ClickScan — Security checks anyone can run,
in plain language.
Keeping what you own online safe should not require a security team. Sign in with a one-time email code, add what you own, and pay only for the scans you run.
ClickScan is not open to the public yet. Leave us your details and we'll tell you the day it opens.
How it will work
From nothing to a clear answer in a couple of minutes.
Add what you own
A domain, an IP address or a mailbox. You confirm you're authorized to test it — and for the deeper checks you prove it's yours, in whichever way suits you.
Run it now, book it, or repeat it
Run a check on the spot, book it for a date and time in your own time zone, or repeat it daily, weekly or monthly at a discount. It costs a few credits; a scan that fails is refunded.
Read, fix, re-check
A plain-language report with a grade and exact fixes. Export it as a PDF, hand it to whoever needs it, and the next run tells you what changed.
What the platform checks
The platform is not live yet, so everything below is coming soon. The first checks are built and in testing; the rest follow, in this order.
SSL/TLS certificate & encryption
Coming soonIs your HTTPS valid, trusted and modern? Certificate expiry and trust chain, every protocol version and cipher suite your server actually accepts, forward secrecy, HSTS, OCSP stapling, certificate transparency and CAA — graded A+ to F. Named weaknesses are actively probed, not guessed: Heartbleed, POODLE, ROBOT, DROWN, Logjam, CRIME, Ticketbleed, CCS injection, insecure renegotiation and the CBC padding-oracle family. A check we cannot complete says "not tested" rather than passing you.
HTTP security headers
Coming soonWhether your site sends the security response headers that protect visitors — HSTS (forced HTTPS), Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy — plus the cross-origin isolation headers, anything deprecated, and the headers that quietly advertise which software and version you run.
Email security (SPF, DKIM, DMARC)
Coming soonCan scammers spoof your domain? Checks your mail servers and your email authentication — MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI — so phishing and business-email-compromise can't impersonate you. The report carries the raw DNS answers we read, and a generator that writes out the exact records to paste into your DNS, already filled in with your domain.
Email spoofing test
Coming soonWe actually try to deliver a forged message to your own domain and show you whether it gets through — proof, not theory. One fixed, plain-text message that explains itself, sent only ever to an address at the domain being tested. If your server refuses it for the wrong reason we report the test as inconclusive rather than calling it a pass.
Email breach exposure
Coming soonWhich known breaches an address of yours appears in, and what types of data each one held — passwords, addresses, phone numbers. A mailbox is an asset in its own right here, so it gets the same history, scheduling and reports as a domain. We never receive the breached values themselves.
Domain threat intelligence
Coming soonFinds look-alike and typosquatting domains registered to impersonate your brand, so you catch phishing infrastructure early.
Open ports & perimeter
Coming soonFinds internet-exposed services on your servers. An active check — it will run only on assets whose ownership you've proven.
Subdomain & asset discovery
Coming soonFinds the subdomains and internet-facing hosts attached to your domain, so you can see — and check — your whole attack surface, not just the sites you already knew about.
Infrastructure vulnerability scan
Coming soonScans your internet-facing servers for known software vulnerabilities and misconfigurations — outdated services, missing patches (CVEs), weak configuration — with clear, prioritized fixes. Requires proven ownership.
Web app scan (DAST)
Coming soonActively tests your live web application the way an attacker would — injection, broken authentication, misconfiguration and more. Requires proven ownership.
Other types of scans
Coming soonWe're continuously adding new checks. Tell us what you need — and if you have a specific requirement, our experts can run it for you.
Not just scans — a platform
Manage what you monitor, work as a team, and prove it to management.
Assets & proven ownership
Keep an inventory of the domains, IP addresses and mailboxes you watch — imported and exported as CSV, with related addresses nested under the domain they belong to. For the deeper checks we ask you to prove an asset is yours, in whichever way suits it: a DNS TXT record, a file at /.well-known/, a code emailed to an address at the domain, a callback from the IP itself, or reverse DNS.
Groups & teams
Create organizations to group assets by client, project or brand, invite teammates with roles, and share assets, scans and reports. An owner can also let a member run scans on the owner's credits, for that organization's assets only. Included by default.
On demand, booked, or recurring
Run a check now, book it for a date and time in the time zone you pick, or repeat it daily, weekly or monthly — recurring runs are discounted, so continuous monitoring stays cheap. If a scheduled run can't be paid for, you're told; the schedule stays active.
Whole estate in one go
Select many assets and many checks at once and the wizard collects only what each one needs, skips the pairs that don't apply, and shows the total cost before you spend a credit.
Plain-language reports, with the evidence
Every scan gets an A+–F grade, a line saying which finding drove that grade, and "what you have / how bad it is / what to do" findings — each marked with how we know, whether we proved it or read it from a published record. Underneath sit the cipher tables, raw DNS answers and per-weakness verdicts for whoever wants them. PDF export for one scan, or one report covering every check on an asset.
What changed since last time
Each scan is compared with the previous one for the same asset and check, and you're told only when something actually moved — leading with what got worse and naming it, rather than sending you an identical notice every morning.
Mark a finding as not applicable
"We know that port is open, it's our VPN." Hide a finding on one asset with a reason on the record. It always expires, it never changes the grade, and it's hidden rather than deleted — so the report you hand a client is still the truth.
Your brand on the report
Consultants and agencies can put their own logo and colour on the PDFs, per workspace. Submissions are reviewed before they go live, and the contrast is adjusted so a report is always readable.
Alerts & notifications
Told before a TLS certificate expires — at 30, 7 and 1 day, and again if it lapses — when a scan finishes or fails, when something changed, and when a scheduled run was skipped because credits ran out. In the app and by email.
One view of your exposure
A dashboard that answers the questions worth asking: which assets are worst, how many open findings and how serious, how much of what you own has actually been checked, and whether your grades are getting better or worse over time.
Pay as you go
Buy credits, spend them on the scans you actually run. No seats, no subscription, no lock-in. A scan that fails is refunded, and so is one that found nothing to test. Recurring runs are discounted, and referrals earn credits for both sides.
No passwords, and your data is yours
Sign in with a one-time code sent to your email — there is no password to steal, reuse or reset. Reading everything the platform found is always free; only taking it out as a file needs a paid account. You can close your account yourself, from inside the app.
Organizations are your asset groups
An "organization" isn't only your company. Create as many as you need to organize assets the way you actually work — and share each with the right people.
- Group by client, project or brand. One space per client or environment, cleanly separated.
- Invite people with roles. Owner, admin, member or viewer — share assets, scans and reports; everyone sees the same picture.
- Let the owner pick up the bill. Credits are personal by default; an owner can let a member run scans on the owner's balance for that group's assets.
- Hand over a clear report. Give clients, management or auditors a plain-language PDF they can act on — with your own logo on it, if you want.
Roles, shared assets and scan history are included by default — no enterprise plan required.
Who it's for
If you have something on the internet, you have an attack surface to watch — and you shouldn't need a security background to watch it.
Freelancers & solo makers
Check your own sites and your clients' without hiring a pentester — and look more professional doing it.
Startups
Ship fast without leaving security behind. Continuous checks on a startup budget, no security hire needed.
SMEs & IT teams
Keep an eye on your domains, certificates and email without a dedicated security team — with reports for management.
Agencies & MSPs
Monitor every client from one place using separate groups, and hand each a clear, branded report they understand.
Enterprise & security teams
Add lightweight, continuous external monitoring alongside your stack. Proven ownership keeps the active checks safe.
Bug bounty & researchers
Fast recon on authorized targets — TLS, email and exposure at a glance, graded and exportable.
Simple, credit-based pricing
Start free, pay only for what you run. Organizations, asset groups and referral bonuses are included at every tier. Indicative — final packages are set in the app at launch.
Starter
to try
- Free starter credits
- Every check, at its normal credit cost
- Organizations & asset groups
- Referral bonuses
- On-screen reports & grades
Credit packs
top up anytime
- Buy credits, spend on any scan
- Discount on recurring scans
- PDF report exports
- White-label PDF reports
- Referral bonuses & voucher codes
- Pay by card — invoices available
Teams / Enterprise
for organizations
- Volume credits & discounts
- Pay by card or bank transfer, invoiced
- Consolidated billing across groups
- Priority support & SLA
- Onboarding & training
- Optional bundled expert pentest or review
No subscription and no seats: a credit is spent when a scan runs. Credits you buy don't expire; free ones — starter, referral and goodwill credits — last twelve months from the day they're granted, and are always spent first.
Questions
Can I use ClickScan yet?
Not yet. ClickScan is in final testing and everything described here is coming soon. Ask us for early access and we'll tell you the day it opens.
Who is this for?
Anyone with something exposed online: freelancers and agencies checking clients, startups and SMEs without a security team, enterprise teams wanting lightweight external monitoring, and bug-bounty researchers doing fast recon on authorized targets.
Do I need to be technical?
No. Reports are written in plain language — what you have, how serious it is, and exactly what to do. No CVSS jargon in the main view, and where a fix means publishing a DNS record we write the record out for you, already filled in with your domain.
What's an "organization"?
A flexible group of assets — not necessarily your company. Create one per client, project, brand or environment, invite the right people with roles, and share assets, scans and reports within it. It's included by default.
How do I sign in?
With a one-time code emailed to you. There are no passwords to remember or reset.
What does it cost?
Pay-as-you-go credits — no subscription and no per-seat fee. New accounts get free starter credits; recurring scans are discounted; PDF exports and higher volumes come with paid credits. Final packages are set in the app at launch.
Do my credits expire?
Credits you pay for don't expire. Free credits — starter, referral and goodwill grants — expire twelve months after they're granted, and are always spent before the ones you paid for.
Can I scan any website?
Passive checks (like TLS and email) run on public data. For active checks you confirm you're authorized to test the target; for certain checks — the deeper ones, such as open ports and vulnerability scanning — we also ask you to prove the asset is yours, using whichever suits it: a DNS TXT record, a file at /.well-known/, a code emailed to an address at the domain, a callback from the IP, or reverse DNS. Exactly which checks require proof is subject to change as we add them.
What happens if a scan fails, or finds nothing to test?
You get the credits back. A scan that fails is refunded automatically, and a check that couldn't test anything is graded "not applicable" and refunded rather than being passed off as a good result.
Be first in when it opens
ClickScan is coming soon. Tell us where to reach you and we'll let you know the day you can add your first asset.
Get early access