Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=imperva.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2025 Q4
Valid From
December 05, 2025
Valid Until
June 03, 2026
161 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C8:E8:E1:AA:79:8F:72:24:0B:43:2F:BF:43:80:BB:07:5E:E6:BC:C9:69:E4:B0:58:A6:7C:A8:9F:E1:74:34:D9
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
147 domains
*.pwc.com
*.assettelemetrydev.pwc.com
*.bankbenchmarking.pwc.com
*.bookkeepingconnect.pwc.com
*.ca.pwc.com
*.co.pwc.com
*.dev.pwc.com
*.dynamictestingsox.pwc.com
*.east.pwc.com
*.hr.pwc.com
*.intelligentinvoiceagent.pwc.com
*.internal.pwc.com
*.jp.pwc.com
*.ke.pwc.com
*.ksa.pwc.com
*.performplus.pwc.com
*.platformstage.pwc.com
*.proposal.pwc.com
*.ro.pwc.com
*.saratoga.pwc.com
*.sg.pwc.com
*.stage.pwc.com
*.supportcentral.pwc.com
*.terraininsights.pwc.com
*.transparencyhub.pwc.com
*.uprod.pwc.com
*.us.pwc.com
*.viewpoint.pwc.com
*.west-uat-restore.pwc.com
*.west.pwc.com
*.workforcesolutions.pwc.com
*.zm.pwc.com
*.au.indirecttaxedge.pwc.com
*.datamodellingplatform.sa.pwc.com
*.datamodellingplatform.za.pwc.com
*.digitalworklife.africa.pwc.com
*.east.ngc.pwc.com
*.einvoicing.pl.pwc.com
*.intg.ngc.pwc.com
*.junction-dev.lower-pwclabs.pwc.com
*.perf.ngc.pwc.com
*.qa.enterprisecontrol.pwc.com
*.stg.ngc.pwc.com
*.taxandlegalinsights.ke.pwc.com
*.taxdocumentrepository.ke.pwc.com
*.tst.ngc.pwc.com
*.west.ngc.pwc.com
*.workforcehub.br.pwc.com
*.admin.riskfreeinterestcalc.jp.pwc.com
*.dev.taxdocumentrepository.ke.pwc.com
*.digitalworklife.api.africa.pwc.com
*.east.intg.ngc.pwc.com
*.east.perf.ngc.pwc.com
*.east.stg.ngc.pwc.com
*.east.tst.ngc.pwc.com
*.engine.calc.ca.pwc.com
*.engine.report.ca.pwc.com
*.eu.stg.indirecttaxedge.pwc.com
*.hub.reportingsuite.transferpricing.pwc.com
*.stg.riskdetect.insurancefraud.pwc.com
*.stg.taxandlegalinsights.ke.pwc.com
*.stg.workforcehub.br.pwc.com
*.west.intg.ngc.pwc.com
*.west.perf.ngc.pwc.com
*.west.stg.ngc.pwc.com
*.west.tst.ngc.pwc.com
*.word.reportingsuite.transferpricing.pwc.com
*.writer.reportingsuite.transferpricing.pwc.com
*.api.hub.reportingsuite.transferpricing.pwc.com
*.api.writer.reportingsuite.transferpricing.pwc.com
*.digitalworklife.api.stage.africa.pwc.com
*.eu.stg.indirecttaxedge.itx.pwc.com
auditintelligenceassistsuite.com
*.auditintelligenceassistsuite.com
cipdcee.com
*.cipdcee.com
cloudwebapitab.gr
*.cloudwebapitab.gr
*.agentic.ai.navigatetax.pwc.co.in
*.aw.navigatetax.pwc.co.in
*.dev.navigatetaxhub.az.navigatetax.pwc.co.in
*.einvoice.aw.navigatetax.pwc.co.in
*.navigatedata.aw.navigatetax.pwc.co.in
*.qa.navigatetaxhub.az.navigatetax.pwc.co.in
*.wht.aw.navigatetax.pwc.co.in
*.ctd-poc.com
*.ict.ctd-poc.com
*.ripjar.ti.cyberthreatops.com
costinsightshub.england.nhs.uk
*.testdyhfdh.ibrows.ch
imperva.com
pricewaterhouse.in
*.pricewaterhouse.in
*.backend-preprod-ds.digitalsuite.pwc-tls.it
*.preprod-ds.digitalsuite.pwc-tls.it
*.accesssaveit.pwc.at
*.pwc.at
*.pwc.be
*.cognitiveinsightsuite.pwc.ch
*.pensionpillarinsights.pwc.ch
pwc.ch
*.pwc.ch
*.ariasmbc.pwc.co.uk
*.projectoffice.stage.pwc.co.uk
*.pwc.co.uk
*.staging.backend.pwc.co.uk
*.staging.pwc.co.uk
*.ti.pwc.co.uk
*.atoready-engage.pwc.com.au
*.perspectives-stg.pwc.com.au
*.apps.pwc.com.br
*.engagementpricingtool-stg.apps.pwc.com.br
*.humancapitalprocesses.apps.pwc.com.br
*.pwc.com.br
pwc.cz
*.pwc.cz
backend.stage.knowledgeintegrationassistant.pwc.de
dataoperatingsuite-api.pwc.de
dataoperatingsuite.pwc.de
*.pwc.de
*.pwc.fi
*.pwc.fr
*.r-assessment.pwc.fr
*.complianceinsights.pwc.in
*.contractinsights.pwc.in
*.pwc.in
*.pwc.it
*.pwc.my
*.pwc.pe
*.ctech.pwc.pl
*.hrportal.tts.pwc.pl
pwcacademy.sk
*.pwcacademy.sk
*.pwcmalta.com
pwcprivatebusiness.co.nz
*.pwcprivatebusiness.co.nz
pwcslovakia.com
*.pwcslovakia.com
pwcslovakia.sk
*.pwcslovakia.sk
pwctraining.co.nz
*.pwctraining.co.nz
*.samil.com
*.taxagent.samil.com
*.terraininsights.net
valuefinancials.co.nz
*.valuefinancials.co.nz
Other domains in certificate