generated: '2026-08-10' method: probed source: live DNS/TLS/HTTP probes of the apis.yml Website + Login hosts note: >- Two hosts carry CapsoVision's public surface: the WordPress marketing site at capsovision.com and the CapsoCloud clinical web application at www.capsocloud.com. Neither serves HSTS and neither publishes a CAA record. capsocloud.com has no SPF record of its own and no DNSSEC, but does publish a strict DMARC reject policy that reports to dmarc@capsovision.com. The investor-relations host investors.capsovision.com (Akamai / gcs-web.com) answered HTTP 403 to every automated request and could not be probed. hosts: - host: capsovision.com https: true tls_version: TLSv1.3 cert_expires: Sep 13 07:56:36 2026 GMT hsts: false note: every path answers HTTP 202 with a SiteGround captcha challenge (sg-captcha; header) - host: www.capsocloud.com https: true tls_version: TLSv1.3 cert_expires: Oct 24 23:59:59 2026 GMT cert_subject: CN=*.capsocloud.com hsts: false - host: investors.capsovision.com https: true reachable: false http_status: 403 note: Akamai-fronted Q4/gcs-web investor site; blocks automated clients domains: - domain: capsovision.com dnssec: true caa: [] spf: true dmarc: true dmarc_policy: quarantine - domain: capsocloud.com dnssec: false caa: [] spf: false dmarc: true dmarc_policy: reject dmarc_record: 'v=DMARC1; p=reject; rua=mailto:dmarc@capsovision.com; adkim=s; aspf=s'