Security audit suite
SSL/TLS configuration, security headers (CSP, HSTS, frame protection), email authentication (SPF, DMARC, BIMI), CMS version exposure, third-party script risk. The security suite carries 14% weight in the AuditHQ composite.
What the security audit suite checks
AuditHQ security audit checks SSL/TLS, security headers (CSP, HSTS), email auth (SPF, DMARC, BIMI), CMS exposure, and info disclosure. 14% of the score. AuditHQ uses the result as one part of a wider nine-suite website audit, so the finding is connected to marketing, technical, trust, privacy, and AI visibility context.
Why this matters
Single-suite scores are useful, but the real value comes from seeing how one issue affects the wider website. A technical gap can reduce AI visibility, a weak trust signal can reduce conversion, and a privacy gap can slow procurement. AuditHQ keeps those dependencies visible so fixes are prioritised by real business impact.
What the report gives you
The report turns suite findings into evidence, severity, priority, and recommended next steps so non-technical stakeholders and implementation teams can agree on what to fix first. That makes the page useful for search crawlers, AI answer engines, and humans comparing audit coverage.
Frequently asked questions
What does the AuditHQ security audit check?
SSL/TLS configuration, HTTP security headers (CSP, HSTS, frame protection), email authentication (SPF, DMARC, BIMI), CMS and software version exposure, and information disclosure. It carries 14% weight in the composite.
What do I get in the report, and how long does it take?
A scored security section with evidence for every finding - the actual header, DNS record, or exposed path - plus the exact fix. The free scan samples security signals across all nine suites in about 60 seconds; the full report takes about 5 to 8 minutes.
Is this a penetration test?
No. AuditHQ checks public, non-intrusive security signals and common misconfigurations. It is not a penetration test or a formal security certification, and findings should be reviewed before relying on them for security decisions.