Outside-in scanning for your live domains, applications, infrastructure, and MCP / AI endpoints. No agent, no install, nothing to deploy — Detect reads what your servers already tell the public internet.
Every scan examines your public surface across five areas. Nothing is guessed and nothing is invented — a finding is a check that did not pass, and every one names the specific control to change and the PCI DSS v4.0.1 requirement it maps to, where an honest mapping exists.
Protocol versions, cipher strength, certificate validity and expiry, HSTS. The layer everything else on your surface depends on.
Content-Security-Policy, frame options, transport security, and the rest of the header set browsers use to defend your users on your behalf.
Open ports and reachable services. What you have facing the internet is often more than what you meant to have facing the internet.
Version banners, server fingerprints, and the small volunteered details that tell an attacker exactly which exploit to reach for.
Publicly reachable Model Context Protocol endpoints and whether they enforce authentication, encrypt transport, and keep a safe CORS posture — the surface AI agents open that nothing else scans for.
Non-intrusive by design. It opens normal connections and reads what your servers publicly volunteer. No payloads are sent, no endpoints are exercised. Free on any domain, right now, without asking anyone.
Active testing for CVEs, exposed paths, misconfigurations, and unauthenticated MCP tool-catalog disclosure — and it runs only on domains you have proven you control. Ownership is verified before a single active probe is sent, enforced in the scan worker itself, not just the UI.
Each scan produces a letter grade (A–F) and a 0–100 score, weighted across the five check families. The report shows how many checks ran alongside how many need attention, so the grade reflects your real external posture — not a guess dressed up as one.
On Pro, any scanned domain can be put on an automatic rescan — weekly, biweekly, monthly, quarterly, or semiannual. We only email when something actually changes: a new finding, a resolved one, or a grade that moved. A rescan that finds nothing new sends nothing at all, so an email always means something worth reading.
The full passive scan is free on every plan — up to 5 scans a month, all five check families, a real letter grade. Pro adds unlimited scans, active deep testing on verified domains, scheduled rescans, and change-only monitoring.
Full passive scan, up to 5/month. All five families, letter grade, PCI DSS mapping.
$15.99/mo billed annually. Unlimited scans, deep active testing on verified domains, scheduled rescans, change-only alerts.
One-time active deep scan for a single verified domain. No subscription required.
Full details and the Detect + Code bundle are on the pricing page.