For small & growing businesses
Scheduled scans, DNS/TLS checks, and forgotten-subdomain discovery - the basics enterprise scanners charge thousands a year for, built into Starter from £29/month.
Security Score
Good - minor issues
my-startup.io
just now
TLS certificate expires in 4 days
issuer: Let's Encrypt · no auto-renewal detected
SPF record missing - spoofing risk
No SPF TXT record found on root domain
Forgotten staging subdomain still live
staging.my-startup.io · exposed admin login
AI Summary
Overall posture is solid. One certificate needs renewing this week, and a staging subdomain with an exposed admin login should be taken down or locked behind auth.
Features for small & growing businesses
Scanning
HTTP/TLS, HTML, network traffic, JavaScript CVEs, tag managers, third-party supply chain, platform misconfigurations, server/CMS software CVE checks, and AI synthesis all run on every scan.
Platform Security
Detects the most common security failures in apps built with Lovable, Supabase, Base44, Bubble, and similar AI app builders - publicly readable databases, exposed service_role keys, and known platform CVEs.
Scanning
Web server software disclosed in response headers (Apache, nginx, IIS, PHP, and more) is matched against the National Vulnerability Database, with the exact version and CVE ID shown for anything found.
Scanning
Detects the CMS or e-commerce platform a site runs on - WordPress, Joomla, Drupal, Magento, Shopify, Wix, Squarespace, Webflow, and more - and checks any self-hosted, version-disclosed platform against the National Vulnerability Database.
DNS & Subdomains
SPF, DMARC, DNSSEC, CAA, mail and nameserver records - every check shown, even when clean, so you can see exactly what was verified.
DNS & Subdomains
Certificate issuer, expiry, protocol version, cipher suite, and key strength - flagging weak or expiring certificates before they become an outage or a warning page.
DNS & Subdomains
Finds forgotten staging, dev, and admin subdomains via common-name enumeration plus a certificate transparency log lookup (real hostnames a public CA has issued a certificate for), with a quick reachability check on each - and a one-click button to run a full scan on any of them.
DNS & Subdomains
Every discovered subdomain's CNAME record is checked against commonly-hijacked services (GitHub Pages, Heroku, S3, Azure, Netlify, and others) for dangling or unclaimed targets an attacker could register and serve content from.
Scanning
When you scan a bare IP directly, a passive connect-only probe checks common non-web service ports (databases, remote access, file transfer) for exposure, captures any banner offered, and runs a reverse DNS (PTR) lookup - never sends payloads or attempts exploitation.
AI Investigation
An AI agent crawls your entire site - or a defined scope - running all 8 layers on every page it decides is worth investigating.
AI Investigation
AI-written remediation steps specific to each finding - not generic advice. Tells your developer exactly what to change and why.
AI Investigation
A ranked top-25 fix list from your latest scan, deduplicated and written in plain English, exportable as a PDF you can hand straight to a client or developer without them opening the full report.
Reports
Timestamped, formatted PDF with your scan details, findings, and an attestation block. Accepted by auditors for SOC2, ISO 27001, NIS2, and DORA evidence.
Automation
Set a weekly, monthly, or quarterly cadence and scans run automatically. Never miss a security check-in for SOC2, ISO 27001, NIS2, or DORA again.
Automation
Get notified when a scheduled scan completes or when a new critical or high severity finding is detected - before your next scheduled check.
Support
A chat assistant that knows your scan results - ask it to explain a finding, walk through remediation, or find the right guide, right from the report or dashboard you're already on.
Team
A glanceable, colour-coded report card for your whole account and every domain - security score, findings by severity, DNS/TLS posture, active testing, and compliance coverage all in one grid. Free for every account; paid tiers unlock more tiles as you upgrade.
Starter and up
You don't have an in-house security team to interpret a hundred findings - the Priority Remediation Plan ranks the top 25 that actually matter and explains each in plain English, ready to export as a PDF and hand straight to whoever's doing the fixing, in-house or contracted.
Every finding scored by severity, then whether a CVE is involved, then how long it has sat open - so the list is always "fix this first," not just "everything we found."
Each item comes with specific, actionable remediation advice - not a CVE ID and a shrug.
Hand a finished plan straight to a client or developer - no one has to click into individual findings to know what to do next.
Mark items Open, In Progress, or Resolved and assign them to a teammate, right from the plan - a Pro-plan upgrade on top of Starter.
Pricing
Full-site scans, DNS/TLS analysis, and scheduled monitoring - at a fraction of what enterprise scanners charge.