hugra.no

.no crawl

First seen 2026-06-01 · Last seen 2026-06-01 · ok HTTP/1.1 200 305 ms crawled 2026-06-02

NO · 185.35.184.202 · AS39783 Webhuset AS

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Hugra — KI for bedrifter med taushetsplikt og sensitive data
Description
Norsk KI-assistent for advokater, regnskapsførere, kommuner og andre som ikke kan bruke ChatGPT med klientdata. Nulltilgangs-kryptert, driftet i EU, GDPR-trygg.
Language
nb

Open Graph

url
https://hugra.no
title
Hugra — norsk KI-assistent
locale
nb_NO
site name
Hugra
description
En norsk KI-assistent der meldingene dine krypteres på enheten din før de lagres — serverne våre lagrer bare kryptert tekst, og KI-en kjører på europeiske servere uten logging.

Technology

CMS
Next.js

DNS records live

NS
  • ns1.nordkapp.net
  • ns2.nordkapp.net
MX
  • 10 mail.protonmail.ch
  • 20 mailsec.protonmail.ch
TXT
  • protonmail-verification=56258af06e9afe788c9fa8d8b8d3f425eab41c38

Email authentication partial

SPF
v=spf1 a mx ip4:185.114.57.56 include:_spf.tem.scaleway.com include:_spf.protonmail.ch include:mailgun.org -all
strict (-all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • s1: k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxHwaAv0Tbeev9MaRYxkdg3YtykXAz/OXXGKUCdTWq6xky8CB6sOXvn5iF0gNyUNesIPnSBbvRIIF0D3GsPq0x+v…
selectors probed

Certificate (current)

R13
from 2026-04-18 to 2026-07-17
Expires in 43 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://hugra.no/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
no-referrer
x-frame-options
DENY
permissions-policy
geolocation=(), camera=(), microphone=(self), payment=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' blob: data:; script-src 'self' 'nonce-OGU3Y2Q4NWUtMzYwNC00NGIwLTk1MzUtZDE1NGVmMDNmNjk2' 'strict-dynamic' 'wasm-unsafe-eval' blob:; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; font-src 'self' data:; worker-src 'self' blob:; connect-src 'self' https: data: blob:; frame-ancestors 'none'; base-uri 'self'; form-action 'self' https://www.mollie.com https://*.mollie.com; object-src 'none'
strict-transport-security
max-age=31536000; includeSubDomains

Links to (1)

Linked from (1)