OWASP-aligned DAST · DoubleMind LLC

Find the cracks
before attackers do.

VeriClad scans your live site the way any outside visitor sees it — then hands your team a clear, prioritized path to close what it finds.

Referenced to OWASP Top 10 10+ years in security Reports in plain English
What we scan

The security settings your site shows the world.

VeriClad crawls your running site and checks the configuration any outside visitor can see — the headers, cookies and policies that decide how much a browser will protect your users.

Missing Security Headers

Check whether X-Frame-Options, X-Content-Type-Options, Permissions-Policy and the cross-origin headers are present and valid.

A02:2025 — Misconfiguration

Content Security Policy Gaps

Flag a missing CSP, wildcard sources, and script or style directives that still allow unsafe-inline or unsafe-eval.

A02:2025 — Misconfiguration

Cookie Security Flags

Catch cookies served without HttpOnly, Secure or SameSite — the three flags that keep a session cookie out of reach.

A07:2025 — Auth Failures

Transport Security

Check that HTTPS is enforced with a Strict-Transport-Security header, so browsers refuse to fall back to plain HTTP.

A04:2025 — Cryptographic

Information Disclosure

Surface server and framework versions leaked through Server and X-Powered-By headers, and timestamps exposed in responses.

A02:2025 — Misconfiguration

Third-party Resource Integrity

Flag scripts loaded from external domains without a Subresource Integrity attribute to verify what actually arrives.

A03:2025 — Supply Chain

Built on OWASP ZAP baseline scanning — passive checks against your running site, with no attack traffic sent. Injection, cross-site scripting and access-control testing fall outside this scope.

DAST

Dynamic Application Testing

Black-box scanning of your running site, exactly as an outside visitor sees it.

OWASP

OWASP-aligned methodology

Checks follow the open OWASP ZAP methodology and reference the OWASP Top 10:2025, so audits and submissions line up with the international standard.

REPORT

Reports you can act on

Every finding carries its severity, a plain-language description and the concrete fix — your engineers can start work without a second round of research.

RESCAN

Re-scan to verify

Scan again the moment you have fixed something. Paid plans include unlimited scans, so there is no queue to rejoin.

How it works

From request to verified fix in four steps.

01

Request a scan

Submit your target URL and a few details through our form — no software to install.

02

We scan

Our engine runs an OWASP-aligned dynamic assessment against your application.

03

You get a report

A prioritized, severity-ranked report with clear remediation steps for every finding.

04

Fix & re-verify

Once you've patched, re-scan any time to confirm the issues are gone — paid plans include unlimited scans.

Pricing

Plans that scale with your attack surface.

Start with a free trial scan on one target; upgrade when you need more sites or a formal report.

Free trial

Scan one target and see what the report looks like.

$0
 
Start free
  • 1 target — one IP or one service
  • One scan — a one-off trial, not a monthly allowance
  • OWASP Top 10 coverage
  • Full findings on screen
  • PDF report (TRIAL watermark)

Essential

One site or a small team.

$39/ mo
About $33 / month
Start Now
  • Up to 3 targets
  • Unlimited scans
  • OWASP Top 10 coverage
  • PDF summary report
  • Email support
  • Priority email support

Enterprise

Large institutions with compliance needs.

Custom
 
Contact Sales
  • Unlimited targets
  • OWASP Top 10 coverage
  • Unlimited re-scans
  • Custom compliance mapping
  • Report format and data export scoped to your needs
VeriClad is fully automated (OWASP-aligned DAST); we do not offer manual penetration testing. For a larger scope, use the contact option below to request a quote.
Sample report

See exactly what you'll get.

Every scan ends in a report like this one — every finding rated, explained in plain language, and paired with the fix.

VeriClad Security Scan Report

VC-2026-0421-DEMO · DAST assessment · April 21, 2026
Target demo-shop.example.com
Methodology OWASP-aligned DAST
Status Completed
Findings 9 total
Overall risk: Medium

Risk summary

9findings, ordered
by risk level
High 0
Medium 3
Low 6

Findings summary

FindingSeverity
Content Security Policy (CSP) Header Not Set Medium
Missing Anti-clickjacking Header Medium
Sub Resource Integrity Attribute Missing Medium
Strict-Transport-Security Header Not Set Low
Cookie No HttpOnly Flag Low
Cookie Without SameSite Attribute Low
Server Leaks Version Information via "Server" HTTP Response Header Field Low
X-Content-Type-Options Header Missing Low
Permissions Policy Header Not Set Low

Finding names come straight from the scanner, so they stay in English. The description and fix for each one are translated.

Medium

Content Security Policy (CSP) Header Not Set

Description Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks, including Cross Site Scripting (XSS) and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files. This response does not set a CSP header.
How to fix it Ensure that your web server, application server, or load balancer is configured to set the Content-Security-Policy header.

Want a report like this for your site?

Start free
About DoubleMind LLC

Security rigor, born in the classroom.

DoubleMind LLC has spent more than ten years helping organizations build safer digital environments. We got our start in campus and education security — protecting the networks, student data, and learning platforms that schools and universities depend on every day.

Over time, that mission expanded into AI-powered education services, where we help institutions adopt modern, responsible technology in the classroom.

VeriClad is our dedicated web vulnerability scanning service. It brings the same rigor we apply to protecting campuses to any organization that needs to know whether its websites and applications are secure. Built on industry-standard methodologies including the OWASP framework, VeriClad gives you a clear, prioritized picture of your security posture — and a practical path to fixing what matters most.

10+yrs
in security
OWASP
aligned testing
Edu-first
mindset
Start free

Scan it yourself, before someone else does.

The free trial covers one target and one scan — no card, no sales call. Upgrade when you need more.

OWASP-aligned, severity-ranked reporting
No software to install
Fully automated — scanning starts as soon as you submit
Start free

Sign in with Google. Your first scan runs within minutes.


Need more sites, a custom scope, or a quote for your organization?

Talk to us