HTTPS everywhere with HSTS to block plaintext downgrades.
More · site security
Site securityScan
See the TLS and security-header posture of c2pa.xenlook.com on one page. We read live response headers and you can re-check on Mozilla Observatory.
Engines: XenLook Observatory SSOT (@xenlook/config), StartupGuard header checklist, Mozilla Observatory API — not a homemade rubric.
Media provenance certificates are issued separately on /xmse-learn.
Domain security scan
Enter a host to run the same 6 scanners as StartupGuard (SSL Labs, Observatory, Safe Browsing, PageSpeed, headers, email DNS) with score and detail report.
saas_member_site_security
saas_member_signupSecurity strengths
Defense layers on the public portal surface — while the CA itself remains a disclosed pilot.
Content-Security-Policy constrains script and frame origins.
MIME sniffing, Referrer, and Permissions policies shrink browser-side risk.
Anyone can re-verify independently on Mozilla Observatory.
This portal (c2pa.xenlook.com) header probe
Observatory header checklist for this CA portal origin — separate from the domain scanner above.
HSTS
Strict-Transport-Security keeps browsers from falling back to HTTP.
…
Content-Security-Policy
Limits which origins may load scripts and other resources.
…
X-Content-Type-Options
nosniff blocks MIME-confusion execution.
…
X-Frame-Options
SAMEORIGIN blocks clickjacking frames.
…
Referrer-Policy
Reduces referrer URL leakage to third parties.
…
Permissions-Policy
Restricts default exposure of sensitive browser APIs.
…
How this relates to the CA
Site security asks how hardened this website is. Certificate issuance, revocation, and Trust List status are published separately on Transparency and Practices.