Solution · Cyber Insurance

See your domain before underwriters do

Before your cyber insurance quote arrived, the underwriter likely ran an automated external scan of your domain — checking your DMARC policy, SSL certificate, open ports, and HTTP headers, and factoring the result into your application. ComplianceLayer checks the same categories of external signals, so you can review your posture before the renewal.

Use CasePre-audit assessment
Primary ValueRenewal preparation
SurfaceFull domain scan report
AccessExternal only — no credentials
15+
Scan modules
4
Risk categories checked
1
Scan = pre-audit readiness
$0
Required for first scan
Workflow

From scan to renewal confidence

Three steps. Fix issues before the underwriter finds them.

Step 01
Scan your domain

Enter your domain. ComplianceLayer runs the same external checks that underwriters use — DMARC, SSL, open ports, HTTP headers. No credentials, no internal access required.

DMARCSSL/TLSOpen ports
Step 02
See your score

Get an A-F grade with a breakdown of every finding. See which issues underwriters commonly flag for manual review, pricing, or coverage decisions.

GradeRisk flagsImpact
Step 03
Fix before renewal

Get prioritized remediation steps. Fix DMARC policy, close exposed ports, add HSTS — then re-scan to document the improvement before renewal.

RemediationRe-scanProof
Frameworks

Mapped to what insurers check

Insurance-relevant risk categories alongside the compliance frameworks your auditors ask for.

Cyber Insurance
Insurance Requirements
Match what underwriters check: DMARC policy, SSL grade, exposed ports, and HTTP headers. Know your score before the application.
SOC 2
Trust Services Criteria
Map email auth and infrastructure findings to Common Criteria controls. Evidence ready for auditor delivery.
NIST CSF
Cybersecurity Framework
External posture mapped to Identify, Protect, and Detect functions. Suitable for federal and enterprise environments.
ISO 27001
Information Security
Align domain scan results to Annex A controls for ISMS evidence packages and certification readiness.
CIS Controls
CIS Critical Controls
Coverage for network monitoring, secure configuration, and email/web browser protections from domain-level scans.
HIPAA
Healthcare Security
Support Security Rule evidence for covered entities and business associates. Domain hygiene as part of the picture.
Capabilities

What gets scanned

The four categories that drive the most weight in underwriting decisions — plus DNS and a full grade report.

Email authentication check
Verify DMARC policy, SPF record, and DKIM alignment. A domain without DMARC at p=reject is a common red flag on carrier scorecards.
SSL/TLS configuration
Detect expired certs, legacy TLS 1.0/1.1, and missing HSTS. Rating platforms often use SSL configuration as a proxy for overall infrastructure hygiene.
Open port exposure
Flag exposed RDP (3389), Telnet (23), and FTP (21). Exposed RDP is treated as a high-risk signal by many underwriters — some carriers restrict ransomware coverage when it's open.
HTTP security headers
Check for missing Content-Security-Policy, X-Frame-Options, and HSTS. Missing headers are weighted risk signals on many carrier scorecards.
DNS security
Validate DNSSEC, check for dangling DNS records, and detect subdomain takeover risks. DNS hygiene signals operational maturity to underwriters.
Full grade report
Get an A-F grade with prioritized findings and remediation steps. Understand which issues commonly draw underwriter attention.
Scan Result

See what underwriters commonly flag

A ComplianceLayer scan gives you an outside-in view of your domain before your application is submitted. Fix the issues that matter, document the improvement, and walk into renewal with full visibility. A weak external posture can draw manual review, pricing impact, or coverage exclusions — practices vary by carrier.

Domain Scan Result
yourdomain.com · Mar 28, 2026
Pre-Audit
DMARC Policyp=none — WARN
SSL GradeB — TLS 1.2
Open Ports3389 exposed
HTTP Headers Score70 / 100
Overall GradeC — 61 / 100
External Risk SummaryElevated — remediation advised

Disclaimer: ComplianceLayer assesses externally observable technical controls. Scan results are informational and do not constitute a compliance certification, audit opinion, or guarantee of insurability or insurance outcomes. Full compliance requires organizational controls, policies, and formal audits, and acceptance of any report is at the discretion of your auditor, assessor, or insurer.

Run your pre-audit scan before the underwriter does

See your domain score, fix what matters, and walk into renewal prepared. Free scan — no credentials required.

No account required for first scan. See full pricing →