secscout quietly checks your website every week for expiring certificates, missing security headers, exposed admin ports, and leaky software banners — then emails you a clear, prioritized report. No agents to install, no dashboards to babysit.
Opening to our first customers shortly. $10/month, 30-day free trial · passive, read-only checks on domains you've verified you own
Four passive checks that catch the security gaps small-business sites most often miss — no logins, no attacks, no slowdown.
Catches certificates that are expiring or expired, weak or outdated TLS versions, and trust problems — before your visitors see a browser warning.
Flags missing protections like HSTS, Content-Security-Policy, X-Frame-Options and X-Content-Type-Options — with the exact header to add for each one.
Looks for databases, admin panels and management ports reachable from the open internet that should be firewalled off or bound to localhost.
Spots server and framework version banners that hand attackers a roadmap, so you can genericize them and reduce easy reconnaissance.
From sign-up to your first report in a couple of minutes.
Start your free trial and tell us which domain to keep an eye on.
Click the one-time link we email you. We only ever scan domains you've confirmed are yours.
Every Monday, a plain-English security overview lands in your inbox — sorted by severity, with fixes.
Every finding comes with the affected check, what we saw, and exactly how to fix it. Here's a real example.
One plan. Start free for 30 days — no charge if you cancel before it ends.
Sign-up opens shortly · secure checkout by Stripe · 30-day free trial, cancel anytime
No. secscout only performs passive, read-only checks — the same kind of requests a normal visitor's browser makes. We never log in, never send attacks, and never try to break anything. It's a health checkup, not an intrusion.
No. The checks are lightweight and run once a week from the outside. Your visitors won't notice a thing.
Subscribe, enter your domain, and click the verification link we email you. That's it — your first report arrives the following Monday and then every week after.
We only scan domains whose owner has confirmed they control them. It keeps the service responsible and legal, and makes sure reports only ever go to the rightful owner.
You can cancel anytime through Stripe's secure customer portal. The first 30 days are free — if you cancel before the trial ends, you're never charged.
Small businesses and teams that run a website but don't have a dedicated security person watching it. secscout is the lightweight, always-on second pair of eyes.
secscout is opening to its first customers shortly. Sign-up goes live here soon.
Launching soon