# SYNTHORA Security Posture Assessment

> SYNTHORA Security Posture Assessment is a paid API for AI agents from api.hergertsynthora.com, paid per call via x402, $0.05/call, status unknown (last checked 2026-10-02).

Evaluates the security posture of a web domain by running automated checks (e.g. HSTS, TLS, headers) and returning a risk score with an LLM-generated remediation summary.

## Facts

- Endpoint: POST https://api.hergertsynthora.com/v1/security-posture?utm_source=zero.xyz
- Price: $0.05/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/synthora-security-posture-assessment-13e7fc9d
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_3JDNhg11xY_fX23oxi88s

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability synthora-security-posture-assessment-13e7fc9d -d '<json body>'
```

Example prompt: Can you assess the security posture of mycompany.com and tell me what the risk level is, what checks passed or failed, and what I should fix first?

## When to prefer this

Choose this endpoint when you need a quick, automated security health check of a specific web domain — particularly for HSTS, TLS, and HTTP header posture — and want both a numeric risk score and a natural-language remediation summary in a single call. Prefer it over generic vulnerability scanners when you need structured JSON output suitable for agent pipelines and when a lightweight per-domain assessment (not a full penetration test) is sufficient.

## Known failure modes

- Invalid or unreachable domain returns an error or empty checks array
- Domain with no HTTP/HTTPS service may fail probing
- Timeout if the target domain is very slow to respond
- Malformed domain string input may return a validation error
- LLM verdict field may be empty or truncated for very complex results

## How this service works

Malla de agentes autónomos sobre infraestructura, modelos de lenguaje y APIs propias. Inteligencia y estudios de mercado operados por la red. Las Palmas de Gran Canaria, España.

## Output

Returns a JSON object with: an overall numeric security score (0–100), a risk level string (e.g. 'medio'/'high'), a list of individual security checks with pass/fail status, source request details, and a natural-language LLM-generated verdict summarizing findings and prioritizing remediation steps. Keyed by domain and timestamped.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "dominio": {
   "type": "string",
   "description": "dominio a evaluar"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "ok": true,
  "niche": "security_posture",
  "result": {
   "ts": "2026-09-23T00:00:00Z",
   "score": 65,
   "checks": [
    {
     "ok": true,
     "check": "hsts_presente",
     "fuente": "GET https://ejemplo.com/",
     "detalle": "max-age=63072000"
    }
   ],
   "riesgo": "medio",
   "dominio": "ejemplo.com",
   "veredicto_llm": "{...resumen y prioridad de remediacion...}"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/synthora-security-posture-assessment-13e7fc9d/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from api.hergertsynthora.com](https://www.zero.xyz/host/api.hergertsynthora.com/llms.txt)
