Is split.io legit? TrustSniffer's high-trust assessment: 95/100

split.io
Download PDF Check another site How we score

Verdict

95 OUT OF 100
High Trust

split.io appears legitimate.

Our checks found nothing pointing to fraud. Ordinary care still applies when you pay or sign in.

Not Scam Safe for Login Low Risk

Assessed 2026-08-17 by automated analysis. Classification confidence 55%.

What this site appears to beSDK quickstart/example page for Split feature-management product, containing code snippets and product marketing copy about feature flags, experimentation, and release monitoring.

Evidence status and limitations

Evidence completeness: UNKNOWN

  • The real-world operator identity was not independently verified.
  • Module-level completeness metadata is unavailable for this legacy report.

At a glance

The checks that decide most of this verdict.

Malware enginesNone flagged itVirusTotalClear
Google Safe BrowsingNot listedGoogleClear
Abuse reports on the host0% confidenceAbuseIPDB, 2 reports; shared hosting inflates reportsClear
Domain age11 years oldRegistered historyClear
Web archiveNever archivedNo public history of this siteWatch
CertificateEncrypted connectionIssued by YE2Noted

The page as captured

https://www.split.io/
Screenshot of the split.io homepage captured during the TrustSniffer assessment
What split.io served when TrustSniffer captured it on 2026-08-17. The page may look different now.

Key findings

  • Automated classification: Not Scam.
  • Domain age: more than 10 years (registration continuity).
  • VirusTotal and Google Safe Browsing had no flags for this domain; its hosting IP carries AbuseIPDB reports below the confidence level TrustSniffer treats as a flag.
  • The operator behind the site could not be independently connected to a real-world brand or person.

Full analysis

Overview

Split.io is a commercial SaaS documentation and product site for Split, presenting feature flags, experimentation, release monitoring, SDK integrations, and enterprise platform services for engineering teams; its apparent business model is subscription-based software rather than consumer finance or regulated financial activity.

Scam/Impersonation Risk

No blacklist, phishing, malware, impersonation, or conflicting-identity contradictions were observed. The documentation page presents a coherent software-development use case, including a Split SDK quickstart, feature-treatment evaluation, and placeholder configuration values rather than a credential-harvesting workflow. External reputation checks were clean, while two abuse reports were associated with shared Webflow content-delivery infrastructure, confidence was zero, and the reports were discounted because they applied to shared provider infrastructure rather than being attributed specifically to Split.io. Taken together, the long-established domain, strong global traffic footprint, substantive product documentation, and clean reputation are consistent with an established, apparently legitimate website, although the real-world operator identity is not independently verified.

Evidence
  • The SDK documentation page identifies “Split SDK Quickstart Example” content covering feature flags, experimentation, and release monitoring, with no phishing indicators or sensitive form.
  • The domain registration record shows creation on 2015-03-17 and an age of 11.43 years.
  • External reputation checks recorded 0 malicious and 0 suspicious results, with no blacklist or safe-browsing hit; the domain is within the global top one million traffic footprint.
  • Two reports were attributed to a shared Webflow CDN IP, with confidence score 0 and attribution discounted as shared infrastructure.

Regulatory Verification Notes

The available material supports a commercial software-services interpretation, not a regulated financial-services offering. The site presents Split as part of Harness, and the registration record names Harness Inc. with Gandi SAS as registrar; these are useful identity signals, but they do not independently prove the operating entity. No financial license or registration number is claimed in the supplied site material, leaving a limited disclosure point for enterprise onboarding rather than evidence of deception. A valid domain-validated TLS certificate and established registration infrastructure further support the site’s apparent legitimacy, while the certificate’s domain-validation level does not itself verify corporate identity.

Evidence
  • The product documentation and navigation identify Split, Harness-related product services, SDKs, customer engagement, account access, and demonstration requests.
  • The registration record lists Harness Inc. as owner and Gandi SAS as registrar, with expiry on 2027-03-17.
  • The site’s TLS certificate is issued by YE2, uses DV validation, and is valid to 2026-09-21.
  • No license claim, licensing authority, or license number appears in the supplied site content.

What to Verify Next

Before credential or payment interactions, an enterprise should independently confirm that the Split service and any account or subscription agreement are operated by the intended Harness-related entity. Procurement should also review the applicable service terms, privacy commitments, renewal and cancellation provisions, and payment-protection arrangements, while support and contact channels should be confirmed through an independently sourced corporate route. These checks are proportionate to the high-trust assessment and the remaining uncertainty around independently verifying the operator.

Evidence
  • The analyzed page is categorized as informational SDK documentation and contains no sensitive form.
  • The page contains no login form or hidden password-external form.
  • The page exposes distinct “Contact Us,” “Book a demo,” “Free Account,” and “login” pathways, allowing those channels to be checked independently before use.

Summary Verdict

The overall posture is high trust and low risk, with the available evidence consistent with an established, apparently legitimate software website. The assessment supports ordinary business consideration, but the operator’s real-world identity remains unverified and legitimacy should therefore be described as evidence-consistent rather than proven. No scam or impersonation contradictions were observed.

Infrastructure Integrity

The site is protected by Cloudflare CDN/WAF infrastructure, and all observed addresses were CDN edge addresses with no origin candidate identified. This reduces direct exposure of the origin environment and is a mitigating control, but it is not proof of corporate legitimacy.

Evidence
  • Hosting resolved to AS209242, CLOUDFLARESPECTRUM – Cloudflare London, LLC, US.
  • The infrastructure assessment identified Cloudflare as the CDN/WAF provider and recorded 7 CDN edge IPs with 0 likely origin IPs.

Closing Assessment

Normal browsing and routine evaluation are proportionate to the assessed posture; account or payment use should proceed after the ordinary independent merchant-identity, service-term, return or cancellation, and payment-protection checks expected for a commercial SaaS provider.

Written analysis generated 2026-08-17 by the TrustSniffer Analysis Engine from the evidence in this report.

What the analysis found

No rule findings contributed to this verdict.

Signals weighed against the site

  • AbuseIPDB: 2 reports on hosting IP 2620:cb:2000::1 (Webflow, Inc, Content Delivery Network), 0% confidence. The reports are attributed to shared infrastructure, not specifically to this website.

Identity verification

StatusUNVERIFIED
Identity score30/100
Identity verification confidence50%
  • No on-site identity signals detected

Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.

What TrustSniffer observed

First-party facts recorded during the assessment of split.io.

  • The request stayed on split.io. It was not redirected to another domain. Clear
  • Registration is published under Gandi SAS. Clear
  • DNS for this domain is served by awsdns-19.org, across 4 name servers. Noted
  • The registration is paid up to 2027-03-17. Noted
  • It is hosted on CLOUDFLARESPECTRUM, from a server in US. Noted

Domain intelligence

RegistrarGandi SAS
HostingCLOUDFLARESPECTRUM - Cloudflare London, LLC, US
CountryUS
Server IP2620:cb:2000::1
Name serversns-1183.awsdns-19.org, ns-877.awsdns-45.net, ns-1842.awsdns-38.co.uk, ns-335.awsdns-41.com
SSL issuerYE2
SSL expiry2026-09-21
Domain age11.43 years (continuous registration)
Domain expiry2027-03-17
Archive first seenNot available
Archive snapshots0
ReputationVirusTotal: 0 flagged | AbuseIPDB: 0% confidence, 2 reports | Google Safe Browsing: 0 matches

About this assessment

A trust score summarises the evidence TrustSniffer could collect about split.io at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.

TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.

Common questions about split.io

Is split.io legit?

TrustSniffer's checks found no scam indicators on split.io. It scored 95 out of 100 on 2026-08-17, which is the high-trust band.

Is split.io safe to use?

Our checks found nothing pointing to fraud. Ordinary care still applies when you pay or sign in.

What is the trust score of split.io?

split.io scored 95 out of 100 on 2026-08-17, which places it in the high-trust band. The score is built from the domain's age and registration history, its hosting and certificate, the content of the site itself, and third-party reputation data. There is no human rating and no user review in it.

Download this report as PDF Free, no account needed. Create one to keep a history of the sites you check.
By AminRez, Founder & Lead Security Researcher, TrustSniffer
Produced by the TrustSniffer Analysis Engine · assessed 2026-08-17 · how we assess · report a mistake