Public cryptographic exposure

See the cryptography visible on your public services.

Run a conservative TLS scan against one public hostname and one selected service. Every reported property includes deterministic evidence, confidence and coverage.

  • HTTPS, SMTP STARTTLS, IMAPS, POP3S or LDAPS
  • No port sweep, login, crawling or vulnerability exploitation
  • No internal infrastructure or repository scanning
Public cryptographic exposure scanLimited anonymous access

One exact hostname and one fixed service profile. No port sweep, authentication or application-content access.

4 public addresses max32 TLS attempts max5 min hard limit

Anonymous reports expire within 24 hours. Session, client-network and target-volume limits apply before contact. Do not submit credentials or private keys.

What the scan observes

Public evidence, not a complete inventory.

The scanner records safely observable TLS and X.509 metadata. It does not infer coverage it did not perform.

01

TLS negotiation

Bounded exact-version probes for TLS 1.0 through 1.3, with negotiated cipher and key-establishment metadata when available.

02

X.509 certificates

Public certificate fingerprints, subject, issuer, validity, key algorithm, key size, signature and presented chain order.

03

PQC relevance

Explainable treatment of observed public-key cryptography without a speculative readiness score or quantum-safety claim.

04

Coverage

Addresses and probes inspected, failures, omissions, safety limits and the systems that were explicitly not scanned.

Scope boundary

Internal services, subdomains, other ports, repositories, cloud resources, endpoints, authenticated services and public trust-store validation are not included in this scan.

Review the methodology →