Automated domain security overviews

Weekly security checkups
for your business domain

secscout quietly checks your website every week for expiring certificates, missing security headers, exposed admin ports, and leaky software banners — then emails you a clear, prioritized report. No agents to install, no dashboards to babysit.

Launching soon See a sample report

Opening to our first customers shortly. $10/month, 30-day free trial · passive, read-only checks on domains you've verified you own

What we check, every week

Four passive checks that catch the security gaps small-business sites most often miss — no logins, no attacks, no slowdown.

TLS & certificate health

Catches certificates that are expiring or expired, weak or outdated TLS versions, and trust problems — before your visitors see a browser warning.

HTTP security headers

Flags missing protections like HSTS, Content-Security-Policy, X-Frame-Options and X-Content-Type-Options — with the exact header to add for each one.

Exposed admin & DB ports

Looks for databases, admin panels and management ports reachable from the open internet that should be firewalled off or bound to localhost.

Software fingerprint

Spots server and framework version banners that hand attackers a roadmap, so you can genericize them and reduce easy reconnaissance.

Set it up once. Forget about it.

From sign-up to your first report in a couple of minutes.

Subscribe & add your domain

Start your free trial and tell us which domain to keep an eye on.

Verify you own it

Click the one-time link we email you. We only ever scan domains you've confirmed are yours.

Get a report every week

Every Monday, a plain-English security overview lands in your inbox — sorted by severity, with fixes.

This is what lands in your inbox

Every finding comes with the affected check, what we saw, and exactly how to fix it. Here's a real example.

Weekly security overview

yourbusiness.com · generated this Monday
0High
2Medium
2Low
5Info
http_headers
HSTS not set
Response from https://yourbusiness.com did not include 'strict-transport-security'.
Fix: Add 'Strict-Transport-Security: max-age=31536000; includeSubDomains'.
http_headers
X-Frame-Options not set
Response did not include 'x-frame-options', leaving the page open to clickjacking.
Fix: Set 'X-Frame-Options: DENY' or a CSP 'frame-ancestors' directive.
tls
TLS certificate valid
Issued by a trusted CA; valid for 31 more days. Negotiated TLSv1.3.
secscout passive security overview — an automated, best-effort report, not a guarantee of security.

Simple, honest pricing

One plan. Start free for 30 days — no charge if you cancel before it ends.

$10 / month
30-day free trial
  • Weekly security overview for your domain
  • TLS, headers, exposed ports & fingerprint checks
  • Plain-English findings, sorted by severity
  • Exact fix for every issue we flag
  • Cancel anytime — no contract
Launching soon

Sign-up opens shortly · secure checkout by Stripe · 30-day free trial, cancel anytime

Questions, answered

Is this a penetration test or a hack attempt?

No. secscout only performs passive, read-only checks — the same kind of requests a normal visitor's browser makes. We never log in, never send attacks, and never try to break anything. It's a health checkup, not an intrusion.

Will it slow down or break my website?

No. The checks are lightweight and run once a week from the outside. Your visitors won't notice a thing.

What do I have to do to set it up?

Subscribe, enter your domain, and click the verification link we email you. That's it — your first report arrives the following Monday and then every week after.

Why do I have to verify my domain?

We only scan domains whose owner has confirmed they control them. It keeps the service responsible and legal, and makes sure reports only ever go to the rightful owner.

Can I cancel? What about the free trial?

You can cancel anytime through Stripe's secure customer portal. The first 30 days are free — if you cancel before the trial ends, you're never charged.

Who is secscout for?

Small businesses and teams that run a website but don't have a dedicated security person watching it. secscout is the lightweight, always-on second pair of eyes.

Know where your domain stands — every Monday.

secscout is opening to its first customers shortly. Sign-up goes live here soon.

Launching soon