XENLOOK
c2pa-route-marker:site-security

More · site security

Site securityScan

See the TLS and security-header posture of c2pa.xenlook.com on one page. We read live response headers and you can re-check on Mozilla Observatory.

Engines: XenLook Observatory SSOT (@xenlook/config), StartupGuard header checklist, Mozilla Observatory API — not a homemade rubric.

This page is an edge web check (HTTPS + HTTP headers). It is not a C2PA Trust List, WebTrust, or CA issuance audit.

Media provenance certificates are issued separately on /xmse-learn.

Domain security scan

Enter a host to run the same 6 scanners as StartupGuard (SSL Labs, Observatory, Safe Browsing, PageSpeed, headers, email DNS) with score and detail report.

saas_member_site_security

saas_member_signup

Security strengths

Defense layers on the public portal surface — while the CA itself remains a disclosed pilot.

HTTPS everywhere with HSTS to block plaintext downgrades.

Content-Security-Policy constrains script and frame origins.

MIME sniffing, Referrer, and Permissions policies shrink browser-side risk.

Anyone can re-verify independently on Mozilla Observatory.

This portal (c2pa.xenlook.com) header probe

Observatory header checklist for this CA portal origin — separate from the domain scanner above.

Gap

HSTS

Strict-Transport-Security keeps browsers from falling back to HTTP.

…

Gap

Content-Security-Policy

Limits which origins may load scripts and other resources.

…

Gap

X-Content-Type-Options

nosniff blocks MIME-confusion execution.

…

Gap

X-Frame-Options

SAMEORIGIN blocks clickjacking frames.

…

Gap

Referrer-Policy

Reduces referrer URL leakage to third parties.

…

Gap

Permissions-Policy

Restricts default exposure of sensitive browser APIs.

…