Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: high
Fingerprint: c2db3a1c40d490db1a0bbaa3924ef5a2969d8ff2194f58348cd805a549d7e8fe
GraphQL introspection enabled at /graphql Types: 408 (by kind: ENUM: 44, INPUT_OBJECT: 170, INTERFACE: 1, OBJECT: 187, SCALAR: 6) Operations: - Query: Query | fields: checkSlug, companies, company, crcPurposes, creditBundles - Mutation: Mutation | fields: addAccountMember, addTfaPhoneNumber, archiveCheckLists, archiveDocuments, archivePeople Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 10 crcPurposes (args: optional/default) : total=0 creditBundles (args: optional/default) : total=4 creditTransactions (args: optional/default) : total=0 departments (args: optional/default) : total=0 documents (args: optional/default) : total=0 members (args: optional/default) : total=0 paymentMethods (args: optional/default) : total=0 people (args: optional/default) : total=0 phoneNumbers (args: optional/default) : total=0 products (args: optional/default) : total=0
Open service 99.83.217.1:443 · admin.reportsecurely.com
2026-01-09 13:54
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://admin.reportsecurely.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=wJvKGrGaYCQoBJjk%2FJQOBF7V44dm%2BFGf0BDvHwneh%2FI%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767966858"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=wJvKGrGaYCQoBJjk%2FJQOBF7V44dm%2BFGf0BDvHwneh%2FI%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767966858"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: cc3d2025-251b-3e65-2710-637e920966ea
X-Runtime: 0.004220
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 13:54:18 GMT
Connection: close
Open service 99.83.217.1:443 · admin.reportsecurely.com
2026-01-02 13:49
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://admin.reportsecurely.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=jUHqB5dugOQHVU5O6ofbeOfn0aSo%2FUShBfdqy9GVkOM%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767361781"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=jUHqB5dugOQHVU5O6ofbeOfn0aSo%2FUShBfdqy9GVkOM%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767361781"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 9f771e1e-8b11-66cf-03d6-b35de5c4b850
X-Runtime: 0.004711
X-Xss-Protection: 0
Date: Fri, 02 Jan 2026 13:49:41 GMT
Connection: close
Open service 99.83.217.1:443 · admin.reportsecurely.com
2025-12-30 14:46
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://admin.reportsecurely.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=046DYjqDW4lZbv6eTUuRYErG8UovzNekJtnkRqMsk%2BQ%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767105970"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=046DYjqDW4lZbv6eTUuRYErG8UovzNekJtnkRqMsk%2BQ%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767105970"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 175a82ee-4669-e3c7-19bf-5810f0ad1ac6
X-Runtime: 0.003555
X-Xss-Protection: 0
Date: Tue, 30 Dec 2025 14:46:10 GMT
Connection: close
Open service 99.83.217.1:443 · admin.reportsecurely.com
2025-12-22 10:10
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://admin.reportsecurely.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=3pmAG7NoC6IjN%2F2Tl26unSa43m%2FN8onbW9r6F0ysJkk%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766398215"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=3pmAG7NoC6IjN%2F2Tl26unSa43m%2FN8onbW9r6F0ysJkk%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766398215"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 45c33810-21bc-d117-6c8d-09e0f36fc781
X-Runtime: 0.003729
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 10:10:15 GMT
Connection: close
Open service 99.83.217.1:443 · admin.reportsecurely.com
2025-12-20 07:11
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://admin.reportsecurely.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=3LZMy6S8zJACiUcwfSH%2FWd5Nr6U2eXzXEw5jrDruzO4%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766214686"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=3LZMy6S8zJACiUcwfSH%2FWd5Nr6U2eXzXEw5jrDruzO4%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766214686"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 26c4a1b7-f6a7-2bd6-d528-5c66a089e852
X-Runtime: 0.003545
X-Xss-Protection: 0
Date: Sat, 20 Dec 2025 07:11:26 GMT
Connection: close