Every company that runs our free Surface Check gets an A to F grade for the part of their security that faces the public internet. We have now checked 284 of them, and the anonymous picture is worth sharing. A fair caveat first: these are companies that chose to run a security tool, not a representative sample of all startups, so read the numbers as a snapshot of the ones curious enough to look, not a verdict on everyone.
The grade spread
Grades cluster in the middle. Here is how the 284 checks landed.
- A: 33%
- B: 36%
- C: 23%
- D: 7%
- F: 1%
Roughly 31% scored a C or below, and about 8% landed at D or F. Most companies are not wide open, but a clear slice are leaving easy, visible things unaddressed. If you want to know what a grade actually means, we broke it down in what your Surface Score means.
The gaps we see most often
The same handful of issues come up again and again across the 284 checks.
- 90% have no MTA-STS policy, so inbound mail can be delivered without TLS.
- 65% publish no security.txt, so there is no clear way to report a vulnerability.
- 61% set no Referrer-Policy.
- 55% have no Content-Security-Policy.
- 45% are missing X-Content-Type-Options: nosniff.
- 38% can be embedded in a hostile frame (clickjacking).
Almost all of these are configuration and hygiene: headers that were never set, email records that were never tightened. They are cheap to fix and worth fixing, and several are the kind of default that ships open, which is exactly the theme of security misconfiguration in plain English.
Most of this is hygiene. The risks that bite are inside.
Here is the honest limit of any external grade, including ours. Everything above is visible from outside, so it is the easy half to measure. The failures that actually cause breaches, such as whether one customer can reach another's data, live inside the application where a passive scan cannot see them. A clean external grade is necessary, not sufficient. That is why our own work is a real person going through the app by hand, and why we keep saying a list of vulnerabilities is not security.
Check your own
Run the free Surface Check on your domain to see where you sit, then close the quick wins. If you want the inside half looked at properly, our application security assessment reviews authentication, access control, data handling and configuration in the round. We prepare the fixes and hand them to your team to review and deploy, or apply them directly where you have authorised us to do so in writing. You can get in touch through our website.