WHAT IT CHECKS
Server configuration, response-header configuration and deployment documentation, against 63 rules — HSTS, Content-Security-Policy, clickjacking protection, MIME-sniffing, CORS, cookie attributes, caching of sensitive responses, the Cross-Origin isolation policies, version-disclosing headers, TLS versions and cipher suites, certificate signature algorithms, and HTTP-to-HTTPS redirects.
WHERE THE RULES COME FROM
The OWASP Cheat Sheet Series.
WHAT IT DOES NOT CHECK
- Referrer-Policy is not covered, and is listed on every report. The pack covers 17 of its 18 topics.
- Configuration, not a live scan. It reads the configuration you give it; it does not probe your server.
WHAT YOU GET BACK
- Each gap it finds, with the rule it fails and the source text that rule was taken from, quoted, so you can check it yourself.
- Replacement wording for each finding, and a corrected copy of your document to download.
- The pack's declared gaps, printed on every report, so you know what was not checked.
HOW TO RUN IT
In the browser. Sign in at https://vera.ink/verify, paste or upload the document, and choose this pack. New accounts start with 40 credits; a check costs 3 credits up to about 4,500 words.
From your AI assistant. vera.ink is an MCP server. Connect it to Claude Code or Cursor and ask your assistant to check a file against this pack: https://vera.ink/developers
GOOD TO KNOW
- vera.ink only reports findings it can tie to a rule in this pack, and quotes the source text so you can check it. Anything it can't tie to a rule is dropped from the report.
- It is a review aid, not legal advice or a certification. Read each finding before you act on it.
More checks: https://vera.ink/check