generated: '2026-08-17' method: probed source: live DNS/TLS/HTTP probes of every Acheel and Charlee host reachable from public pages checked: '2026-08-17' summary: >- Every host is HTTPS on TLS 1.3 with a valid certificate, but HSTS is enabled on none of them — not on the public site, not on the borrower funnel, and not on the Charlee broker portal that handles partner authentication. Both registrable domains publish SPF and DMARC, but neither publishes DNSSEC or CAA, and charlee.fr's DMARC policy is p=none (monitor only) against acheel.com's p=quarantine. RFC 9116 security.txt is absent everywhere (see well-known/). hosts: - host: www.acheel.com https: true tls_version: TLSv1.3 cert_expires: Jan 18 23:59:59 2027 GMT hsts: false note: redirects to v2.acheel.com - host: v2.acheel.com https: true tls_version: TLSv1.3 cert_expires: Sep 26 23:28:30 2026 GMT hsts: false note: the live public website - host: faq.acheel.com https: true tls_version: TLSv1.3 cert_expires: Dec 23 23:59:59 2026 GMT hsts: false note: Intercom-hosted help centre on an Acheel hostname - host: emprunteur.acheel.com https: true tls_version: TLSv1.3 cert_expires: Oct 20 03:34:24 2026 GMT hsts: false note: borrower-insurance funnel - host: www.charlee.fr https: true tls_version: TLSv1.3 cert_expires: Oct 18 23:21:51 2026 GMT hsts: false note: Charlee broker brand marketing site - host: back.charlee.fr https: true tls_version: TLSv1.3 cert_expires: Oct 25 23:27:12 2026 GMT hsts: false note: 'Charlee broker portal ("Acheel Omega") — login-gated, no HSTS' domains: - domain: acheel.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: quarantine - domain: charlee.fr dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none