but it is not a formal audit.

styleYour run· 15 to play

routeRun map· tap an area to focus its cards
Showing
lockSome cards are locked until ownership is verified

To protect site owners, deeper findings stay face-down until you prove you own — or are authorized to check — this target.

  • category2 items in publicly exposed files
verified_userVerify to reveal
mapSide quests — basics scans can’t see0/15 self-reported

These are the breach paths a scan can’t check — and they matter most. Your answers are self-reported, not verified by Pazmo, and stay on this device.

Is MFA on for email, GitHub, and your cloud console?

Account takeover is the most common way small companies get breached — and MFA stops almost all of it.

  1. Turn on 2-step / MFA in your email provider (Google, Microsoft).
  2. Enable 2FA in GitHub org settings and require it for members.
  3. Enable MFA in your cloud console (AWS, GCP, Azure) for all admins.
Your answer — Pazmo can’t verify this.
auto_awesomeRelics — optional hardening6/21 checks cleared5 relics available

These aren’t problems — they’re relics that make your run stronger. Tap one to see how to equip it.

verified1 already equipped
assignment_turned_inShow this run to a customer or investor?Preview the shareable readiness report for https://example.com.arrow_forward
verified_userUnlock report and retestOwnership not verified · Verification is required before external sharing, saved report actions, or retest execution. Agent delivery remains locked in this preview.arrow_forward