Free tool · Runs in your browser · Nothing uploaded

Grade your security headers.

Run curl -I https://yoursite.com (or copy Response Headers from dev tools) and paste them below. You get a grade, what's present, weak, or missing — and the exact headers to add.

100% client-side

The cheapest security you're not shipping

Security headers are close to free — a few lines in your reverse proxy — and they shut down whole classes of attack: protocol downgrades, clickjacking, MIME confusion, and a big slice of XSS. On a managed platform some of these came set by default. On a box you own, they're yours to add, and they're the first thing a security review checks. This grades what you've got and hands you the rest.

The hard part is monitoring relevant services and releases for drift after the initial change. A control plane can contribute configured evidence, but it does not cover every service or release or prove the live header state.

Set them once. Keep them set, provably.

For configured managed origin routes, Infraveil can report selected policy and drift evidence. It does not manage every edge or host, guarantee that headers stay set, or produce proof of configuration state. Generate a starting point with our reverse-proxy tool, then verify it independently.

See how it works