Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanUnclassified/Scanned 8 Sept 2026, 14:11 UTC/1 browser pass
Drata blocks automated clients at the door while serving real browsers, forcing assistants to drive a browser instead of reading the site directly.
Older scan
This report was produced by an earlier version of the scanner. Some findings may not match how the site is measured now.
Wide. Agents are dropping out well before humans do.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
1 piece of evidence and the recommended fix are recorded for this issue, with notes written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
Robots.txt names 10 AI crawlers and allows them, a real browser is served the page normally, no sitemap, no schema.org markup, llms.txt is published, a declared intent for assistants, a key page turns the honest client away while serving a.
4 observations recorded.
Programmatic onboarding
No API documentation is linked from the homepage in raw HTML or rendered page. No OpenAPI spec exists at any of the 5 standard paths checked. The signup form itself is reachable by browser but offers no programmatic alternative for.
3 observations recorded.
Pricing legibility
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Agent-aware instrumentation
Robots.txt names 10 AI crawlers explicitly and allows them, showing awareness of agent traffic. No MCP manifest exists at any of the 3 standard paths checked. No Web Bot Auth signals are published.
4 observations recorded.
Machine-fetchable trust
No security.txt file exists at /.well-known/security.txt. The homepage refuses automated clients outright with HTTP 403, blocking the most basic trust signal: the ability to fetch and read the site's own published policies.
2 observations recorded.
Commercial rails
A self-serve signup form is reachable 2 steps from the homepage at drata.com/demo. The form asks for 18 fields with 10 required, and does not ask for payment information.
2 observations recorded.
Steps to first value
The primary call to action 'Get Started' leads to a signup form in 2 steps from the homepage. The form is rendered and functional in a real browser.
1 observation recorded.
Required fields
The signup form contains 18 total fields, of which 10 are marked required: First Name, Last Name, Company Name, Work Email, and Number of Employees appear twice in the field list.
1 observation recorded.
Verification walls
No verification requirement appears on the signup page itself. The form collects email and name but does not show email confirmation, phone verification, or identity checks as blocking steps.
1 observation recorded.
Error recovery
10 of 24 form inputs carry validation rules, meaning 42 percent of fields have constraints. No inline error containers or live regions were detected on the form, so error feedback mechanism could not be verified.
1 observation recorded.
It got through 4 of 14.
The site refused automated access at drata.com, so the agent could not reach the site at all.