0
Scans run
0
Domains protected
0
Critical findings caught (7d)
—
Average score / 100
CamsClaw public beta
Security validation for the AI era.
Scan any site's traditional and AI attack surface — free. TLS, headers, injection & access-control, plus exposed LLM/MCP endpoints, vector stores, model artifacts and prompt-injection. Verify ownership to unlock deep scans and consented active + AI/LLM probing.
OWASP Top 10
OWASP LLM Top 10
MCP / agentic
MITRE ATLAS
PCI · GDPR · DPDPA · ISO 27001
Your recent scans
Passive scan in ~3s — TLS · headers · DNS · stack & CVEs · info-disclosure · client-side secrets · AI-surface (LLM / MCP / vector / model) · WAF · privacy.
No tracking, no accountAnonymous scans, nothing stored
We scan ourselvesSee CamsClaw's own report
What's in a CamsClaw scan?
CRITICAL
No HSTS header
Browsers can downgrade your visitors to plain-text HTTP, enabling
man-in-the-middle attacks on coffee-shop wi-fi.
OWASP: A02
PCI DSS: 4.1
ISO 27001: A.13.1.1
HIGH
Server version disclosed
Your nginx/Apache version is in the Server header. Attackers
cross-reference it with CVE databases to pick exploits faster.
OWASP: A05
CWE-200
MEDIUM
SPF record missing
Spammers can forge mail "from" your domain. Mailbox providers
downgrade your legitimate mail too.
RFC 7208
DPDPA: §11
Each finding ships with: remediation steps · evidence (request/response) · CVE
correlation · per-framework compliance mapping · permanent shareable URL.
See all 110+ checks — passive · authenticated · active →
Live · last 12 scans
Trending this week
—
Your digital footprint — everything every website learns about you
live
$ cclaw inspect --target=you
INFO Every entry below was sent by your browser or derived from your public IP.
We display it back to you and never store it for anonymous visits.
Network — what the internet sees
Your public IP address…
IP address type…
Reverse DNS hostname (PTR record)…
Network operator (ASN)…
Internet Service Provider…
Approximate location (from IP)
…
why off?
Browser time zone…
Cloudflare edge data center…
Connection scheme…
HTTP protocol version…
Client — what your browser tells every site
Browser & operating system…
Operating system platform…
Display resolution…
Display color depth…
CPU cores (logical)…
RAM (approximate)…
Graphics renderer (WebGL)…
Network connection speed…
Privacy signals — what you broadcast
Browser language preference…
Cookies enabled…
Do-Not-Track signal…
Global Privacy Control (GPC)…
Prefers dark theme…
Prefers reduced motion…
DONE enriching …
$
AI & LLM securityNew
Exposed LLM / MCP endpoints · vector stores · leaked model artifacts ·
prompt-injection & agentic-AI probing. Mapped to OWASP LLM Top 10 & MITRE ATLAS.
Three-layer scanning
Public passive → verified-owner deep scans → consented active
& AI/LLM probing. Authorized at every step.
Compliance mappings
Every finding mapped to OWASP · PCI DSS · ISO 27001 · GDPR · DPDPA · RBI CSF.
Industry leaderboards
Banking · fintech · government · global — re-scanned daily.
Side-by-side compare
Up to 8 domains in one shareable URL.
Methodology
Every test_id · severity · what we check · default fix.
Scanning
—