For small & growing businesses

Real security posture,
without an enterprise budget.

Scheduled scans, DNS/TLS checks, and forgotten-subdomain discovery - the basics enterprise scanners charge thousands a year for, built into Starter from £29/month.

Features for small & growing businesses

Your first real security posture.

Free

Scanning

8-layer security analysis

HTTP/TLS, HTML, network traffic, JavaScript CVEs, tag managers, third-party supply chain, platform misconfigurations, server/CMS software CVE checks, and AI synthesis all run on every scan.

Free

Platform Security

Vibe-coded platform security

Detects the most common security failures in apps built with Lovable, Supabase, Base44, Bubble, and similar AI app builders - publicly readable databases, exposed service_role keys, and known platform CVEs.

Free

Scanning

Server software CVE detection

Web server software disclosed in response headers (Apache, nginx, IIS, PHP, and more) is matched against the National Vulnerability Database, with the exact version and CVE ID shown for anything found.

Free

Scanning

CMS & platform fingerprinting

Detects the CMS or e-commerce platform a site runs on - WordPress, Joomla, Drupal, Magento, Shopify, Wix, Squarespace, Webflow, and more - and checks any self-hosted, version-disclosed platform against the National Vulnerability Database.

Starter

DNS & Subdomains

DNS record analysis

SPF, DMARC, DNSSEC, CAA, mail and nameserver records - every check shown, even when clean, so you can see exactly what was verified.

Starter

DNS & Subdomains

SSL/TLS certificate analysis

Certificate issuer, expiry, protocol version, cipher suite, and key strength - flagging weak or expiring certificates before they become an outage or a warning page.

Starter

DNS & Subdomains

Subdomain discovery

Finds forgotten staging, dev, and admin subdomains via common-name enumeration plus a certificate transparency log lookup (real hostnames a public CA has issued a certificate for), with a quick reachability check on each - and a one-click button to run a full scan on any of them.

Starter

DNS & Subdomains

Subdomain takeover detection

Every discovered subdomain's CNAME record is checked against commonly-hijacked services (GitHub Pages, Heroku, S3, Azure, Netlify, and others) for dangling or unclaimed targets an attacker could register and serve content from.

Starter

Scanning

Open port & service discovery for IP scans

When you scan a bare IP directly, a passive connect-only probe checks common non-web service ports (databases, remote access, file transfer) for exposure, captures any banner offered, and runs a reverse DNS (PTR) lookup - never sends payloads or attempts exploitation.

Starter

AI Investigation

Full-site AI agent

An AI agent crawls your entire site - or a defined scope - running all 8 layers on every page it decides is worth investigating.

Starter

AI Investigation

Per-finding remediation

AI-written remediation steps specific to each finding - not generic advice. Tells your developer exactly what to change and why.

Starter

AI Investigation

Priority Remediation Plan

A ranked top-25 fix list from your latest scan, deduplicated and written in plain English, exportable as a PDF you can hand straight to a client or developer without them opening the full report.

Starter

Reports

PDF evidence export

Timestamped, formatted PDF with your scan details, findings, and an attestation block. Accepted by auditors for SOC2, ISO 27001, NIS2, and DORA evidence.

Starter

Automation

Scheduled recurring scans

Set a weekly, monthly, or quarterly cadence and scans run automatically. Never miss a security check-in for SOC2, ISO 27001, NIS2, or DORA again.

Starter

Automation

Email alerts

Get notified when a scheduled scan completes or when a new critical or high severity finding is detected - before your next scheduled check.

Starter

Support

AI assistant

A chat assistant that knows your scan results - ask it to explain a finding, walk through remediation, or find the right guide, right from the report or dashboard you're already on.

Free

Team

Visual scoreboard dashboard

A glanceable, colour-coded report card for your whole account and every domain - security score, findings by severity, DNS/TLS posture, active testing, and compliance coverage all in one grid. Free for every account; paid tiers unlock more tiles as you upgrade.

Starter and up

A punch list, not a wall of jargon.

You don't have an in-house security team to interpret a hundred findings - the Priority Remediation Plan ranks the top 25 that actually matter and explains each in plain English, ready to export as a PDF and hand straight to whoever's doing the fixing, in-house or contracted.

Top 25, ranked

Every finding scored by severity, then whether a CVE is involved, then how long it has sat open - so the list is always "fix this first," not just "everything we found."

Plain-English AI guidance

Each item comes with specific, actionable remediation advice - not a CVE ID and a shrug.

Client-ready PDF export

Hand a finished plan straight to a client or developer - no one has to click into individual findings to know what to do next.

Status & assignment tracking

Mark items Open, In Progress, or Resolved and assign them to a teammate, right from the plan - a Pro-plan upgrade on top of Starter.

Pricing

Starter covers most growing teams.

Full-site scans, DNS/TLS analysis, and scheduled monitoring - at a fraction of what enterprise scanners charge.

Free

£0
  • 1-page scan per submission
  • All 8 scan layers
  • Vibe-coded platform security scan (Supabase, Lovable, Base44 & more)
  • AI executive summary
  • Scan history in your account
  • Re-scan and delete anytime
  • Shareable public link
  • Visual scoreboard dashboard
Create free account

Starter

Popular
£29/ month
  • Full AI agent investigation
  • Up to 50 pages per scan
  • Per-finding remediation guidance
  • Priority Remediation Plan (top fixes, AI-written, exportable PDF)
  • AI assistant chat
  • DNS & SSL/TLS security analysis
  • Subdomain takeover detection
  • Open port & service discovery for IP scans
  • PDF evidence export
  • Scheduled recurring scans
  • Scan comparison reports
  • Email alerts for new criticals
Get started

Pro

£79/ month
  • Everything in Starter
  • Up to 200 pages per scan
  • ISO 27001 / SOC2 / NIS2 / DORA control mapping
  • Remediation tracking
  • Team access and finding assignment
  • Slack and webhook notifications
  • API access
  • Audit evidence packages
  • Audit activity log
  • White-label PDF branding
Get started

Enterprise

Full DAST
£99/ month
  • Everything in Pro
  • Active Security Testing (DAST)
  • Independent Active Testing Score
  • AI Pentesting (exploitation-confirmation testing)
  • Forced browsing, CORS, reflected-input probes
  • API endpoint discovery & testing (REST, GraphQL, SOAP)
  • Authenticated scan mode (session capture)
  • Enable active testing via API / MCP
  • Expert Mode & Scan Profiles (rate limits, crawl scope, per-tool pentest control)
  • Priority support
Get started