87/100 SECURITY SCORE

Certificate Information

Subject
CN=imperva.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2025 Q4
Valid From
December 17, 2025
Valid Until
June 15, 2026 174 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FD:79:29:1F:DD:01:2C:0C:9B:33:5E:DC:25:32:BC:E0:BB:9A:BF:26:7B:08:EC:F0:76:87:4A:B3:28:20:1A:C2
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=31536000 ; includeSubDomains ; preload
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Significantly strengthen CSP directives
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

151 domains
*.pwc.com *.1851.pwc.com *.alpha-perf.pwc.com *.assembly.pwc.com *.auto-qa.pwc.com *.ca.pwc.com *.connectedsolutions.pwc.com *.customerhub.pwc.com *.dev.pwc.com *.employeeclaimsportal.pwc.com *.in.pwc.com *.info.pwc.com *.insights.pwc.com *.insurancefraud.pwc.com *.jp.pwc.com *.lower-pwclabs.pwc.com *.ngc.pwc.com *.performplus.pwc.com *.sg.pwc.com *.stage.pwc.com *.staging.pwc.com *.statelifecycletool.pwc.com *.stg-validation.pwc.com *.stg.pwc.com *.transparencyinsights.pwc.com *.uat2-equityrewardanalytics.pwc.com *.za.pwc.com identity.virtualspaces.pwc.com *.aiavatar.innovationcatalog.pwc.com *.alternative.co.pwc.com *.backend.mer.pwc.com *.blob.sightline.pwc.com *.compliance.1851.pwc.com *.confirmation.in.pwc.com *.cyberconcierge.jp.pwc.com *.east.ngc.pwc.com *.east.stg-validation.pwc.com *.east.stg.pwc.com *.erie.innovationcatalog.pwc.com *.eu.indirecttaxedge.pwc.com *.expro.mer.pwc.com *.globalpayrollplatform.ksa.pwc.com *.insightsengine.transparencyinsights.pwc.com *.int.ngc.pwc.com *.intg.ngc.pwc.com *.ksa.taxautomate.pwc.com *.onlinepayrollreports.ph.pwc.com *.perf.ngc.pwc.com *.projectlifecycleadmin.jp.pwc.com *.reports.transferpricing.pwc.com *.riskdetect.insurancefraud.pwc.com *.stg.ngc.pwc.com *.stg.py.pwc.com *.tst.ngc.pwc.com *.west.ngc.pwc.com *.api.insightsengine.transparencyinsights.pwc.com *.east.int.ngc.pwc.com *.east.intg.ngc.pwc.com *.east.perf.ngc.pwc.com *.east.stg.ngc.pwc.com *.east.tst.ngc.pwc.com *.eu.stg.indirecttaxedge.pwc.com *.peopleconnect.admin.mer.pwc.com *.west.intg.ngc.pwc.com *.west.perf.ngc.pwc.com *.west.stg.ngc.pwc.com *.west.tst.ngc.pwc.com *.za.datamodellingplatform.africa.pwc.com

Other domains in certificate

*.bvsas.sk
caresummit.nl *.caresummit.nl
*.aw.navigatetax.pwc.co.in *.cia.az.navigatetax.pwc.co.in *.uat.cia.az.navigatetax.pwc.co.in
*.gq324e.ctd-poc.com
*.devcfs.com *.prd.devcfs.com *.preprod.devcfs.com
*.easydita.com
*.heromotocorp.biz
imperva.com
*.pwc.or.ke
transparency-reporting-portal-qa.pfizer.com transparency-reporting-portal-stg.pfizer.com
*.pwc-tls.it
*.fundinginsights.pwc.at *.pwc.at staging.knowledgesourceexplorer.pwc.at
*.pwc.be *.stage.pwc.be
*.transformationdelivery.pwc.co.nz
*.api.stg.pwc.co.uk *.dealstechnology.pwc.co.uk *.dev.pwc.co.uk *.internal.pwc.co.uk *.pwc.co.uk *.stage.assessmenthub.pwc.co.uk *.uat2-equityrewardanalytics.pwc.co.uk
*.pwc.co.za
pwc.com.ar *.pwc.com.ar
*.pwc.com.au
*.apps.pwc.com.br *.quickassign.stg.apps.pwc.com.br *.voting.apps.pwc.com.br
backend.knowledgeintegrationassistant.pwc.de funding-program-management.pwc.de lucanet.pwc.de
pwc.ee *.pwc.ee
*.pwc.es
*.pwc.fi *.staging.pwc.fi
*.r-assessment.pwc.fr
*.pwc.ie *.uat2-equityrewardanalytics.pwc.ie
*.pwc.in
*.docsweb.pwc.it *.pwc.it
*.pwc.kr
*.pwc.my *.taxestimatestracker.pwc.my
*.interactiveriskmanagement.pwc.nl *.pwc.nl store.pwc.nl
*.admin-dev.pwc.pe *.admin.pwc.pe *.pwcinternal.pwc.pe
*.de.hrtoolkit.pwc.pl *.enova365.tts.pwc.pl *.hrportal.tts.pwc.pl *.hrtoolkit.pwc.pl *.piapl.tts.pwc.pl *.pwc.pl *.ssb02.tts.pwc.pl *.taxolite.pwc.pl *.tts.pwc.pl
*.pwc.pt
*.stage.pwc.se
*.pwc.tw
*.dev.pwcinternal.co.uk *.hybridworkingdeclaration.dev.pwcinternal.co.uk *.hybridworkingdeclaration.pwcinternal.co.uk *.hybridworkingdeclaration.stage.pwcinternal.co.uk *.stage.pwcinternal.co.uk
pwclegalservices.ee *.pwclegalservices.ee
*.samil.com
*.terraininsights.net
theessentialadvantage.com *.theessentialadvantage.com