ethika.app

.app crawl

First seen 2026-04-15 · Last seen 2026-05-07 · ok HTTP/1.1 200 420 ms crawled 2026-05-10

CH · 185.143.103.238 · AS29222 Infomaniak Network SA

Reputation 100/100

Classifying

HTML metadata

Description
Secure whistleblowing platform based on GlobaLeaks free and open-source software.
Language
en

Technology

Server
GlobaLeaks

DNS records live

NS
  • nsany1.infomaniak.com
  • nsany2.infomaniak.com
MX
  • 10 mail.protonmail.ch
  • 20 mailsec.protonmail.ch
TXT
  • protonmail-verification=6626d544380a02bcfd1536218459830976bc8a84

Email authentication strong

SPF
v=spf1 include:_spf.protonmail.ch ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine
policy: quarantine
DKIM
no key found at common selectors

Certificate (current)

E7
from 2026-03-10 to 2026-06-08
Expires in 20 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://ethika.app/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
  • cross-origin-resource-policy
findings
  • missing frame protection
Header values
referrer-policy
no-referrer
permissions-policy
accelerometer=(),ambient-light-sensor=(),bluetooth=(),camera=(),clipboard-read=(),clipboard-write=(self),document-domain=(),display-capture=(),fullscreen=(),geolocation=(),gyroscope=(),idle-detection=(self),keyboard-map=(),local-fonts=(),magnetometer=(),microphone=(),midi=(),notifications=(),payment=(),push=(),screen-wake-lock=(),serial=(),speaker-selection=(),usb=(),web-share=(),xr-spatial-tracking=()
x-content-type-options
nosniff
content-security-policy
base-uri 'none';connect-src 'self';default-src 'none';font-src 'self';form-action 'none';frame-ancestors 'none';frame-src 'self';img-src 'self';media-src 'self';script-src 'self';style-src 'self' 'nonce-KyRrcnwf4pUeUydybCkgGw==';trusted-types angular angular#bundler dompurify default;require-trusted-types-for 'script';report-to csp-endpoint
strict-transport-security
max-age=31536000; includeSubDomains; preload
cross-origin-opener-policy
same-origin
cross-origin-embedder-policy
require-corp
cross-origin-resource-policy
same-origin

Links to (2)

Linked from (1)