We run a directory of launched software (web apps, SaaS, AI tools) and every listing gets the same deterministic 7-frame benchmark. No LLM in the scoring path, public surface only: the headers and policies a browser sees before you ever sign in.

Across 6,289 launched products, here is the security baseline as measured on August 4, 2026:

76% ship with no Content-Security-Policy. CSP is the browser's front line against injected scripts (XSS).

39% have no Strict-Transport-Security header, leaving a window for protocol-downgrade attacks.

35% have no schema.org markup, which makes them invisible to AI answer engines and rich search results.