Interactive sample report

See the signal. Understand the fix.

Explore how Qourby turns public scan evidence into a prioritized, plain-English security review.

Scan your domain
Public security report

Illustrative data · safe to explore

June 12, 2026 Report ready

Scanned asset

demo.qourby.com

https://demo.qourby.com
Public, non-invasive scope
64/100

Overall security score

Action required

5 review items across public checks

Review items

5Prioritized by severity

Checks passed

2Visible baseline controls

Coverage

7Outside-in checks
Executive summary

The demo target exposes several medium-priority public hardening gaps across browser and cross-origin controls. The highest-value next step is to review the missing browser security policies before expanding monitoring.

Priority findings

What deserves attention first.

5 findings shown
medium01

Content-Security-Policy header

The site does not appear to publish a Content-Security-Policy header. This header can reduce the impact of some script injection and content loading mistakes.

Affected surfaceHTTP response headers

Observed evidence

content-security-policy: —
Recommended next stepStart in report-only mode, review required sources, then enforce a narrow policy.
medium02

X-Frame-Options header

The public response does not appear to publish a frame-embedding policy. Confirm that pages cannot be embedded by untrusted sites in a misleading context.

Affected surfaceHTTP response headers

Observed evidence

server: framework-hint
Recommended next stepRemove unnecessary framework and version details from public responses.
medium03

Cross-origin resource sharing policy

A public response appears to allow broad cross-origin access. Confirm that sensitive data is limited to trusted origins and is never exposed with credentials.

Affected surfacePublic API response policy

Observed evidence

server: framework-hint
Recommended next stepRemove unnecessary framework and version details from public responses.
low04

Strict-Transport-Security header

The public response does not include an HSTS policy. HSTS tells browsers to keep using HTTPS after the first successful secure visit.

Affected surfaceHTTPS configuration

Observed evidence

strict-transport-security: —
Recommended next stepConfirm HTTPS coverage, then publish an HSTS policy with an appropriate max-age.
low05

Technology hints

Some framework or server hints may be exposed in public responses. Reducing unnecessary version details can limit easy fingerprinting.

Affected surfacePublic headers and HTML

Observed evidence

server: framework-hint
Recommended next stepRemove unnecessary framework and version details from public responses.

What the full report includes

Ready for technical and non-technical review.

Use the same evidence in a developer handoff, internal security review, or client conversation without translating raw scanner output by hand.

Executive summary Affected assets Evidence notes Plain-English context Recommended actions Scope disclosures

Take the report with you

Unlock the sample export experience, or run a live scan for a domain-specific report.

Email required for full export

The preview stays visible. Export requires an email for delivery and follow-up.

Compare saved history and export options

Ready to check your own public baseline?

Run the same outside-in checks on an authorized domain.

Start free scan