Real projects. Real results.

Every number on this page is independently verifiable. No stock photos, no made-up stats. Just before-and-after data from actual work.

Case Study

PokeBotTCG — Security Hardening & Performance Audit

A promotional website for a Discord gaming bot. The site had excellent performance but zero security hardening — scoring an F on security headers and running weak TLS cipher suites.

Results at a Glance
Security Headers
F
A
SSL Labs
A
A+
PageSpeed (Desktop)
99
What We Found
Zero security headers — every major header missing
Weak TLS cipher suites (CBC-based) flagged by SSL Labs
Server version exposed in response headers
No HSTS — browser didn't enforce HTTPS
No Content Security Policy — vulnerable to XSS injection
No clickjacking protection (X-Frame-Options missing)
Security Headers — Before & After
Before
PokeBotTCG security headers score F - all six headers missing
After
PokeBotTCG security headers score A - all six headers present
SSL Labs — Before & After
Before
PokeBotTCG SSL Labs score A with weak ciphers
After
PokeBotTCG SSL Labs score A+ with no weak ciphers
Weak Cipher Suites — Before & After
Before — 6 Weak Ciphers
Six weak CBC cipher suites flagged
After — 0 Weak Ciphers
All weak ciphers removed, only strong suites remain
Performance — Already Excellent
Desktop — 99/100
PokeBotTCG PageSpeed desktop score 99
Mobile — 92/100
PokeBotTCG PageSpeed mobile score 92
What We Did
Added six HTTP security headers
Removed weak CBC cipher suites
Enforced TLS 1.2 and 1.3 only
Hidden server version information
Implemented HSTS with preload
Added Content Security Policy
Configured clickjacking protection
Set referrer and permissions policies

Security hardening transformed this site from an F to an A on security headers and from A to A+ on SSL — without changing a single line of the site's code or affecting its 99/100 performance score.

Our Own Site

Apex Web Forge — Built From Scratch

We don't just talk about performance and security. We prove it on our own site. Every score below is independently verifiable right now.

SSL Labs
A+
Security Headers
A
PageSpeed
99
Hand-coded HTML & CSS — no CMS
Self-hosted private analytics
AI-powered lead notifications
Form-to-Discord pipeline
Automated intrusion detection
Rate limiting on all endpoints
Zero third-party dependencies
Gzip compression & cache headers

Everything we offer to clients, we run on our own site first. This is our proof of concept — scan it, test it, verify the scores yourself.

Verify everything yourself

Every score on this page comes from independent, publicly available tools. Test our site — or any site — right now.

Want to see what your site really scores?

We'll run the same tests on your website and send you the results — along with a plan to fix what we find. Free, no commitment.

Takes 30 seconds. Results within 24 hours.