01 — Sections
從哪裡開始
依目標挑選入口。全部免費,免註冊。
02 — Field notes
重大資安事件與漏洞
Capital One、Log4Shell、MOVEit 等——公開的入侵事件與漏洞,轉化為你的防禦之道。
03 — Our stance
本站堅持的原則
資安產品必須先把自家的事做好。
We don't hold secrets
We never store your real API keys — only metadata. The safest secret is the one we can't leak.
Scan only what you own
Diagnostics run on verified domains only. Internal IPs and metadata endpoints are blocked — SSRF defense is built in.
Minimal blast radius
Isolation so one breach can't cascade. This site itself runs on a dedicated, isolated host.
We test on ourselves
This site watches its own dependencies for CVEs. The incident that started this never gets missed by a human again.