Sample report
A complete scan of a fictional estate. This is generated by the real scan engine, so it is exactly what the product produces — not a mockup.
northwind-financial.example is a fictional domain on the IANA-reserved .example TLD. We never publish reports about real organisations.
What every tier sees
HARVEST NOW, DECRYPT LATER
4 of 5 reachable hosts are exposed to harvest-now-decrypt-later: traffic sent to them today can be recorded now and decrypted once a sufficiently capable quantum computer exists.
Severity breakdown
| Grade | Hosts |
|---|---|
| A+ | 1 |
| D | 2 |
| F | 2 |
What Assessment and Monitoring do not include
Below Professional, the specifics are not sent to your browser at all — they are never included in the response. This is what is withheld:
- per host detail
Which host is affected, and which key-exchange algorithm each one negotiates. - cbom
Cryptographic Bill of Materials (CycloneDX JSON) covering every algorithm in use across the estate. - remediation roadmap
Prioritised remediation steps, ordered by harvest-now-decrypt-later exposure. - compliance mapping
Findings mapped to CNSA 2.0, FIPS 203/204/205, NIST, and PCI DSS. - attestation
Branded PDF attestation of scan results, grade, timestamp, and scope. - estate discovery
DNS-verified discovery of every subdomain and internet-facing service in the estate, not just the hosts covered by this scan.
What Professional and Enterprise add
The same scan, with every specific named.
| Host | Grade | Protocol | Key exchange | Exposure |
|---|---|---|---|---|
| www.northwind-financial.example | A+ | TLS 1.3 | X25519MLKEM768 | protected |
| api.northwind-financial.example | D | TLS 1.3 | x25519 | HNDL |
| checkout.northwind-financial.example | D | TLS 1.3 | x25519 | HNDL |
| mail.northwind-financial.example | F | TLS 1.2 | secp256r1 | HNDL |
| vpn-legacy.northwind-financial.example | F | TLS 1.0 | none (static RSA key exchange) | HNDL |
Certificate inventory
| Host | Key | Signature | Expires in |
|---|---|---|---|
| www.northwind-financial.example | ECDSA 256 | ECDSA-SHA256 | 74 days |
| api.northwind-financial.example | RSA 2048 | SHA256-RSA | 41 days |
| checkout.northwind-financial.example | RSA 2048 | SHA256-RSA | 41 days |
| mail.northwind-financial.example | RSA 2048 | SHA256-RSA | 12 days |
| vpn-legacy.northwind-financial.example | RSA 1024 | SHA1-RSA | 6 days |
Why one host is graded F
This host negotiates secp256r1, a classical key exchange. Data you transmit today can be recorded now and decrypted later, once a sufficiently capable quantum computer exists. This is not a future risk to the data — the recording happens today.
Rules applied
kex.classical_no_tls13— Classical key exchange with no TLS 1.3 path (score 30)proto.deprecated— Deprecated TLS versions accepted (RFC 8996) (score 40)suite.weak— Weak cipher suites accepted (score 60)cert.expiring— Certificate expires within 30 days (score 70)cert.classical_signature— Quantum-vulnerable certificate signature (informational) (score -5)
Every grade lists the exact rules that produced it. The full rubric is published.
Scan your own estate
SecretSpan scans only after payment, and only the domain you nominate.