← Back to browse

Kestrel Labs

Kestrel is the one-click building code compliance platform for design teams, checking your BIM model against local codes for first-pass permit approval.

kestrellabs.com · Added June 10, 2026 · Last analysed June 10, 2026 · via · 60% unique tagline

StackScope is a free public catalogue of indie launches. We find launches on Product Hunt, Hacker News and similar feeds, then crawl each site to detect its tech stack and score it for launch readiness: DNS, security headers, SEO basics. This page is what we saw on 10 June 2026; the live site may have changed since.

Kestrel Labs ships with the launch fundamentals in place, with complete legal pages, a thorough launch checklist, and clean crawl signals. What needs work: no Content-Security-Policy, analytics without a consent banner, and incomplete email security.

Launched on Product Hunt on June 10, 2026. The site is hosted on Cloudflare in the United States, with a domain registered in 2001. The crawl picked up 10 technologies on this site, covering analytics, CDN, CSS frameworks, and DNS providers. The stack includes Tailwind CSS, Cloudflare, and Cloudflare DNS.

For context, it's running the same core stack as 1,042 other launches and tighter on security headers than most Product Hunt launches.

If you own this site, refresh the snapshot and see the full fix list any time →

9.5
StackScope Score
Excellent
100/100 Launch Readiness
Launch ready
3/3* Legal
Complete*
2/2 Web Standards
Complete
Vibe Score 30 · Some AI signals
Informational pattern-match signal. Does not feed the StackScope Score. See which fingerprints fired →

Tech Stack (10)

Infrastructure
CDN Cloudflare
DNS Cloudflare DNS
Protocol HTTP/3
Security HSTS
Email
Business email Google Workspace (3)
Transactional email Resend
Build & Framework
CSS framework Tailwind CSS
Font Google Fonts
Analytics & Marketing
Analytics Google Analytics (3)
SEO Google Search Console

Infrastructure

Network
AS13335 · US
DNS
Cloudflare DNS
Authoritative nameserver
DNSSEC
Not enabled
DNS responses unsigned. Cache-poisoning vulnerable.
SSL Certificate
Google Trust Services
Valid 4 Jun 2026 to 2 Sep 2026
Certificate as captured in this snapshot, not a live check.
Domain Age
24.6 years
Registered Nov 2001 · Cloudflare, Inc.

Email Security

SPF Not published. Your domain can be spoofed in phishing emails.
DKIM Detected via known email provider
DMARC p=reject Reject (strict). Strong.
MTA-STS mode=enforce Enforce mode. Strong, blocks plaintext fallback.
TLS-RPT Reporting endpoint configured. Receivers can tell you about TLS failures.

Storage (2)

Cookies (2)
NameLifetimeDetected as
_ga 1y Google Analytics
_ga_HY43EMP05Z 1y Google Analytics

Readiness Breakdown How?

Custom title and meta description
Open Graph tags (title, image, description)
Twitter card meta tags
Canonical URL declared
Responsive viewport meta tag
Favicon present
Semantic HTML (nav, main, article)
Page title is 62 characters (advisory) Google only shows about 60 characters of the title in search results; aim for 50–60 to keep the whole thing visible.

Performance How?

177 ms Server response
75% Faster than peers
0.00 Cumulative layout shift
1.0 MB Page weight
563 KB Image weight
4 Third-party domains
0 Console errors
0 Failed requests

40 images: 2 oversized, 36 without width/height, 12 missing alt text

Indicative grade from a single automated render, not a substitute for Lighthouse or field data, and not part of the StackScope score.

Vibe Score Breakdown How?

SignalPoints
Placeholder branding +10
AI onboarding signals +5
AI palette signals +5
AI writing signals +5
AI typography signals +5

This score is based on structural patterns and is not definitive. Many legitimate sites may trigger signals, and AI-built sites may go undetected. It should be treated as an indicator, not a verdict.

AI Stance

Welcomes AI crawlers
llms.txt published
No AI bots blocked in robots.txt
? No directive declared
? None advertised

Well-Known Files

sitemap.xml (35 URLs)
security.txt
llms.txt
ads.txt
humans.txt
? Consent manager not detected
Analytics detected; tracking fires without visitor opt-in.
94% unique

Security Headers (5/6)

Permissions-Policy experimental (check browser support)
X-XSS-Protection deprecated (use Content-Security-Policy)

Build

HTML minified
CSS minified
JS minified
Code splitting
9 JS files
2 CSS files
4 Third-party domains

Brand Colours

App Manifest

Kestrel Labs
display: standalone 2 icons
theme #F3F0E8
Something not look right? If a technology shown here is wrong or out of date, email [email protected] and we'll review it.