Unified.to

Unified.to

View product →
amitfeldmanhq
amitfeldmanhq

@amitfeldmanhq

A unified API for HR/ATS/CRM/auth data is exactly the kind of product where the marketing site's own hygiene is part of the trust pitch so here's a passive launch-day check on unified.to (headers + public HTML only, nothing intrusive):

The good: TLS 1.3 with a Google Trust Services cert, X-Content-Type-Options already set (most launch sites miss this), canonical, robots.txt and sitemap.xml all live, and a fast 522 ms total load (398 ms TTFB).

The finding: five standard security headers are unset — HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy. For a platform whose customers pipe employee and customer records through it, this layer is the cheapest trust signal you control: HSTS is one line, and a report-only CSP lets you watch what would break before enforcing.

Two smaller ones: the title tag runs 111 chars (it gets truncated in SERPs — the front half alone would carry), and there are two H1s on the page where one is the convention. 12 of 43 images are also missing alt text.

Happy to re-run the check free once the headers land. Good luck with launch week!

August 19, 20260 likes 0 replies
Share: