Web Security
Security headers, HTTPS and other externally visible website settings. Not a full crawl and not a penetration test.
Choose the check that fits your website, email domain or an API endpoint. The report files on offer are free during the beta as well.
All three checks work without a Wolf-Agents account. Read the scope of each one and only check targets you are authorised to assess.
Security headers, HTTPS and other externally visible website settings. Not a full crawl and not a penetration test.
SPF, discoverable DKIM keys, DMARC and transport signals of a domain. No mailbox scan and no proof of delivery.
CORS, security headers and limited response signals of one API endpoint. It does not check user permissions or business logic.
The public web, email and API checks and their visible results are free. During the report beta the PDF, DOCX and CSV downloads on offer are free as well, with no Wolf-Agents account and no email address. Protective measures and scan limits still apply.
The web check examines website configuration, the email check looks at published domain and mail server signals, and the API check looks at selected responses from one public endpoint. The organisational self-assessments are kept separate, in the NIS2 section for Germany.
No. The downloads on offer are accessible during the beta without an email address. Sending a report by email is optional and unlocks no additional content. Save the files you need locally; downloading them again depends on whether the stored result is still available.
Yes. Data is processed for a limited time to deliver the result and to operate the service. The details and retention periods are set out in the privacy policy. Downloading a report again uses the existing scan and does not start a new check.
No. A grade only describes the scope of that check. Items that were not measured are not passed tests. The checks replace neither a penetration test nor a complete legal or organisational assessment.
The checks record selected configuration features that are visible from outside. Read the explanations and the notes on limited measurements alongside the grade.
Our web security guides (German) and email security guides (German) support the technical work that follows.
PDF to read and file, DOCX for your own additions and CSV to keep working with the findings: all three formats document the same scan.
A report is a technical working document, not a security certificate or proof of compliance.
Information on the NIS2 implementation in Germany (German) remains available separately.
Only check targets you operate or have been authorised to assess. Scanner usage rules · Privacy and retention periods (German)