Authorized security scan

Run a read-only security posture scan on assets you own or are authorized to test.

This MVP is designed for defensive assessment only. It reviews visible transport, TLS, header, cookie, and basic web-surface signals so businesses can understand where to focus next.

Authorized testing only

Use this workflow only for assets your organization owns or assets for which you have explicit written authorization. The current MVP is read-only, non-destructive, and intended for defensive review, not offensive testing.

What the MVP Reviews

A credible first pass instead of a fake all-in-one promise

Nourmed starts with practical signals that matter early: reachable services, transport posture, basic web safeguards, and issues that are easy to prioritize.

TLS and transport checks

Review HTTPS reachability, certificate age, and whether HTTP behavior points visitors back to secure transport.

Header and cookie posture

Check for missing security headers and weak cookie flags that can signal avoidable hardening gaps.

HTML and form surface review

Look for insecure form actions, mixed-content references, and other basic exposure signals on the analyzed page.

How It Works

A small-business-friendly flow from request to findings

The platform records the request, verifies the declared target type, executes a safe review, and returns a report sorted by severity.

01

Declare the target

Choose a website, domain, or explicit host:port that you are authorized to review.

02

Confirm authorization

You must attest that the target belongs to you or that you have permission to test it.

03

Run the scan

Nourmed performs a read-only review and stores findings in the backend for reporting.

04

Review the report

The resulting report highlights risk level, findings, and practical next-step guidance.

Launch a scan

Start an authorized vulnerability assessment

Provide the target, organization, and authorization confirmation. The report stays limited to this session unless you share it deliberately.

Scan report

This report reflects the current MVP scope: safe posture checks, not exhaustive penetration testing.

Launch a scan to generate a report for an authorized target.

Operational Guardrails

Built to stay defensive, limited, and extensible

This release is a safe first layer. It is meant to support triage and prioritization, not to claim exhaustive coverage or replace a deeper assessment.

Read-only by design

The scanner focuses on observation and posture review rather than exploit attempts or destructive probes.

Explicit authorization required

Every scan request requires an authorization attestation before the backend will accept the job.

Structured findings

Results are stored with severity, description, and remediation guidance so they can support follow-up work.