HSTS, CSP, X-Frame-Options, cookie flags, CORS policy: the controls that stop whole classes of attack, and the ones that quietly disappear after a deploy. PulseTrace grades them on every check and alerts when the grade drops.
The SSL/TLS Security monitor inspects the response headers served over TLS — HSTS and its max-age, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-Frame-Options — plus Set-Cookie flags (Secure, HttpOnly, SameSite), CORS headers and redirect behaviour, and folds them into the endpoint's letter grade.
Findings are listed individually, with what was expected and what was found, so 'B' is never a mystery. A dropped header is also a change event on the timeline — the moment it happens, with the deploy window right next to it.
Team and above (SSL/TLS security posture); trust pages with grades on Pro and above.
Compare plans →