How to run a scan, verify a workshop lab, use the member tools, and understand what we map your findings to.
Comptrusence is free to start. Without an account you can check a password against public breach data, check whether your domain can be spoofed, and watch the open videos in the library. Everything else sits behind a free login, because those tools do real work on our servers and we need to know who is asking.
Go to Sign up. Name, email, password. No card, no trial clock.
You land on the dashboard overview. Every tool is in the left sidebar, and the quick actions on the overview take you straight to the common ones.
Enter your address in the Website Scanner, choose Security, confirm you are authorised, and press Run. A security scan takes about a minute. Full and Design scans take longer because they load your pages in a browser.
Our scans behave like an ordinary visitor, but you must still only scan sites you own or are authorised to test. The scanner will not start until you confirm that, and it is a condition of using the tools.
Two tiers, both free. There is no paid plan for the portal.
| Access | What you get |
|---|---|
| Public | The Password Breach Check, the Email Spoofing Check, the open videos, the blog, and all the information pages. |
| Free account | The Website Scanner and every member tool listed below, plus the full video library as it grows. |
Passwords are hashed with a modern algorithm and never stored in plain text. Sessions are held on our server, not in your browser, and end when you sign out. Every lookup and scan you run is tied to your account, which is how fair-use limits work: each tool allows a set number of runs per hour per account.
All data is processed and held in Australian data centres. What each tool collects is set out in the Privacy Policy.
The scanner looks at your website the way the internet sees it and reports what it finds, mapped to the frameworks your auditor or insurer already asks about. Three profiles.
| Profile | What it looks at | Time |
|---|---|---|
| Security | Your public footprint, the technologies you run, browser protections, certificates and encryption, cross-origin rules, session handling, and third-party components with known published vulnerabilities. | About a minute |
| Design | Screenshots at desktop, tablet and phone sizes, how the layout behaves on mobile, accessibility against WCAG 2.1 A and AA, and search visibility. | A few minutes |
| Full | Both of the above, plus performance measurement. | Several minutes |
Every scan ends in a score out of 100 and a band: Strong from 85, Moderate from 65, Needs attention from 45, and At risk below that. The score starts at 100 and deducts for each finding by severity. Deductions are capped per severity, so one noisy category cannot sink a site on its own, and informational findings cost nothing. The deduction breakdown is shown with the score, so you can see exactly where the points went.
If the site did not respond to us, the score is shown as Not assessed rather than a number. A site we could not reach is not a site that passed.
Findings are grouped into six areas that map to what can be observed from outside: patch applications, application hardening, third-party data sharing, data in transit, admin exposure and breach exposure. Each area is marked OK, attention, or not assessed, and an area is only ever marked OK when a check genuinely looked at it.
Each finding carries a severity, the area it belongs to, the affected address, the evidence we based it on, and a plain-English fix. The evidence is there so you can judge it yourself. Automated checks produce false positives, and we would rather show our working than ask you to trust a red icon.
The self-service scanner makes visitor-level requests only. It does not attempt to exploit anything, guess passwords, or submit forms. Intrusive testing is a separate, contracted engagement with written authorisation, and it is never available through the portal.
Each tool answers one question a small firm actually asks. None of them needs a paid third-party service, and none of them sends your personal information anywhere.
| Tool | You give it | It tells you |
|---|---|---|
| Email Header Analyser | The raw headers of a suspicious email | A verdict, where the message really came from, the route it took, whether SPF, DKIM and DMARC passed, and the warning signs such as a Reply-To that goes somewhere else. There is a sample scam built in so you can see what a bad one looks like. Headers are processed in memory and never stored. |
| Lookalike Domains | Your domain | The typos, swapped letters, look-alike characters and other endings of your domain that someone has already registered, and which of them are set up to send email. Around a hundred variations, checked in a few seconds with ordinary DNS lookups. |
| Breached Services | The domain of a service you rely on, such as xero.com or dropbox.com | Whether that service has a recorded data breach, when, how many accounts, and what kind of data leaked, with passwords highlighted. Answered from a copy of the public breach catalogue refreshed daily on our server. |
| Domain Registration | A domain | When it expires, who the registrar is, whether it is locked against transfer, whether DNSSEC is on, and whether the registrant's details are in the public record. Read from the registry directly. Australian domains get the advice that applies to them, which differs from the rest. |
| DNS and Email Security | A domain | SPF, DKIM, DMARC, MX and DNSSEC posture, which together decide how easily someone can send email pretending to be you. |
| SSL / TLS Checker | A hostname | Certificate issuer and expiry, which protocol versions are accepted, weak ciphers, missing HSTS, and an overall grade. |
| AWS Lab Checker | A resource name from a workshop lab, such as a bucket or instance ID, and the region | Pass or fail for each step of the lab, with a hint pointing back to the step to fix. Read-only checks against your workshop resources; it never creates, changes or deletes anything. |
| Mermaid / UML Renderer | Mermaid or UML code | A rendered diagram you can download as SVG. Flowcharts, sequence, class, state, entity relationship and Gantt, with a starter example for each. Runs entirely in your browser. |
| Tool | You give it | It tells you |
|---|---|---|
| Password Breach Check | A password | Whether it appears in public breach data. Your browser hashes it and sends only the first five characters of the hash, so the password never leaves the page and nobody, including us, learns which one you asked about. |
| Email Spoofing Check | Your domain | Whether forged email in your name would be delivered, from your SPF, DKIM and DMARC records, with a plain-English verdict. DNS lookups only, nothing stored, no login needed. |
Explainers, talks, recordings and walkthroughs on security and compliance, for people who run a business rather than a data centre. Some are open to everyone and are marked as such; the rest are for members. New videos are added as they are made.
Every video is captioned. Captions are on by default and can be switched off with the CC control in the player's control bar. Videos stream from Australian storage over an expiring link that is issued per view, which is why a video address cannot be copied out and shared.
Raw findings are not much use to an auditor. Every finding we report is mapped to the frameworks Australian regulators and customers expect.
An automated scan is evidence, not certification. It does not replace an audit, a manual penetration test, or professional advice. Accessibility results are indicative and are not a legal conformance statement. Six of the eight Essential Eight strategies cannot be observed from the internet at all, and a report says so rather than showing a tick it did not earn.
The portal runs on a JSON API, and a documented public API with tokens is on the roadmap. It is not offered yet, and the tools are rate limited per account, so please do not script against the portal's own endpoints. If you have a use for API access, tell us what it is and we will prioritise it.
Scheduled recurring scans with change alerts, PDF report export, team accounts, and API tokens. If one of these is blocking you, say so.
The site did not answer our requests. Check the address, including https, and that the site is reachable from the public internet. A site behind a VPN, an IP allow-list, a login page, or a firewall that blocks unfamiliar visitors will look like this.
Your session has ended. Sessions expire after a period and when you sign out. Log in again and the tool will work.
Each tool allows a set number of runs per hour per account. Wait a little and try again. If you genuinely need more, email us and say what for.
That is a good result, not a broken tool. Registrations change, so run it again every few months.
The catalogue records breaches whose data has been publicly loaded. Some well-known incidents never were. Nothing recorded means no public record, not that the service has never been compromised.
Every finding includes the evidence we based it on, so you can judge it. If we got it wrong, tell us. That feedback improves the engine.
Email support@comptrusence.com.au or see Contact.