Perimeter grades the security and compliance posture that anyone on the internet can already observe about your site: your TLS certificate and protocol, your HTTP security headers, your public DNS and email-authentication records, and the accessibility of your rendered HTML. Everything below is what sits behind a grade — no black box. It's read-only and external; we never touch the inside of your systems.
Perimeter checks configuration posture against current best practice — not CVE-style exploit signatures. That's a deliberate choice. A vulnerability scanner chases a firehose of new exploit signatures every day and needs a constantly-refreshed threat feed. The things Perimeter watches — is your certificate valid, are the right headers present, is your DMARC policy actually enforcing — change slowly and are governed by stable, published standards. So our "signatures" are rules grounded in those standards, and keeping them current means tracking standards, not racing a feed. If you also need deep application-layer vulnerability scanning, Perimeter sits alongside that; it doesn't replace it.
frame-ancestors), and Permissions-Policy.The grade comes from the worst issue present, moderated by how many there are: a clean site is A+, a single minor note is A-, warnings pull you to B/C, and anything critical (an expired certificate, say) caps you at D or below. The same inputs always produce the same grade — it's deterministic, so your evidence is reproducible.
The ruleset is versioned with a date (2026.08.24 today) and that version is stamped onto every result and every dated compliance report — so an auditor can see exactly which ruleset produced a given piece of evidence. Because Perimeter is a hosted service, there is nothing to update on your side: when we tighten a threshold or add a check, we bump the version, note what changed, and deploy once — and the very next check for every customer uses the new ruleset. No agents, no plugins, no version drift between customers. When a standard moves — a protocol is deprecated, a header becomes expected, an email-auth spec is revised — the rule moves with it and the version records when.
Run the exact ruleset above against your site, free and without signup — then let Perimeter watch it every day and keep the dated record.
Monitor it continuously → · from $29/mo