callistovault.org

.org crawl

First seen 2026-05-01 · Last seen 2026-05-20 · ok HTTP/1.1 200 2821 ms crawled 2026-05-08

US · 188.114.97.3 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Callisto Vault
Description
Callisto's mission is to empower survivors of sexual violence to navigate inequitable systems utilizing technology.
Language
en

Technology

CDN
Cloudflare

Registration

Registrar
GoDaddy.com, LLC
Created
2022-07-13
Expires
2026-07-13 53 days left
Updated
2024-08-27
Name servers
  • ruth.ns.cloudflare.com
  • sam.ns.cloudflare.com

DNS records live

NS
  • ruth.ns.cloudflare.com
  • sam.ns.cloudflare.com
Verified for
  • Google

Email authentication no MX

SPF
not published
DMARC
v=DMARC1; p=none; rua=mailto:bcafc0936be74109b801cf208bcd478c@dmarc-reports.cloudflare.net
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-03-13 to 2026-06-11
Expires in 22 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.callistovault.org/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • cross-origin-opener-policy
  • cross-origin-resource-policy
findings
  • short HSTS max-age
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'self' data:; base-uri 'self'; font-src 'self' https: data:; form-action 'self'; frame-ancestors 'self'; img-src 'self' data: https://www.google-analytics.com; script-src 'self' blob: https://www.google-analytics.com https://donorbox.org/ https://www.googletagmanager.com 'unsafe-inline' 'unsafe-eval'; script-src-attr 'none'; connect-src 'self' ws://localhost:* https://*.callistovault.org/ data: https://browser-intake-us3-datadoghq.com/ https://*.localhost http://*.localhost wss://*.localhost ws://*.localhost http://localhost:*; object-src 'none'; style-src 'self' 'unsafe-inline' https:; manifest-src 'self'; upgrade-insecure-requests
strict-transport-security
max-age=0; includeSubDomains
cross-origin-opener-policy
same-origin
cross-origin-resource-policy
same-site

Linked from (1)