Four ways people use HIP.
Use it before visiting a site, while running one, or when adding website checks to your own product.
How HIP checks a website.
HIP scans the site, scores the evidence and lists every reason. Website owners can fix problems, verify their domain and appeal a finding.
Scan
Enter a domain or page. HIP fetches it and collects transport, DNS, content and reputation signals.
Score
Detection rules and weighted scoring rules combine the signals into one trust score and list every reason.
Fix & verify
Owners register a domain, prove control with a DNS record, resolve findings and re-scan to confirm.
Show it
Complete HIP domain verification to qualify for an earned trust badge. Visitors also see results in the portal and browser extension.
What you can use today, and what is still being built.
HTTPS & certificate checks
HIP flags redirect behaviour, protocol versions, issuer, validity window and expiry risk before your visitors see a warning.
DNS & domain verification
Records, mail-authentication signals and a TXT-record proof of ownership that links a domain to its HIP profile.
Explainable trust scores
One score with a clear list of the signals that raised or lowered it, plus the effect of each finding.
Versioned rules & policies
Each result names the policy version, reasons and score changes. HIP keeps evasion-sensitive detection details private.
Browser extension warnings
Checks the page you are on, shows its score in the toolbar, and speaks up only when a risk is meaningful.
Domain verification & trust badges
Domains that pass verification and review earn a trust badge that links back to a live, dated result.
Appeals, feedback & audit history
Disagree with a finding? Submit an appeal, get a manual review, and keep a dated record of every change.
HIP-aware DNS
A resolver that carries trust results at lookup time, so protection works before a page even loads.
Links, messages, images & files
The same trust layer applies to email and chat links without storing private conversations or extra personal data.
Your domain, its signals, and what to do next.
Every finding is a row you can open. Every row says what was checked, what was found, and how much it affects the score.
// Illustrative interface: example data for one domain
The badge is earned through published requirements, not purchased.
Registering a domain is not enough. The owner proves control and meets the current policy for the requested certificate level. Certified status includes authorized manual review. The embedded badge links to verifiable certificate and public-safe status information.
- Bound to verified control and the requested level's policy
- Paused if required checks fail or the score falls below the current standard
- Domain-bound embed with a verifiable click-through result
<img src="https://hip.example/badge/yourdomain.com.svg" alt="Verified by HIP" />
</a>
See where each finding came from.
HIP labels its own checks and any results from outside security providers. You can see the source, what it found and how it affected the score. The methodology page explains how HIP handles each provider.
SSL Labs
Deep TLS configuration grading for the certificate signal.
Google Safe Browsing
Known phishing and malware listings for the reputation signal.
VirusTotal
Multi-engine verdicts on URLs and downloadable files.
HIP-aware resolvers
Trust results delivered at DNS lookup time. In design.