Latana · Domain Security

Latana Domain Security

Domain security

Domain security posture for Latana, probed live across 5 host(s) and 1 registrable domain(s). 5 host(s) serve HTTPS (up to TLSv1.3); 1 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=none).

CompanyBrand TrackingMarket ResearchConsumer InsightsBrand AwarenessMarketing AnalyticsSurvey DataAdvertisingSaaS

Transport & Host Security

www.latana.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 1 03:32:31 2026 GMT
app.latana.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Feb 24 23:59:59 2027 GMT
back.latana.com
HTTPS: yes · TLS: TLSv1.2 · HSTS: no · cert expires: Feb 25 23:59:59 2027 GMT
llmagent.latana.com
HTTPS: yes · TLS: TLSv1.2 · HSTS: no · cert expires: Feb 25 23:59:59 2027 GMT
resources.latana.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Feb 24 23:59:59 2027 GMT

Domain (DNS/Email) Security

latana.com
DNSSEC: no · SPF: yes · DMARC: yes (p=none) · CAA: none

Source

Domain Security

latana-domain-security.yml Raw ↑
generated: '2026-08-12'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml hosts plus the application hosts discovered in the app.latana.com JavaScript bundle
notes: >-
  The 2026-08-12 pass discovered three Latana-operated hosts that earlier rounds never probed,
  read from the REACT_APP_* configuration block inside
  https://app.latana.com/static/js/main.09065b02.chunk.js: back.latana.com (REACT_APP_API_URL,
  a Rails API backend), llmagent.latana.com (REACT_APP_LLM_AGENT_API_URL, titled "Data Assistant
  Streaming Server") and resources.latana.com. Only the marketing host www.latana.com sends HSTS;
  the application, API and agent hosts send no Strict-Transport-Security header, and the two
  backend hosts negotiate TLS 1.2 where the S3-fronted hosts reach TLS 1.3. Recorded as observed.
hosts:
- host: www.latana.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct  1 03:32:31 2026 GMT
  hsts: true
  hsts_max_age: 31536000
- host: app.latana.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Feb 24 23:59:59 2027 GMT
  hsts: false
  server: AmazonS3
  note: Single-page application shell; answers HTTP 200 with the same 80,361-byte HTML for every path.
- host: back.latana.com
  https: true
  tls_version: TLSv1.2
  cert_expires: Feb 25 23:59:59 2027 GMT
  hsts: false
  note: >-
    Rails API backend (REACT_APP_API_URL). /api-docs answers HTTP 401 with a
    "WWW-Authenticate: Basic" challenge.
- host: llmagent.latana.com
  https: true
  tls_version: TLSv1.2
  cert_expires: Feb 25 23:59:59 2027 GMT
  hsts: false
  note: '"Data Assistant Streaming Server" (REACT_APP_LLM_AGENT_API_URL); /health returns 200.'
- host: resources.latana.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Feb 24 23:59:59 2027 GMT
  hsts: false
  server: AmazonS3
  note: Marketing resources/blog host.
domains:
- domain: latana.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: none