Did you know

The property sites you use aren't all looked after the same way

When you browse a listing or send an enquiry about a home, the details you share travel through whatever technical security setup that particular website happens to have — and, as it turns out, no two sites in the UK property industry are set up quite the same way. We took a quiet look across the sector to see how consistently the basics are being looked after. Here's what we found — shared openly, without pointing at anyone in particular.

Publicly observable data · refreshed periodically · current view: July 2026

Where this data comes from

The numbers on this page are computed from a rotating sample of publicly-available residential property websites across the South East of England, together with the major national property portals for context. The sample is scanned periodically using free, independent industry-standard tools (Mozilla Observatory and Qualys SSL Labs) and our own origin-side configuration checks.

No individual website is named on this page. The chart below shows only the aggregate percentage of the sample where a given security concern is absent or incomplete — it does not, and cannot, identify any specific business.

The industry picture, at a glance

Ordered by prevalence — the concerns most commonly missing across the sampled sites are at the top. Click any row to see a plain-English explanation and what it means for someone using the site.

31 sites in the sample
9 concerns tracked
July 2026 latest refresh

How the data is gathered

The methodology is transparent by design — everything on this page can be reproduced by anyone with a browser.

Sampling

A rotating sample of residential property websites operating across the South East of England, together with the major UK national portals for national context. Individual sites are never listed on this page.

Origin-side checks

In addition, we verify HTTPS enforcement, redirect handling, header hygiene, and cookie configuration — the same checks any browser can observe against any public URL.

Refresh cadence

The sample is scanned periodically and the chart above updates within minutes of each scan completing. No site is ever probed beyond what a normal visit would do.

Reproducing the checks yourself

You do not have to take our word for it. The two tools below are free, run in any browser, and can be pointed at any public URL — including our own.

  1. Pick a public property website — your local agent, a national portal, or FYSH itself. Copy its address.
  2. Run it through Mozilla Observatory at developer.mozilla.org/en-US/observatory. Note the grade and the specific tests that pass or fail.
  3. Run it through Qualys SSL Labs at ssllabs.com/ssltest. Note the grade and the details of the certificate and encryption configuration.
  4. Compare the specific findings on the report cards with the plain-English descriptions above. The percentages here are simply what you'd get if you ran those same tests across many sites and counted up the results.

Important context — what this isn't

Even in aggregate form, it's important to be clear about what these numbers do and don't mean.

  • Not a judgement on any business

    The chart is an industry-wide picture. It is not a judgement on the quality, professionalism, reputation, service or reliability of any specific agency — those are separate concerns and are not measured here.

  • Not a security audit

    This is a snapshot of publicly-observable configuration, not a professional security audit. Real audits are commissioned privately, follow a formal scope, and produce findings only for the organisation involved.

  • Not a permanent picture

    These numbers move. Every scan reflects only what was publicly observable on that day. Sites, providers and configurations change — and the chart moves with them.

  • Not a reason to distrust any specific site

    Many low-scoring configurations come from third-party website providers whose product the agency using them does not directly control. The industry-wide gaps shown above are shared across many operators for many reasons.

Notice. The data on this page is calculated from publicly-observable configuration of property websites, measured with free public tools available to anyone. FYSH does not access private systems, internal data, or non-public information about any organisation. The page is intended for general information about the state of the industry. It is not a security audit of any specific business, does not constitute professional advice, and should not be relied on in isolation for any commercial or reputational decision.

Curious how FYSH handles your data?

Read about how we look after listing details, messages and enquiries — and why security is a first-class concern for us.