What is Hard2bit Scanner?
+
Hard2bit Scanner is a SaaS scanner that audits your domain's public security posture. It analyses any domain in 30 seconds across 16 check categories (HTTP headers, TLS, email authentication, DNS health, known vulnerabilities, cloud exposure, threat intelligence, supply chain) plus 11 emerging 2025-2026 standards for AI agent readiness. Built for consultants, auditors and internal CISOs.
Is it really free to get started?
+
Yes. The Free plan includes 3 scans per month with no credit card and no trial period. Without registering you can run 1 anonymous scan per day per IP. For more volume there's Starter (20 scans/month, €19/month) and Pro (60 scans/month, €29/month).
What technologies and configurations does it analyse specifically?
+
The scanner runs 16 check categories: HTTP security headers (HSTS, CSP, X-Frame-Options), TLS/SSL, email authentication (SPF, DKIM, DMARC, MTA-STS), DNS health (DNSSEC, MX, records), known public vulnerabilities (CVEs), exposed cloud storage (S3, public blobs), threat intelligence (URLhaus, Feodo, Spamhaus, PhishTank, Google Safe Browsing), vendor breach exposure for supply chain, shadow IT subdomains via Certificate Transparency, leaks in pastes and public repositories, AI dataset exposure, AI bot blocking, compliance signals, domain status (WHOIS), detected technologies, and 11 AI agent readiness standards (llms.txt, sitemap, Content-Signal, Markdown negotiation, MCP, Agent Skills, RFC 9727/9728).
How does it differ from SecurityScorecard, UpGuard or Detectify?
+
Hard2bit Scanner focuses on passive public posture analysis, accessible for European SMBs and consultancies. Unlike SecurityScorecard (continuous ratings based on external feed aggregation, enterprise pricing) or UpGuard (supply chain risk focus, enterprise pricing), Hard2bit is self-service freemium with no opaque scoring: every finding includes evidence and actionable recommendation. It is also purpose-built for the 11 emerging AI agent readiness standards (llms.txt, MCP, etc.) alongside classic security checks.
Can the reports be used as evidence for NIS2, DORA, ENS or ISO 27001 audits?
+
Yes. The generated reports are usable as supplementary evidence in NIS2 audits (Art. 21 technical measures), DORA (Art. 9-10 ICT management), ENS (medium/high categories — continuous exposure monitoring) and ISO 27001 (A.12.6 technical vulnerability management). It does not replace a professional audit, but provides objective, timestamped and reproducible evidence of public posture at the moment of analysis.
Is the scan passive or does it actively probe my server?
+
Completely passive. Hard2bit Scanner only queries public information: DNS, TLS certificates, HTTP headers, Certificate Transparency logs, etc. It does not send anomalous traffic, does not actively probe vulnerabilities, does not generate entries in your logs or WAF systems. Equivalent to what any browser and public DNS resolver would do when visiting your site.
How does it differ from a professional pentest?
+
The scanner detects public posture: exposed configuration, visible misconfigurations, internet exposure, AI agent readiness. A professional pentest goes further: actively tests vulnerabilities, exploits flaws to verify real impact, and requires expert human intervention. Hard2bit Scanner is a complement, not a substitute. If you need a pentest, we offer that service at hard2bit.com/servicios/pentesting.
What domains am I legally allowed to scan?
+
Only domains you're authorized to scan: your own corporate domain or that of a client who has engaged you. Scanning unauthorized domains goes against our terms and, depending on jurisdiction, may be illegal. Although technically we only query public data, legal responsibility for the scan always rests with the user who initiates it.
Why do you include AI agent readiness checks?
+
AI agents (ChatGPT with browsing, Perplexity, Claude with search, proprietary agents) increasingly discover and interact with websites following emerging 2025-2026 standards: llms.txt (curated index), Content-Signal in robots.txt (AI preferences), MCP Server Cards (exposed capabilities), Agent Skills, RFC 9727/9728 (API Catalog, OAuth Protected Resource). Hard2bit Scanner is purpose-built to audit all 11 standards alongside classic security checks, helping you ensure your site is discoverable and operable by AI agents — increasingly relevant for SEO, conversion and technical efficiency.
Does it have an API or integrations with M365, SIEM or Slack?
+
In the current beta the scanner is self-service via web interface, with PDF export in paid plans. Public API and native integrations (M365, SIEM, Slack, ticketing) are on the 2026 roadmap. For enterprise needs (high volume, custom integrations), contact info@hard2bit.com.
What data do you require and what do you do with it?
+
We only require the domain name for anonymous scans. For registered users we keep email and scan history (30 days for reports, indefinite for email until deletion request). We do not require credentials, panel access, or agent installation. GDPR compliance: Hard2bit S.L. is the data controller, data hosted on European Union servers (Helsinki, Hetzner), deletion right via info@hard2bit.com (GDPR Art. 17).
Who is behind Hard2bit Scanner?
+
Hard2bit S.L., a Spanish cybersecurity company with over 10 years of experience. ISO 27001, ISO 9001, ISO 14001, ISO 22301 and ISO 20000-1 certified, with ENS High category. Active members of ISMS Forum, ASLAN, CyberMadrid and UN Global Compact.