CamsClaw public beta

Security validation for the AI era.

Scan any site's traditional and AI attack surface — free. TLS, headers, injection & access-control, plus exposed LLM/MCP endpoints, vector stores, model artifacts and prompt-injection. Verify ownership to unlock deep scans and consented active + AI/LLM probing.

OWASP Top 10 OWASP LLM Top 10 MCP / agentic MITRE ATLAS PCI · GDPR · DPDPA · ISO 27001

Passive scan in ~3s — TLS · headers · DNS · stack & CVEs · info-disclosure · client-side secrets · AI-surface (LLM / MCP / vector / model) · WAF · privacy.

Open methodologyEvery check & score weight published AGPL-3.0 open sourceAudit the scanner yourself
No tracking, no accountAnonymous scans, nothing stored
We scan ourselvesSee CamsClaw's own report
What's in a CamsClaw scan? 3 of ~80 passive checks · click "Run Scan" above to see your real results
CRITICAL
No HSTS header
Browsers can downgrade your visitors to plain-text HTTP, enabling man-in-the-middle attacks on coffee-shop wi-fi.
OWASP: A02 PCI DSS: 4.1 ISO 27001: A.13.1.1
HIGH
Server version disclosed
Your nginx/Apache version is in the Server header. Attackers cross-reference it with CVE databases to pick exploits faster.
OWASP: A05 CWE-200
MEDIUM
SPF record missing
Spammers can forge mail "from" your domain. Mailbox providers downgrade your legitimate mail too.
RFC 7208 DPDPA: §11
Each finding ships with: remediation steps · evidence (request/response) · CVE correlation · per-framework compliance mapping · permanent shareable URL. See all 110+ checks — passive · authenticated · active →
🤖
AI & LLM securityNew
Exposed LLM / MCP endpoints · vector stores · leaked model artifacts · prompt-injection & agentic-AI probing. Mapped to OWASP LLM Top 10 & MITRE ATLAS.
🧭
Three-layer scanning
Public passive → verified-owner deep scans → consented active & AI/LLM probing. Authorized at every step.
📚
Compliance mappings
Every finding mapped to OWASP · PCI DSS · ISO 27001 · GDPR · DPDPA · RBI CSF.
📊
Industry leaderboards
Banking · fintech · government · global — re-scanned daily.
⚖️
Side-by-side compare
Up to 8 domains in one shareable URL.
🔬
Methodology
Every test_id · severity · what we check · default fix.
Scanning
target

Findings