Assessment console
No application selected
No assessment selected
Run a bounded public verification below to see observed controls, evidence age, findings, and certificate state. No account is required, and the console does not display placeholder scores or synthetic activity.
Run an evidence-backed verification
Submit a public HTTPS URL. PlatPhorm Ready runs bounded HTTP, discovery, specialist, contract, feed, policy, and MCP checks, then returns a run ID and evidence-backed results.
Public read-only verification is available without an account. PLATPHORM_API_KEY stays server-side and is never entered into or sent from the browser. Repository and protected evidence remain available through authorized API or MCP calls only.
Control registry
8 domains are defined in the public standard. Coverage is unknown until an assessment produces evidence.
Protocols & transport
18 controlsTLS, HTTP behavior, DNS, redirects, compression, caching, cookies.
Pages & crawl surface
24 controlsRoutes, sitemaps, robots, canonicals, hreflang, feeds, broken paths.
OWASP & vulnerability
31 controlsHeaders, exposure, dependencies, DAST, secrets, supply-chain integrity.
Trust & well-known
16 controlssecurity.txt, change-password, policies, ownership, disclosures, contacts.
APIs & contracts
22 controlsOpenAPI, schemas, compatibility, errors, idempotency, rate limits, webhooks.
Legibility & access
19 controlsWCAG, semantics, contrast, language, keyboard, responsive rendering.
Agents & discovery
14 controlsMCP, llms.txt, structured data, agent permissions, human escalation.
Operations & evidence
40 controlsCI, provenance, SBOM, observability, incident readiness, retention.