Scan the public surface
Enter an authorized domain. Qourby reviews externally visible headers, TLS, DNS, cookies, and metadata.
Website exposure, made visible
Run a free, non-invasive scan of a domain you are authorized to review. Qourby turns public headers, TLS, DNS, cookies, and metadata into a clear, prioritized report.
How it works
Enter an authorized domain. Qourby reviews externally visible headers, TLS, DNS, cookies, and metadata.
See prioritized findings, affected assets, evidence, and plain-English context without digging through raw output.
Move from one-off checks to saved history, scheduled scans, exports, and shared remediation workflows.
Built for the work after detection
Technical evidence stays attached to plain-English context, affected assets, and remediation guidance—so the result is useful beyond the security team.
Explore a sample reportFindings queue
12 open across 8 sitesapp.example.com
www.example.com
api.example.com
The response does not publish a CSP header, which can increase the impact of some content injection mistakes.
content-security-policy: —Start with a report-only policy, review violations, then enforce the smallest required source list.
Free public scan
CSP, HSTS, framing, content-type, and referrer signals.
Certificate visibility, expiry windows, and public HTTPS behavior.
Public A, AAAA, CNAME, and other externally observable records.
Framework and server details exposed by responses and HTML.
Browser-visible Secure, HttpOnly, and SameSite attributes.
Headers and public clues that deserve review or hardening.
No password attacks, authenticated crawling, payload delivery, or internal discovery.
When one scan becomes a workflow
Compare scans and see whether posture is improving or drifting.
Recheck public assets without rebuilding the same review every time.
Turn technical findings into useful PDF and CSV review artifacts.
Assign, filter, and track findings across the people fixing them.
Use API keys and webhooks to connect scan events to your tooling.
Keep a consistent outside-in view across the sites you operate.
Simple starting points
For a fast public baseline.
For owners monitoring a few sites.
For shared remediation work.
Security and scope
Qourby is built for authorized, public-surface visibility. These answers keep that boundary explicit.
No. It is a non-invasive review of externally visible security signals. It does not attempt exploitation, password testing, login testing, or internal network discovery.
Only scan domains you own or are explicitly authorized to review. The public flow is designed for legitimate outside-in visibility, not unsolicited testing.
You receive a report preview with prioritized public findings. A paid workspace adds saved history, scheduling, exports, and team remediation workflows.
No automated public scan replaces a scoped penetration test or expert review. Qourby helps teams find and track visible baseline issues between deeper assessments.
Start with what is already public