Domain.Posture

For SOC 2 / ISO 27001 and vCISO practices

Stop re-collecting the same client evidence every cycle.

The DNS, email-authentication and TLS slice of a readiness engagement is the same work every time, for every client — and it is the part nobody bills for. Give us five client domains and we’ll send back one workpaper covering all of them, with your firm on the cover. Free, and there’s nothing to buy afterwards.

  1. 1

    You tell us the domains

    Your firm's name and up to five client domains. Nothing to install, no access to anything of theirs — every check reads public DNS, TLS and WHOIS records.

  2. 2

    We run the same 15 checks a reviewer runs

    DNS, MX, SPF, DKIM, DMARC, TLS, redirects, security headers, CORS, DNSSEC, MTA-STS, TLS-RPT, WHOIS and CT logs — per domain, with each finding mapped to the SOC 2 or ISO 27001 control it evidences.

  3. 3

    You get one workpaper, with your name on it

    A single document across all five clients, gaps ranked by severity, ready to send or drop into an engagement. Yours to use however you like.

What the free workpaper is not

It’s a working draft: real findings, but unsigned. The paid report is Ed25519-signed and dated, so your client’s auditor can confirm independently that it hasn’t been altered since you issued it — without an account, and without trusting either of us. Try verifying one.

Prepared from public records. It is not an authorised assessment of those domains, and we don’t contact your clients — ever.

Cover page of a sample Domain Audit Report

This is the shape of the document — one section per client instead of one domain. See a full sample.

Request your workpaper (5 domains, free)

Goes on the cover.

Client domains

Up to 5. Public DNS, TLS and WHOIS records only — the same data anyone can look up.

Where we send the workpaper.

Optional.

Free, no card. We don’t sell or share your address.