Verification Governance

Security Header & SSL Analysis Policy

Indicators of configuration — not guarantees of overall website security.

SSL / TLS analysis

  • A live TLS handshake is performed to the target host on port 443.
  • Leaf certificate subject, SANs, issuer, validity dates, and signature algorithm are extracted.
  • Expiry warnings are surfaced based on certificate notAfter timestamps.

What SSL analysis does NOT cover

  • OCSP and CRL revocation chasing.
  • Intermediate chain installation issues beyond the leaf.
  • Cipher-suite ordering audits or full TLS protocol regression testing.
  • Application-layer vulnerabilities behind a valid certificate.

Security header analysis

  • Response headers scored against the OWASP Secure Headers project recommendations.
  • CSP, HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and frame controls evaluated.
  • Cookie attributes (Secure, HttpOnly, SameSite) surfaced for sensitive endpoints.

Interpretation

A valid SSL certificate confirms encrypted transport to the host presenting the certificate. It does not attest to the legitimacy of the operator, the safety of the content, or the absence of application-level vulnerabilities. Likewise, a strong header score reflects configuration discipline — not the absence of business-logic bugs, weak credentials, or insider risk.

Last reviewed: June 2026.

Part of the Information Verification Trust Center. Published by Relationale LLC. Founder: Keiron Brown.