Tools
Free tools, no sign-up
Run these yourself. No email address required to see your result, no sales call attached. If you'd rather someone just fixed the findings, we're here — but the tools work whether or not you ever call us.
Instant · DNS check
Email security checker
Can someone send email pretending to be your company? Checks SPF, DKIM and DMARC and explains every result in plain English.
3 minutes · Self-assessment
Microsoft 365 security self-check
Twelve questions on how far your tenant has moved past Microsoft's defaults, scored against what regulated environments need.
Other free resources worth knowing about
We didn't build these and we don't profit from them. They're genuinely good, and if you're trying to get your own house in order they're the right place to start.
-
HIPAA
HHS Security Risk Assessment Tool Free downloadable tool from the HHS Office for Civil Rights that walks small and mid-sized healthcare organisations through the risk analysis the Security Rule requires. Worth knowing what it doesn't cover: it produces an assessment, but no remediation plan, no policies and no templates. healthit.gov
-
General
CISA no-cost cybersecurity services and tools A catalogue of free services from CISA, federal partners, open-source projects and private vendors. Their Cyber Hygiene Services include free vulnerability scanning for eligible organisations. cisa.gov
-
Breach
Have I Been Pwned Check whether an email address has appeared in a known breach. Domain monitoring is free for domains with up to 10 breached addresses; larger domains need a subscription. haveibeenpwned.com
-
Web
Qualys SSL Labs & Security Headers Two free scans for any site you own: certificate and TLS configuration, and HTTP response headers. ssllabs.com · securityheaders.com
-
PCI
PCI Security Standards Council document library The self-assessment questionnaires and supporting guidance are free downloads. Picking the right SAQ for how you actually take payments is most of the work. pcisecuritystandards.org
A note on tools that offer to scan your network. We only ever read public information — DNS records, certificates, response headers. Be wary of any free tool that offers to scan or probe infrastructure without asking you to prove you own it. Legitimate providers ask first.