Scoring ledger
TraceLattice calculates four component scores: security header posture, cookie hygiene, third-party exposure, and advanced posture. The final score is a weighted bounded snapshot, not a universal security verdict. Optional advanced headers such as COOP, CORP, and COEP are shown as evidence but are not treated like missing core controls for every site.
Header posture35% weight
Cookie hygiene20% weight
Third-party exposure25% weight
Advanced posture20% weight
Core headersCSP, HSTS, frame protection, nosniff, referrer, permissions
Cookie contextsession/security cookies weighted above preference cookies
Exposure contextknown trackers and third-party scripts weighted above functional CDNs
Advanced contextTLS, DNS email-auth, DNSSEC, CAA, security.txt, SRI, forms, client-side risk
90-100score bandExcellent
80-89score bandGood
70-79score bandMixed signals
60-69score bandContext required
0-59score bandWeak
ReproducibilityHow to challenge a result
Export the JSON report, inspect each component reason and penalty, then compare the evidence with the target response. The score contains no hidden model call, random weighting, or proprietary external reputation feed. The same normalized inputs produce the same scoring decision.