FreeDAST by TripleKey

Your website already has a security grade. You just haven't seen it.

FreeDAST scans your live website from the outside, the same way an attacker would, and returns a letter grade with findings in plain language.

  • Read-only external scan. We never touch your code or pipeline.
  • First results in about 60 seconds.
  • Findings you can hand to your engineers or your auditors.

Run your free scan

Enter your website and work email. Your grade and full findings arrive by email.

74% of codebases contain high-risk vulnerabilities
59,427 new CVEs forecast for 2026, the first year past 50,000 (FIRST)
6+ yrs oldest unpatched issue found in an onboarding scan
$0 cost to run your first full scan
Your report

One grade. Clear findings. A fix list your team can act on.

Every scan returns a letter grade for your external security posture, plus each finding in plain language with its severity and the exact step to fix it. See what your grade means for your role

C+ Sample external grade
Critical Credentials file publicly readable /.aws/credentials → HTTP 200
High Session cookie missing HttpOnly flag session_id
High SSL certificate expires in 9 days notAfter 2026-07-11
Medium Admin path exposed in robots.txt /admin/internal-reporting
Pass No mixed content detected 8 of 8 checks clean
Coverage

Thirty-plus checks. The same ones attackers try first.

FreeDAST probes your live application the way an outside attacker or a customer security review would, then explains every result in language your whole team can use.

Files that should never be public

Credentials, private keys, database backups, and configuration files left readable over the internet. We probe 12 file types, unauthenticated, exactly like an attacker.

Real world

In 2024, an extortion crew scanned 110,000 domains for exposed .env files, used the cloud keys inside to take over accounts, then stole the data and left ransom notes.

Login and session weaknesses

Missing cookie security flags leave every logged-in user exposed to session hijacking. We check Secure, HttpOnly, and SameSite on every cookie you set.

Real world

Attackers used forged session cookies to open 32 million Yahoo accounts without a single password. The breach cut $350 million off Yahoo's acquisition price.

Expiring or broken SSL

An expired certificate is a trust failure your customers see before you do. We validate your certificate chain and flag expirations at 30, 14, and 7 days out.

Real world

In 2018, one expired Ericsson certificate knocked O2 and SoftBank networks offline for a day, cutting service to more than 30 million customers across two continents.

Exposed internal paths

Admin panels, internal dashboards, and private API routes published in robots.txt help attackers map your application before they ever probe it.

Real world

Reading robots.txt is step one of nearly every penetration test and attack. A single Disallow: /admin line hands an attacker a map to your most sensitive pages.

Mixed content on secure pages

Encrypted pages loading unencrypted resources undermine HTTPS and trigger browser warnings for users and security reviewers alike. Eight checks per scan.

Real world

In 2015, attackers intercepted unencrypted script traffic and silently rewrote it, turning millions of ordinary browsers into a days-long DDoS attack on GitHub.

Audit-ready results, not raw data

Every finding carries a severity level and a clear remediation path. Export to PDF for your next risk assessment, security questionnaire, or customer review.

Real world

A single critical finding surfaced in a customer security review can add weeks of remediation before signature. Finding it yourself first keeps the deal on schedule.

How it works

Results in 60 Seconds.

FreeDAST runs entirely from outside your application. No access to your code, no changes to your systems, nothing to install.

Step 1

Submit your website

Enter your URL and work email above. Confirm the scan from your inbox. Anyone on your team can start it.

Step 2

We scan from the outside

FreeDAST probes your live application the same way a security reviewer or attacker would, across all five categories.

Step 3

Get your grade and fix list

Your letter grade and plain language findings arrive by email, each with a severity and the step to fix it.

The bigger picture

Your external surface is about 10% of your software risk.

FreeDAST grades everything an outsider can see. The other 90% lives inside your codebase: vulnerable dependencies, license conflicts, and unpatched CVEs. TripleScan monitors that side daily, so you stop relying on point-in-time audits and guesswork.

External surface · FreeDAST Internal codebase · TripleScan
Learn about TripleScan

Know what your customers will find before they look.

Turn the security review stage from a deal killer into a competitive advantage. Results in 60 seconds.

Run My Free Scan