Understand a finding
Turn a summary into something you can review.
Read the prompt
Explain the most important finding from this CertScore report. Show the retained evidence, explain its limitations, and suggest what a human should verify next.
Give your AI assistant the tools to scan public websites, explain privacy signals and show the evidence behind each finding.
CertScore account + Marketplace API key. Shared usage limits apply.
From a question to evidence
“What should I know about this website's privacy?”
Step 1 · Your access
Sign in here to manage your subscription and keys. Your assistant uses the API key for scan requests; you do not need to sign in for each scan.
Sign in or create your CertScore account. Then confirm your AWS subscription and create your API key.
Sign in or create an accountSubscribe to the free offering in AWS Marketplace, then choose Set up your account to return here.
Open AWS Marketplace ↗Keys expire after 90 days. Replacing or revoking a key stops new requests using it. Manage subscription cancellation in AWS Marketplace; public reports remain public.
Step 2 · Connect once
MCP connects your assistant to CertScore's scanning tools. Once connected, you can ask questions in plain language.
In your assistant's MCP settings, add a remote server using Streamable HTTP. Your client must support a custom Authorization header or bearer-token authentication.
Server URL
https://mcp.certscore.ai/mcp/marketplace/lightIf asked for a bearer token, enter your key. For a custom header, use Authorization with the value Bearer YOUR_API_KEY. Replace the placeholder with your key; keep it out of chat messages.
Check the connection before scanning
Start or restart the server in your client's MCP settings. Check its discovered tool list for certscore_scan_site, certscore_get_scan_status, certscore_get_scan_bundle and certscore_get_report_evidence_page, then enable them.
Tool discovery does not start a scan. An assistant's text saying it is connected is not enough to verify the connection. Once the tools appear, continue with a scan prompt.
Step 3 · Scan & explore
Choose a website and a question. We'll prepare a prompt that asks your connected assistant for evidence, context and a report link.
This builds a prompt in your browser. A scan starts only when you send it to your connected assistant.
What happens next?
Your assistant starts or reuses a scan, checks progress and retrieves the results. Ask follow-up questions about the evidence. A partial preview is not the final report.
Keep the conversation going
Save your report link. Come back when you add a vendor, update your website or have another site to review. Bookmark this page for prompts and connection settings.
Turn a summary into something you can review.
Explain the most important finding from this CertScore report. Show the retained evidence, explain its limitations, and suggest what a human should verify next.
Updated your banner, tags or privacy policy? Check again.
Use CertScore to scan this website again. Tell me the scan date and whether the result was reused. If I provide an earlier report, compare only supported observations with comparable coverage. Do not claim a change from reused or incomplete evidence.
Bring the same questions to your next public site.
Help me review another public website with CertScore. Ask me for its URL, scan it, and summarize the privacy signals, supporting evidence, coverage limitations and report link.
Light may reuse a recent result and shares a public scan allowance. It does not include scheduled monitoring or private workspace history.
For setup or scanning questions, email [email protected]. Include the error, time and timezone, client name/version and scan ID if available. Never send your API key or AWS setup token.
Check that you used the Marketplace endpoint and supplied Authorization: Bearer followed by your API key. The key must be unexpired and not revoked, and its subscription must be active. After replacing a key, update your client and start a new MCP session.
Honor the returned Retry-After interval. Marketplace Light shares the public Light allowance; subscribing does not add a dedicated allowance. If the service is temporarily unavailable, retry later. Avoid repeatedly starting the same scan.
Use a remote MCP client that supports Streamable HTTP and a custom Authorization header or bearer token. An OAuth-only connector cannot use this API-key endpoint directly. See the setup choices above and your client's documentation.
No. Light is for public websites and public reports. Do not submit private URLs or sensitive data. Your API key is private and belongs only in your client's authentication settings. Revoking access does not remove independently public reports.
No. Results describe automated observations with evidence and coverage limitations. Missing evidence does not establish compliance or absence of risk. Use the findings to guide human review.