All posts
Security questionnaires

Will you pass an enterprise security questionnaire? The checks buyers run first

Before a customer signs, their security team runs a checklist against your domain. Here are the externally-visible checks that come first — and your free score.

June 20, 2026 · 2 min read

The first time most founders think about security is the day a promising deal stalls on a security questionnaire they can't answer. By then it's expensive: the deal slips a quarter while you scramble, and the buyer's trust takes a hit.

The good news is that the first round of an enterprise security review is mostly mechanical. Before anyone reads your policies, their security team — or their automated vendor-risk tool — checks a handful of things about your domain and app that are visible from the outside, no access required. If those fail, you start the conversation on the back foot.

The checks that come first

These are the externally-detectable basics that map directly to SOC 2's common criteria and to the questions on almost every vendor security questionnaire (VSQ):

  • Email authentication — DMARC, SPF, and DKIM. No DMARC means anyone can spoof email from your domain, and it's one of the first things flagged.
  • HTTPS everywhere — HTTP redirects to HTTPS, modern TLS, and HSTS so browsers never fall back to plaintext.
  • Security headers — Content-Security-Policy, X-Frame-Options / frame-ancestors, X-Content-Type-Options.
  • A documented security contact — a /.well-known/security.txt or a /security page that tells a researcher where to report something.

One more thing gets checked that this list deliberately leaves out: known vulnerabilities in the dependencies you ship. It belongs on a buyer's list, but not on this one — it is not visible from outside your domain, and no scanner can answer it without reading your lockfiles. Anyone who tells you they checked your dependencies from your domain name alone has not checked your dependencies.

None of these are unusual to miss for a team shipping fast. They just all surface at once the moment a customer's security review begins — and they're the cheapest things in your whole security program to fix.

See your own score in 30 seconds

You don't have to guess about the externally-visible ones. Our free scanner runs eight read-only checks against your domain — DMARC, SPF and DKIM for email authentication, HTTPS enforcement, HSTS, Content-Security-Policy, clickjacking and MIME protections, and whether you publish a security contact — and gives you a grade plus the precise fix for anything that fails. No signup, nothing intrusive, just the public checks anyone could run. Your dependencies need a connected repository; the domain scan cannot see them and does not claim to.

Run the free check on your domain

Scan my domain

If you score well, you can embed a badge on your site to show enterprise buyers you take this seriously. If you don't, you'll get the copy-paste fix for each gap. Either way you'll know where you stand before a customer tells you.

See where your security stands — free, no signup.

Run the free scan