What Is DMARC? A Plain-English Guide
DMARC decides what happens to email that fails authentication. Here's what it does, what p=none actually means, and how to set it up in 15 minutes — no prior knowledge assumed.
Read articleExternal Scan vs. Vulnerability Scan vs. Pentest
Three security assessments, three different questions. What each one actually tells you, what each one costs, and why 'we already have a vulnerability scanner' is a category error.
Is It Legal to Scan a Domain You Don't Own?
The unspoken question behind every external security scan. Where the legal lines actually sit, why 'legal' and 'welcome' are different questions, and the authorization practice good MSPs follow.
Building a 15-Module Security Scanning API: Architecture Decisions
15 security scanners running concurrently against a single domain in under 60 seconds. Here's how ComplianceLayer's scanning architecture works — from asyncio.gather to the Postgres job queue to the scoring model.
How We Grade a Domain: The ComplianceLayer Scoring Model
The full scoring model behind every A–F grade we issue: the module weights, the exact grade thresholds, and the failure rules that stop a crashed check from ever inflating a grade.
The MSP's Guide to Automating Client Security Assessments
QBRs need data, not opinions. Here's how to automate client security assessments — from API-based scanning to client-ready reports — and turn them into a $12K+/year revenue center.