All posts
Security questionnaires

Will you pass an enterprise security questionnaire? The checks buyers run first

Before a big customer signs, their security team runs a checklist against your domain. Here are the externally-visible checks that come first — and how to see your own score for free.

June 20, 2026 · 5 min read

The first time most founders think about security is the day a promising deal stalls on a security questionnaire they can't answer. By then it's expensive: the deal slips a quarter while you scramble, and the buyer's trust takes a hit.

The good news is that the first round of an enterprise security review is mostly mechanical. Before anyone reads your policies, their security team — or their automated vendor-risk tool — checks a handful of things about your domain and app that are visible from the outside, no access required. If those fail, you start the conversation on the back foot.

The checks that come first

These are the externally-detectable basics that map directly to SOC 2's common criteria and to the questions on almost every vendor security questionnaire (VSQ):

  • Email authentication — DMARC, SPF, and DKIM. No DMARC means anyone can spoof email from your domain, and it's one of the first things flagged.
  • HTTPS everywhere — HTTP redirects to HTTPS, modern TLS, and HSTS so browsers never fall back to plaintext.
  • Security headers — Content-Security-Policy, X-Frame-Options / frame-ancestors, X-Content-Type-Options.
  • A documented security contact — a /.well-known/security.txt or a /security page that tells a researcher where to report something.
  • No live, known vulnerabilities in your shipped dependencies.

None of these are unusual to miss for a team shipping fast. They just all surface at once the moment a customer's security review begins — and they're the cheapest things in your whole security program to fix.

See your own score in 30 seconds

You don't have to guess. Our free scanner runs exactly these read-only checks against your domain and gives you a grade plus the precise fix for anything that fails — no signup, nothing intrusive, just the public checks anyone could run.

Run the free check on your domain

Scan my domain

If you score well, you can embed a badge on your site to show enterprise buyers you take this seriously. If you don't, you'll get the copy-paste fix for each gap. Either way you'll know where you stand before a customer tells you.

See where your security stands — free, no signup.

Run the free scan