Orbital site inspection
Scan a site.
Get cleared.
Point it at a website for fifteen security checks, or drop in a file — .exe, document, PDF, archive — for a full static inspection. Sites that pass earn a signed certificate anyone can verify by serial.
Takes about 10 seconds. Nothing is attacked — the scanner only reads public responses.
The file is inspected on the server and deleted straight after. It is never run.
Signal lost
A site looks fine
right up until it isn't.
Nothing on the surface tells a visitor whether a form posts over plain HTTP, whether a session cookie can be stolen by any script on the page, or whether the last deploy left .env sitting in the web root with the database password inside it. These are not exotic attacks — they are configuration slips, and they are invisible from the browser.
Inspection sequence
Fifteen checks, four groups.
Encryption
HTTPS reachable, plain HTTP redirects to it, TLS certificate valid and not about to expire.
Browser defences
HSTS, Content Security Policy, MIME sniffing, clickjacking, referrer and permissions policy.
What leaks
Server version leaks, cookie flags, and whether .env or .git are publicly readable.
Signed record
A certificate nobody can forge.
Each certificate is a small record — serial, host, score, grade, dates — hashed together with a secret key that never leaves the server. The result is stored as the signature.
Anyone can read a certificate. Nobody can make one. Change a single character of a stored record and the verify page reports it as tampered. Certificates expire after 90 days, because a scan only describes a site on the day it ran.
Grade readout
How the grade is worked out.
Every check carries a weight. A pass earns full weight, a warning earns half, a failure earns nothing. The score is what you earned over what was available.
A certificate needs 80 or more and no critical failure. A critical failure is any failed check worth 12 points or more — an expired TLS certificate, an exposed .env, a Safe Browsing listing.
Airlock open
Hold a serial? Check it.
Verification is public and needs nothing but the serial number. It will tell you whether the certificate was really issued here, which site it belongs to, and whether it is still in date.
Archive link
What this is, and what it isn't.
VirusTotal runs a URL past around seventy commercial antivirus engines. This does not. This is a security posture scanner — closer to Mozilla Observatory or SSL Labs. It tells you whether a site is configured safely, not whether it is serving malware.
Real malware verdicts can be switched on: drop a free Google Safe Browsing key into lib/config.php and that check goes live. Whatever you decide, say plainly on your site what the badge means. A badge that overpromises is worse than no badge at all.
Airlock — crew access
Open the airlock
Sign in to post roles, apply, and track interviews.
Mission control — restricted
Hiring telemetry
Recent interviews
| Candidate | Role | Language | Score | Verdict |
|---|