Skip to main content

Pentrova is launching soon. Join the waitlist for early access.Join the waitlist

Free tool · Header scanner

Audit the security headers on any HTTPS URL.

Point Pentrova’s header scanner at any public HTTPS URL and get a prioritized audit of the security-relevant response headers, covering transport, framing, content typing, referrer policy, and permissions. Nothing is stored on our servers.

We run checks in your browser. Nothing is stored on our servers.

How the check works

  • Deterministic rule set

    We check for Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and more, with remediation notes for each miss.

  • Read-only request

    The scanner issues a single GET to the URL you provide and reads only the response headers. It never touches forms, cookies, or authenticated routes.

  • No persistence

    Pentrova does not log, cache, or share the URLs you submit. Results live in your browser session only.

Site search

↑↓ navigateEnter openEsc close