Open
Cached
·
just now
80/100
SECURITY SCORE
Certificate Information
Subject
CN=imperva.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2025 Q4
Valid From
December 05, 2025
Valid Until
June 03, 2026
157 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5A:D6:5A:4F:2D:08:30:21:33:2E:54:5C:07:53:C3:2E:F5:11:7B:0F:50:A1:FE:69:20:96:89:B0:66:27:ED:29
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
152 domains
cloudwebapiprd.gr
*.cloudwebapiprd.gr
cloudapistg.gr
*.cloudapistg.gr
*.einvoice.aw.navigatetax.pwc.co.in
*.pwc.com.cy
*.risksensor.pwc.com.tr
*.workforceinsights.pwc.com.tr
grant-manager.com
*.grant-manager.com
imperva.com
*.pwc.or.ke
*.pwc-tls.it
*.pwc.be
*.regulationascode.pwc.ch
*.clientidentificationportal.pwc.co.uk
*.clientidentificationportal.staging.pwc.co.uk
*.dealstechnology.pwc.co.uk
*.deepcommercialintelligence.authentication.pwc.co.uk
*.pwc.co.uk
*.staging.pwc.co.uk
*.adm.proedge.pwc.com
*.admin.managedthreatintel.jp.pwc.com
*.ai.transferpricing.pwc.com
*.aimaturityassessment.my.pwc.com
api.dac6compliance.pwc.com
*.api.engagementcenter.pwc.com
*.api.sightline.pwc.com
api.stage.dac6compliance.pwc.com
*.au.indirecttaxedge.itx.pwc.com
*.be.supplierengagementintelligence.pwc.com
*.ca.pwc.com
*.cyms.pwc.com
dac6compliance.pwc.com
*.dci-uat-dfc5672bd30b472a9f9023e1175a9aaf.pwc.com
*.demo.enterprisecontrol.pwc.com
*.dev-smartbudget.pwc.com
*.devhor.proedge.pwc.com
*.digitalworklife.api.stg.africa.pwc.com
*.digitalworklife.stg.africa.pwc.com
*.docbot-stage.pwc.com
*.docbot.pwc.com
*.east.mx.pwc.com
*.east.ngc.stg.mx.pwc.com
*.einvoicing.pl.pwc.com
*.eu.indirecttaxedge.pwc.com
*.hosting.pwc.com
*.jp.pwc.com
*.lan.pwc.com
*.lite.pwc.com
*.lower-pwclabs.pwc.com
*.managedthreatintel.jp.pwc.com
*.marketplace.asiapacific.pwc.com
*.marketplace.dev.asiapacific.pwc.com
*.my.pwc.com
*.ngc.stg.mx.pwc.com
*.oic.pwc.com
*.pensionview.pwc.com
*.performplus.pwc.com
*.productcentral.products.pwc.com
*.productivitysuite.uk.pwc.com
*.proedge.pwc.com
*.proposal.pwc.com
*.pwc.com
*.qa-smartbudget.pwc.com
*.qahor.proedge.pwc.com
*.readyassess.pwc.com
reh.virtualspaces-stage.pwc.com
rehs.virtualspaces-stage.pwc.com
rehs.virtualspaces.pwc.com
rehshed.virtualspaces-stage.pwc.com
rehshed.virtualspaces.pwc.com
*.riskatlas.pwc.com
*.saratoga.pwc.com
*.sightline.pwc.com
stage.dac6compliance.pwc.com
*.staging.mer.pwc.com
*.staging.pwc.com
strapi.virtualspaces-stage.pwc.com
strapi.virtualspaces.pwc.com
*.testenv.pwc.com
*.transferpricing.pwc.com
virtualspaces.pwc.com
*.webapi.digitaltraceability.jp.pwc.com
*.west.mx.pwc.com
*.west.ngc.stg.mx.pwc.com
*.api.datakit.pwc.com.au
*.cft.pwc.com.au
*.data.pwc.com.au
*.datakit.pwc.com.au
*.documentanalysis.pwc.com.au
*.pwc.com.au
*.agtechinnovation.pwc.com.br
*.pwc.cz
api.connectedscreeningservice.pwc.de
bhw-rechner-stage.pwc.de
connecteddigital.pwc.de
constructionhub.pwc.de
datafactory.pwc.de
digitalbusinesscompass.pwc.de
ediscovery.pwc.de
energyprocessbenchmarking.pwc.de
gaswaermepreisbremse.pwc.de
itcapabilitycompass.pwc.de
itcostefficiencymonitor.pwc.de
*.npenv.dealstechmanagedservices.pwc.de
outsystems.pwc.de
*.propertytaxapp.pwc.de
*.pwc.de
spk-rechner.pwc.de
tas-api.pwc.de
tas.pwc.de
timemanager.pwc.de
transfer.pwc.de
tubes.pwc.de
vatidlookup.pwc.de
*.pwc.dk
*.bat.pwc.es
*.pwc.es
*.pwc.fi
*.accountingpolicymanual.pwc.in
*.fivegassessment.pwc.in
*.integratededucation.pwc.in
*.pwc.in
*.stage.pwc.in
*.staging.pwc.in
*.doc-interact-backend-test.pwc.it
*.piattaformaitalia.pwc.it
*.pwc.it
*.storage.digital-document-platform.pwc.it
*.test.storage.digital-document-platform.pwc.it
pwc.li
*.pwc.li
*.tax.pwc.mx
*.interactiveriskmanagement.pwc.nl
*.pwc.pe
*.lovisa.hrtoolkit.pwc.pl
*.pwc.pl
*.tts.pwc.pl
*.pwc.pt
*.pwc.ro
*.pwc.se
*.cfoinsight.pwc.tw
pwcplus-app.stage-cloud.pwcplus.de
pwcplus-blog.stage-cloud.pwcplus.de
pwcplus-webdav.stage-cloud.pwcplus.de
stage-cloud.pwcplus.de
*.pwcrelativity.com
surfaceink.com
*.surfaceink.com
threatintel.io
*.threatintel.io
Other domains in certificate