We run a directory of launched software (web apps, SaaS, AI tools) and every listing gets the same deterministic 7-frame benchmark. No LLM in the scoring path, public surface only: the headers and policies a browser sees before you ever sign in.
Across 6,289 launched products, here is the security baseline as measured on August 4, 2026:
76% ship with no Content-Security-Policy. CSP is the browser's front line against injected scripts (XSS).
39% have no Strict-Transport-Security header, leaving a window for protocol-downgrade attacks.
35% have no schema.org markup, which makes them invisible to AI answer engines and rich search results.






