Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

What Ward does, and what it never does

Ward looks at your company from the outside, the way an attacker would, but without attacking. It only uses public information and passive techniques.

What Ward does

  • DNS lookups, the same ones any computer makes to find your website or send you email.
  • Public certificate logs (Cert Spotter, with crt.sh as a backup) and domain registration records (RDAP).
  • Public third-party data: email blocklists, lists of phishing sites, lists of attacking addresses and ransomware leak-site records. The full list of sources, with their licenses, is on the sources page.
  • A single visit to your home page, like a browser would make, following at most three redirects.
  • One encrypted connection to your website and to www to read the certificate, cipher and TLS version (plus one optional TLS 1.1 probe).
  • One TLS handshake, with no web request, to each of up to 15 subdomains that already appear in public certificate logs, only to read their certificate's expiry and name.
  • One visit to the homepage of each of up to 10 active lookalike domains of yours, to see whether they copy your website. Nothing else on those sites.
  • One request to each of the three standard files your website publishes on purpose: robots.txt, sitemap.xml and /.well-known/security.txt. We only read them; we never open the paths they mention.
  • Questions to search engines (Common Crawl and, where available, Brave Search) about what they already indexed from your domain, such as forgotten backups. We ask them, not your server.

All our sources and their licenses

What Ward never does

  • Scan ports or probe services.
  • Guess subdomains or probe paths on your website: no lists of addresses, no directory brute force.
  • Try passwords, send malicious payloads or fuzz.
  • Look up personal information about your employees.
  • Change anything in your systems.

Every request identifies itself as “WardBot”, with a link to this page.

Limits, and how to read the results because of them

It's a snapshot from the outside
Ward can't see your internal network or anything that isn't public. A good Ward Score means you're well protected from the outside, not that everything inside is fine.
Third-party data can lag
Open services and their software versions come from databases that scan the internet periodically: something you closed yesterday may still show for a few days. If you're sure it's closed, mark it pending verification.
Vulnerabilities by version
Ward deduces them from the version the software announces. Linux distributions often patch without changing that number, so confirm with whoever maintains the server before assuming it's vulnerable.
DKIM by common names
Ward looks for DKIM under the usual selector names. If it doesn't find it, that doesn't mean you don't have it: check with your email provider.
Domains without public expiry
Registries such as .es don't publish the expiry date. Enter your renewal date on the domain page and Ward will remind you.
Not an audit
It doesn't replace a security audit or an authorized penetration test: it covers what anyone can see from the outside, which is where most attacks on small businesses begin.