What SecQon checks — every external security test, explained
This is the full list of what SecQon sends to a site you have proved you own, grouped the way it appears in your report. Each page says which scan profile runs the tests, which plan includes it, and what we do not test, because a report is only useful if you know where its edges are. Across all profiles, six of the ten OWASP Top 10 (2021) categories — A01, A02, A03, A05, A06 and A08 — have purpose-built tests, A07 is covered in part, and A10 (SSRF) is assessed on Deep scans. A04 (Insecure Design) and A09 (Security Logging and Monitoring Failures) cannot be assessed from outside by anyone, and every report names them.
TLS & certificates
Certificate trust and expiry, and whether your server still accepts TLS 1.0 or 1.1.
Light, and therefore also Standard and Deep. Runs on every plan, on the free instant check and on the Free plan’s monthly re-check.
Security headers & cookies
Missing or ineffective HSTS, CSP, clickjacking, nosniff and Referrer-Policy headers, plus cookie flags.
Light, and therefore also Standard and Deep. Runs on every plan and on the free instant check. Deep scans extend it to every crawled page.
DNS & email security
SPF, DMARC, CAA and DNSSEC — the records that stop spoofed email and mis-issued certificates.
Light, and therefore also Standard and Deep. Runs on every plan and on the free instant check. Subdomain-takeover templates run on Standard and Deep.
Exposed ports & services
36 high-risk TCP ports — databases, container control planes, remote admin — checked with one connect each.
Standard and Deep scans. Never part of Light or the free instant check. Free accounts can launch a Standard scan manually; paid plans also run it on the daily monitoring scan.
API security
Your API’s own schema, read as an outsider: open operations, GraphQL introspection, CORS and leaked stack traces.
Standard and Deep scans, on every plan (Free can launch Standard manually). The IDOR/BOLA and mass-assignment tests run only on Deep + pentest, which is Business or the one-off pentest report.
Web application pentest
A browser-rendered crawl plus bounded proofs for XSS, SQL injection and SSRF, and an active scanner on the pentest tier.
Deep (Growth and Business, and the one-off pentest report). The active scanner, WAF measurement and API account tests run on Deep + pentest, which needs Business or the one-off report and a separate acknowledgement.
How this maps to the OWASP Top 10
Together these checks cover 7 of the 10 OWASP Top 10 (2021) categories — A10 where the out-of-band collector is configured, on Deep scans. A07 is partial, and A04 (Insecure Design) and A09 (Security Logging and Monitoring Failures) cannot be assessed from outside by anyone. Read the category-by-category coverage.
See what a scan finds on your own asset
Free for one verified asset, no card needed. Paid plans add the written report, more assets and deeper scans.