No Content-Security-Policy header on authenticated document responses
- Observed
- header absent on 412 of 412 responses
- Expected
- content-security-policy present and non-permissive
- Source
- https://example.com/account/settings — response headers
Website intelligence
Obcend crawls your site and produces deterministic findings, each one attached to the captured response that produced it. No sampling, no heuristics, no opinions you have to take on faith.
Why it holds up
These are not features. They are constraints the system is built under, and they are what separates an audit from an opinion.
The same site, the same ruleset version, the same result. Runs are deterministic by construction — no sampling, no model output, no run-to-run drift.
Every finding carries the artifact it was derived from. Nothing is asserted without the captured response that proves it.
When a vendor, a client, or an auditor challenges a finding, you open the evidence appendix and the conversation ends.
Lifecycle
The loop is closed. A finding either clears on the next run against the same ruleset, or it does not — and you can see exactly why.
Step 01
A scoped, rate-respecting crawl enumerates reachable documents, assets, and responses. Scope, depth, and concurrency are declared up front and recorded with the run.
Step 02
Each response is measured against a versioned ruleset. Observation is mechanical: a rule either matches the captured artifact or it does not.
Step 03
Every match stores the exact artifact that produced it — markup fragment, headers, timings, source location — hashed and immutable.
Step 04
Scores are computed from findings by a published formula. Open any score and you can trace the exact findings and weights that produced the number.
Step 05
Findings carry the observed value, the expected value, and the location. That is the whole ticket — an engineer can act without a discovery meeting.
Step 06
Re-run against the same ruleset version. A finding either clears or it does not. Improvement is measured, not asserted.
Deliverables
One run produces an executive summary, a technical breakdown, and an evidence appendix. Every claim in the summary is one click from the artifact that supports it.
Executive report · Q3
OBC-SEC-0114
Missing Content-Security-Policy
OBC-PERF-0072
Render-blocking stylesheet on /pricing
OBC-A11Y-0208
Form control without accessible name
OBC-SEO-0031
Duplicate canonical target across 14 URLs
OBC-INFRA-0009
Certificate chain incomplete on cdn subdomain
Every row links to a captured artifact and reproduction steps in the appendix.
We run a scoped crawl, produce evidence-backed findings, and walk your team through the report. No obligation, no pipeline pressure.