Learn

Web security checks, explained.

The pentesting terms we use and define, plus what our scans check, why it matters and how Barrion runs each check. Look up agentic pentesting, Time to Proof, TLS, headers, cookies, CORS, email and more.

Pentesting guides

PTaaS vs continuous AI pentesting

Human testers booked through a platform, or agentic tests that rerun daily. What each is good at, and the hybrid most teams end up with.

How much does continuous pentesting cost?

What vendors publish for year-round programs in 2026, and what to ask before you sign a quote.

How often should you pentest?

What PCI DSS, SOC 2 and ISO 27001 ask for, and why an app that ships weekly needs testing far more often than that.

Best continuous pentesting tools

12 tools compared on proof, regression tracking, scope, self-serve start, human review, limits and triggers.

Best AI pentesting tools

15 AI pentesting tools for web apps, APIs and networks, plus open-source frameworks, on the same criteria.

XBOW alternatives

What XBOW does well, and the alternatives for web and API, network, human-led and open-source testing.

Pentesting in CI/CD

Where a pentest step fits in a pipeline, how to start it without blocking the build, and working examples.

Your customer asked for a pentest report

What security reviews and questionnaires ask for, and whether to send a letter, a summary or the full report.

Is a pentest required for SOC 2?

What the Trust Services Criteria say, what auditors and customers expect, and Type I vs Type II timing.

API penetration testing

The OWASP API Security Top 10 (2023) item by item, REST vs GraphQL, why multi-role testing matters, and how often to test.

How much does a penetration test cost?

Sourced 2026 price ranges for web app and API pentests, and what a quote should include.

AI vs manual pentesting

What AI pentests catch that human testers miss, and what still needs a person.

Pentest vs vulnerability scan

A scan flags possible weaknesses. A pentest proves which ones an attacker can use.

Web security checks

TLS configuration and monitoring guide

What TLS security is, why it matters for web apps, and how Barrion checks TLS configuration, protocols, and certificates. Passive, production-safe.

Security header monitoring guide

What HTTP security headers are, why they matter, and how Barrion monitors CSP, HSTS, X-Frame-Options, and more. Step-by-step fix guides.

Secure cookies: Secure, HttpOnly and SameSite

What the Secure, HttpOnly and SameSite cookie attributes do, why they matter, and how Barrion checks Set-Cookie headers on your site.

Mixed content on HTTPS: detection and fix

What mixed content is, why it weakens HTTPS, and how Barrion's passive scan finds HTTP resources on HTTPS pages, with fix guides.

CORS and cross-origin security monitoring

What CORS is, why misconfiguration matters, and how Barrion checks Access-Control-Allow-Origin and related headers on your site.

Email domain security: SPF, DKIM and DMARC

What SPF, DKIM, and DMARC are, why they matter for email security, and how Barrion checks your domain's email configuration.

TLS certificate validity and expiry monitoring

Why certificate validity and expiry matter, and how Barrion monitors certificate expiry and hostname match. Avoid outages from expired certs.

Clickjacking: X-Frame-Options and frame-ancestors

What clickjacking is, how X-Frame-Options and CSP frame-ancestors prevent it, and how Barrion checks your configuration.

Content Security Policy (CSP) monitoring guide

What CSP is, why it matters for XSS and injection, and how Barrion checks your Content-Security-Policy header. Fix missing or weak CSP.

How to suppress Server and X-Powered-By headers

What server information disclosure is, why it matters, and how Barrion detects headers that leak server or platform details.

Referrer-Policy: a practical reference

What Referrer-Policy is, why it matters for privacy and URL leakage, and how Barrion checks the Referrer-Policy header on your site.

Permissions-Policy: lock down browser features

What Permissions-Policy is, why it matters for browser features and APIs, and how Barrion checks your Permissions-Policy header.

X-Content-Type-Options: nosniff in 5 minutes

What X-Content-Type-Options nosniff is, why it prevents MIME sniffing attacks, and how Barrion checks your configuration.

HSTS: enable Strict-Transport-Security safely

What HSTS is, why it prevents downgrade attacks, and how Barrion checks your Strict-Transport-Security header. Enable HSTS step by step.

CAA records: restrict certificate issuance

What CAA DNS records are, why they limit which CAs can issue certs for your domain, and how Barrion checks your CAA configuration.

SameSite cookies: Lax, Strict, None explained

What SameSite=Lax/Strict/None mean, what changed with Chrome 80, and how to choose the right value. Block most CSRF without breaking SSO.

See what applies to your site.

Run a free passive scan to find which of these checks fail on your domain, with a fix for each one.