Skip to content

Website intelligence

Findings you can prove.

Obcend crawls your site and produces deterministic findings, each one attached to the captured response that produced it. No sampling, no heuristics, no opinions you have to take on faith.

OBC-SEC-0114high

No Content-Security-Policy header on authenticated document responses

Observed
header absent on 412 of 412 responses
Expected
content-security-policy present and non-permissive
Source
https://example.com/account/settings — response headers
2026-07-28 09:14:02 UTCreproduced 3/3 runs · ruleset 2026.07.1

Why it holds up

Three properties every finding carries

These are not features. They are constraints the system is built under, and they are what separates an audit from an opinion.

Reproducible

The same site, the same ruleset version, the same result. Runs are deterministic by construction — no sampling, no model output, no run-to-run drift.

Traceable

Every finding carries the artifact it was derived from. Nothing is asserted without the captured response that proves it.

Defensible

When a vendor, a client, or an auditor challenges a finding, you open the evidence appendix and the conversation ends.

Lifecycle

Findings become remediation. Remediation becomes measurement.

The loop is closed. A finding either clears on the next run against the same ruleset, or it does not — and you can see exactly why.

  1. Step 01

    Crawl

    A scoped, rate-respecting crawl enumerates reachable documents, assets, and responses. Scope, depth, and concurrency are declared up front and recorded with the run.

  2. Step 02

    Observe

    Each response is measured against a versioned ruleset. Observation is mechanical: a rule either matches the captured artifact or it does not.

  3. Step 03

    Evidence

    Every match stores the exact artifact that produced it — markup fragment, headers, timings, source location — hashed and immutable.

  4. Step 04

    Score

    Scores are computed from findings by a published formula. Open any score and you can trace the exact findings and weights that produced the number.

  5. Step 05

    Remediate

    Findings carry the observed value, the expected value, and the location. That is the whole ticket — an engineer can act without a discovery meeting.

  6. Step 06

    Verify

    Re-run against the same ruleset version. A finding either clears or it does not. Improvement is measured, not asserted.

Deliverables

Reports your executives read and your engineers act on

One run produces an executive summary, a technical breakdown, and an evidence appendix. Every claim in the summary is one click from the artifact that supports it.

100%
Findings with evidence
A finding without a captured artifact is not emitted.
3/3
Runs must agree
Non-deterministic observations are suppressed, not reported.
Obcend

Executive report · Q3

72
Composite integrity
Findings
148
Pages crawled
3,204
Reproducible
100%
  • OBC-SEC-0114

    Missing Content-Security-Policy

    high
  • OBC-PERF-0072

    Render-blocking stylesheet on /pricing

    medium
  • OBC-A11Y-0208

    Form control without accessible name

    high
  • OBC-SEO-0031

    Duplicate canonical target across 14 URLs

    medium
  • OBC-INFRA-0009

    Certificate chain incomplete on cdn subdomain

    low

Every row links to a captured artifact and reproduction steps in the appendix.

See a deterministic audit of your own site

We run a scoped crawl, produce evidence-backed findings, and walk your team through the report. No obligation, no pipeline pressure.