Vendor Security Snapshot

Evaluating a vendor? Pay $15 once for a point-in-time snapshot of one third-party hostname's externally-observable security posture — TLS certificate, DNS, SPF/DMARC, security headers, and public blocklists. Emailed to you. No subscription, no certification, not affiliated with the vendor.

Externally observed, point-in-time. No certification implied. Merlonix is not affiliated with the domain you enter.

What is a Vendor Security Snapshot?

It's a one-time, point-in-time report on the externally-observable security posture of a single third-party hostname — for example a vendor or SaaS provider you're evaluating. You pay $15 once, enter the hostname and your email, and we email you the snapshot when it's ready. There is no account, no subscription, and no recurring charge.

What does it actually check?

Only read-only signals that anyone on the public internet can observe: the TLS certificate (issuer, validity dates, days until expiry, key strength), DNS records, email authentication (SPF and DMARC), HTTP security headers, and public DNS blocklists. Everything is the same data a browser or a public scanner would see.

Is this a penetration test or a vulnerability scan?

No. We never attempt to log in, probe, exploit, or send any intrusive traffic to the vendor. Every check is passive and externally observable — the equivalent of reading the vendor's public front door, not testing the locks. If you need an authorized penetration test, that is a different service and requires the vendor's explicit permission.

Is the snapshot a certification or a security guarantee?

No. It is an informational, point-in-time observation of what was externally visible at the moment we ran the checks. It is not a certification, an audit, an accreditation, or a guarantee of the vendor's security. Posture can change at any time after the snapshot is taken.

Are you affiliated with the vendor I enter?

No. Merlonix is not affiliated with, endorsed by, or acting on behalf of any domain you enter. You are requesting an observation of publicly-available information about a third party; the snapshot reflects only what we measured from the outside.

How and when do I get the snapshot?

After payment you're returned to this page and the snapshot is generated and emailed to the address you provided, usually within a few minutes. Check your spam folder if you don't see it. It covers exactly one hostname per purchase.

What are the limits, and can I get a refund?

One snapshot covers one hostname at a point in time. Some checks depend on what the vendor exposes publicly — a signal that isn't published (for example a missing DMARC record) is reported as not-configured rather than as a failure. If a snapshot could not be generated for a valid hostname, contact [email protected] and we'll re-run it or refund the $15.