Buk · Domain Security

Buk Domain Security

Domain security

Domain security posture for Buk, probed live across 6 host(s) and 3 registrable domain(s). 6 host(s) serve HTTPS (up to TLSv1.3); 2 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=quarantine).

Human ResourcesPayrollHR TechTime and AttendanceBenefitsRecruitingPerformance ManagementEmployee RecordsLatin AmericaChileSoftware-as-a-ServiceWebhook

Transport & Host Security

www.buk.cl
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 20 05:00:01 2026 GMT
demo.buk.cl
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 22 23:59:59 2026 GMT
app.swaggerhub.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Nov 14 23:59:59 2026 GMT
app.ctrlit.cl
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Dec 1 23:59:59 2026 GMT
app2.ctrlit.cl
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Dec 1 23:59:59 2026 GMT
zktc.prod.asis.buk.cl
HTTPS: yes · HSTS: no

Domain (DNS/Email) Security

buk.cl
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none
swaggerhub.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
ctrlit.cl
DNSSEC: no · SPF: no · DMARC: no · CAA: none

Source

Domain Security

Raw ↑
generated: '2026-08-08'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts (extended by hand to cover the two Buk
  Asistencia API hosts, which are not on a buk.cl domain)
hosts:
- host: www.buk.cl
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 20 05:00:01 2026 GMT
  hsts: true
  hsts_max_age: 31536000
- host: demo.buk.cl
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 22 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 63072000
- host: app.swaggerhub.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Nov 14 23:59:59 2026 GMT
  hsts: null
- host: app.ctrlit.cl
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec  1 23:59:59 2026 GMT
  hsts: false
  note: Buk Asistencia production API host declared in the ApiAsistencia OpenAPI servers[]
- host: app2.ctrlit.cl
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec  1 23:59:59 2026 GMT
  hsts: false
  note: Second Buk Asistencia production host declared in the same contract
- host: zktc.prod.asis.buk.cl
  https: true
  hsts: false
  note: Biometric clocking ingestion host declared in the AttendanceBiometrics OpenAPI servers[]
domains:
- domain: buk.cl
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: quarantine
- domain: swaggerhub.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: ctrlit.cl
  dnssec: false
  caa: []
  spf: false
  dmarc: false
  note: The Buk Asistencia API runs on a separate, unhardened domain with no SPF, no DMARC, no CAA
    and no DNSSEC.
findings:
- buk.cl serves HSTS with a one-year max-age on www and a two-year max-age on tenant hosts; TLS 1.3
  throughout.
- buk.cl publishes SPF and a DMARC record at p=quarantine (not reject).
- No CAA record on buk.cl or ctrlit.cl; DNSSEC is not enabled on either.
- The Buk Asistencia API hosts (app.ctrlit.cl, app2.ctrlit.cl) send no HSTS header and sit on ctrlit.cl,
  a domain with no SPF, DMARC, CAA or DNSSEC.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/buk-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.