Loading …
Public assessment results and documented ratings. Explore the areas checked or report a vulnerability privately.
Documented results from SSL Labs, Internet.nl and Hardenize for vaapadcapital.com.
TLS rating
TLS encryption and certificate configuration on the public endpoints.
Every endpoint checked in the report shares this rating.
View assessmentInternet standards
IPv6, DNSSEC and RPKI passed.
The HTTPS group did not fully pass; additional security options have recommendations.
View assessmentPassed partial checks
HTTPS, TLS, DNSSEC and HSTS passed.
Partial report: the DMARC check reports an error.
View assessmentTLS encryption and certificate configuration on the public endpoints.
Every endpoint checked in the report shares this rating.
A+ · View assessmentCheck security-related response headers.
Open checkHTTP configuration and security headers.
130 points · MDN reports 12 of 12 checks passed. Inline styles remain allowed; CORP is unset and rated neutral.
A+ · View assessmentHTTPS, TLS, DNSSEC and HSTS passed.
Partial report: the DMARC check reports an error.
Partial · View assessmentIPv6, DNSSEC and RPKI passed.
The HTTPS group did not fully pass; additional security options have recommendations.
95% · View assessmentLook up the domain in the HSTS preload list.
Open checkFind publicly logged certificates.
Open checkResults apply to the stated assessment date. Each provider checks different criteria and areas; open findings appear with the relevant result. Loading this page does not start a scan.
Report suspected vulnerabilities directly to us. A concise, reproducible description helps us assess the issue.
Subject: SECURITY — short summary
Use only accounts you own or are explicitly authorized to test. Do not send passwords, keys, session cookies or unredacted personal, broker or payment data. A minimal synthetic proof is sufficient.
These are policy targets, not guaranteed response or resolution times.
Please follow up if you have not heard back after 7 days. We coordinate public disclosure after a fix is deployed.
Scope, testing restrictions and disclosure process: Security policy on GitHub (opens in a new tab).
Scope, testing rules and disclosure guidance. Open the section you need.
Good-faith research conducted in accordance with this policy will not result in legal action from us. Please do not access, modify, or delete data belonging to other users; stop testing as soon as you can confirm an issue and report it.
The policy provides for acknowledgement with the researcher's permission. This page is not a complete register of received reports, and no conclusion about past findings should be drawn from it. No monetary bounty is offered under the current policy.