September 2026

A security grade from A to F, and the detail behind it

AuditSecurity

August’s audit showed it: a finding without a hierarchy helps nobody. The report now returns a score out of a hundred, its letter, and for every point lost the exact line to add to the server.

Why a grade

A list of six missing headers does not say which ones matter. The reader walks away with an inventory and no order of priority, which amounts to saying nothing. The grade starts at a hundred and subtracts. HSTS and Content-Security-Policy are worth eighteen points each, because they are the only two that close an entire class of attack: falling back to cleartext for the first, content injection for the second. X-Content-Type-Options and X-Frame-Options are worth eight, Referrer-Policy and Permissions-Policy six. Those harden, they do not protect on their own.

Without HTTPS, F, no discussion

When the page is not served over HTTPS, the grade drops to F and the detail is not computed. That is not display severity, it is the only honest reading: everything travels in cleartext, any intermediary reads and rewrites the page, and no header changes that. Adding hardening points on top of an open connection would produce a flattering, false grade.

What costs points beyond headers

Naming a header is not enough

“You are missing Permissions-Policy” means nothing to someone who does not administer a server. They leave without knowing whether to worry, or what to ask their host for. Every missing header therefore comes with three things: what it protects, what an attacker gains without it, and the line to copy as is. For HSTS that line is “Strict-Transport-Security: max-age=31536000; includeSubDomains”. These are the values our own API applies to its responses, with one exception: the content policy of an API that only serves JSON is too strict for a site loading its images and scripts, so we suggest a value fit for a website.

The same grade, continuously

The public audit and continuous monitoring share a single scoring function. The audit brings what it measures on top — the certificate, the domain’s DNS — while monitoring sticks to the headers of each response. The useful consequence: a monitored site’s grade is recomputed on every pass, and a drop shows up. A B that turns into a D is a release that removed a content policy. Nobody will tell you, the page still renders.

What the grade does not say

It measures presence, not tuning. A permissive content policy counts as present, and an A grade does not mean a site is safe: it means it has not forgotten the protections everyone forgets. The audit does not replace an application review, it reports what is missing and what regresses. That is little, it is measurable, and it is exactly what no team watches spontaneously.

See what it does on your own site

Free audit in 30 seconds — or record a journey and watch it daily.