What we check
We apply the same security and configuration principles to our own infrastructure that we recommend to our clients. The numbers below measure exactly that: external security posture, HTTP headers, and TLS configuration, the same aspects we assess when working with our clients.
An external assessment of our infrastructure's observable security posture, carried out with no privileged access.
HTTP header configuration and browser security mechanisms. Mozilla's scale adds points above 100 for hardening beyond the baseline.
TLS configuration, certificate chain, and resistance to known vulnerabilities, tested across every server we publish.
We also hold a top score (100/100) on Google PageSpeed Insights. That's not a security indicator, but it shows the same technical care applied to another part of our operation.
Last verified: September 2026.
Independent Verification
We don't ask you to take our word for it. You can reproduce these results right now, with the same free public tools: Qualys SSL Labs, Mozilla HTTP Observatory, and PageSpeed Insights. These aren't screenshots. They're public, repeatable checks.
Security isn't just what we recommend to clients. It's a standard we hold our own operation to.
Want to assess the security and configuration of your own infrastructure?
Talk to Cyvra