A free, non-invasive check of your encryption and how ready it is for the new post-quantum standards. For public websites and private, internal systems. Fix it yourself, or let us.
Nothing to install. We only look at what your website already shows every visitor, and you can see exactly what we ran.
Use it on systems the whole internet can reach and on systems only your staff can reach. Either way, the check only looks.
Your website, customer portal, webmail or online shop. Type the address and we check it from here in seconds.
Check a public website →Intranets, admin pages and business applications inside your network. We can't see in, so you run one short command yourself and choose what to share. Needs a free account, and you must be an admin of your organisation.
Check internal systems →The check makes a handful of ordinary connections, the same as a browser opening the page, and reads how the server answers. It never logs in, never changes anything, and never tries to break in.
Read exactly what it runs →Built for companies without a security team. Plain English, one question at a time.
Enter your website. In seconds you get a short list of what's fine and what needs attention, with one sentence on why each matters.
Answer three questions and get step-by-step instructions for your server, including how to back up first and how to undo it.
Follow the plan, pass it to your IT person, or have us make the change and confirm it worked.
Most security tools ask you to trust them. We'd rather show you.
Start with your website. The rest is there when you're ready.
Outdated connection versions, certificate problems and post-quantum readiness, for your site and other addresses under your domain.
Check a website →Not technical? Follow our picture guide to check a certificate yourself in Chrome, Edge, Firefox or Safari. Four clicks, nothing to install.
Show me how →Intranets, admin pages and business applications. Upload a list or type them in, and run one command yourself. For signed-in admins.
Check internal systems →Where MD5 and SHA-1 still hide: certificates, SSH, VPNs, stored passwords and more, with the steps to move to SHA-2.
Get the guide →Passwords and access keys left in your code's history, and how to replace each one safely.
Check your code →Encrypted data sent today can be recorded now and decrypted later, once quantum computers arrive. NIST has published the replacement standards and set dates for retiring today's encryption.
It takes about 30 seconds and there's nothing to sign up for.
Check my website