Platform overview

    Daily monitoring. Full control. Audit-ready.

    Security Monitor scans your domains every day, tracks your score, alerts you on change, and lets your team manage risks with a full audit trail — so compliance evidence is always one click away.

    ISO 27001Aligned
    SOC 2 Type IIControls
    GDPRCompliant
    AES-256Encryption
    170+
    Security checks per scan
    10
    Independent security layers
    Daily
    Automated monitoring
    100%
    Audit trail coverage
    Real-time
    Uptime & performance
    Complete coverage

    Every layer of your domain — monitored, scored, tracked.

    Security Monitor combines 10 independent security layers — email, DNS, TLS, headers, domain health, subdomains, breaches, reputation & blacklists, availability, and external services — into one daily-updated score and one normalized view your team and your auditors can both rely on.

    Email security: SPF, DKIM, DMARC, MX configuration
    DNS security: DNSSEC, CAA, NS consistency, wildcards
    TLS certificates: validity, expiration, issuer trust
    Security headers: HSTS, CSP, Permissions-Policy
    Domain health: HTTPS redirect, redirect chains
    Data breaches, reputation & blacklists (25+ sources), subdomains

    Why multiple sources? A single tool might mark your domain as "secure" while missing critical email misconfiguration or outdated TLS versions. We cross-reference everything.

    Command center//acme-corp.com
    72/100
    Posture
    82 critical
    Open issues
    5easy fixes
    Quick wins
    10all online
    Sources live
    Score trend · 30d +20
    Web
    82
    Email
    45
    DNS / TLS
    90
    Hygiene
    68
    Reputation
    95
    Top signals
    2 critical5 quick
    DMARC policy not enforced quick
    Critical
    TLS 1.0 still enabled
    Critical
    Missing Content-Security-Policy
    High
    HSTS max-age too short quick
    Medium
    SPF record valid
    Pass
    Security Copilot
    Beta

    Your AI security analyst, on tap

    A read-only AI assistant grounded in your live scan data. It explains findings in plain language, surfaces quick wins, and tells you exactly what changed between scans — citing every claim back to a real signal in your portal.

    Grounded in your scans
    Cites every finding (SIG-IDs)
    Explains the 'why', not just the 'what'
    Compares scans over time
    Read-only — never makes changes
    Continuous Monitoring & Full Visibility plans
    No signup requiredResults in under 60s170+ checks
    See plans
    Security Copilot//Beta
    What are the top 3 quick wins for acme-corp.com right now?
    Based on your latest scan (score 62 / 100, 3 critical signals), here are the highest-impact fixes:

    1. Enforce DMARC — currently p=none. Move to p=quarantine to block spoofed mail.
    2. Add Content-Security-Policy — protects against XSS on your login flow
    Ask anything about your security posture…
    Read-only· Cites findings· Beta
    AI roadmap
    Coming soon

    Shipping over the next quarters

    AI anomaly detection

    Soon

    Flag unusual changes between scans — and tell you whether they actually matter.

    AI email drafts

    Soon

    One-click remediation emails to IT or vendors, with finding context pre-filled.

    Conversational rescans

    Soon

    Ask the Copilot to re-check a category or finding — without leaving the chat.

    Data breach detection

    Know if your team's credentials leaked.

    Every scan checks all email addresses on your domain against Have I Been Pwned — the world's largest database of known data breaches. Get instant visibility into compromised accounts before attackers exploit them.

    • Checks all email addresses on your domain
    • Cross-references with 700+ known data breaches
    • Identifies which breaches contain your accounts
    • Actionable recommendations per breach
    • Included in every scan and PDF report

    Why breach detection matters: 80% of data breaches involve compromised credentials. If your team's email addresses appear in a breach, attackers can use credential stuffing to access your systems — even if your infrastructure is secure.

    Data Breach Alert

    3 email accounts found in known data breaches

    3
    Exposed accounts
    2
    Known breaches
    Powered by Have I Been Pwned · Checked on every scan
    Actionable signals

    Every finding comes with a fix.

    Raw scan data is useless. Security Monitor normalizes findings from all sources, removes duplicates, and prioritizes by actual risk. Every signal includes clear context and remediation steps your team can act on immediately.

    • Normalized severity across all sources
    • De-duplicated to eliminate false positives
    • Source attribution for every finding
    • Step-by-step remediation instructions
    • Risk-based prioritization
    Signal detail//SIG-2419
    Critical Quick winEmail security
    DMARC policy not enforced
    First seen Mar 24 · DNS + Email scan
    In progress
    What's wrong
    DMARC policy is set to p=none — receivers won't quarantine or reject spoofed mail from your domain.
    How to fix
    Update DNS TXT record to:v=DMARC1; p=quarantine; rua=mailto:dmarc@acme-corp.com
    Mark resolved
    Delegate
    Add note
    Accept risk
    Audit trail
    Status changed → In progress
    Mar 26 · 09:15 · Joeri V.
    Note added: 'Contacted DNS provider'
    Mar 25 · 16:42 · Joeri V.
    Signal detected — DMARC p=none
    Mar 24 · 14:32 · System
    Initial scan — 170+ checks run
    Mar 24 · 14:32 · System

    See how your domain scores

    Run a free scan right now — 170+ checks, results in under 60 seconds.

    No signup requiredResults in under 60s170+ checks
    Continuous monitoring

    Set it once. Stay compliant forever.

    Security is not a one-time event. Security Monitor rescans your domain daily, detects changes automatically, and alerts you instantly. Your audit trail builds itself — no manual work required.

    • Automated daily rescans across all sources
    • Instant email alerts when signals change
    • Full audit history with timestamps
    • Compliance-ready PDF and CSV exports
    • Score tracking and trend analysis
    Continuous monitoring//3 domains
    All healthy
    85/100
    Portfolio score
    3monitored
    Domains
    1hdeep scan
    Cadence
    10live
    Sources
    acme-corp.com
    Strong+5
    85
    app.acme-corp.com
    Needs work+12
    72
    shop.acme-corp.nl
    Strong+3
    91
    Score trend · 30d
    +40 pts
    Recent changes
    Resolved: DMARC enforced on acme-corp.comFIXED
    2h ago
    Score improved: app.acme-corp.com → 72 (+12)
    6h ago
    New signal: Missing CSP on shop.acme-corp.nlNEW
    1d ago
    Quick win available: HSTS on acme-corp.com
    1d ago
    10 layers · 70+ engines · live

    The intelligence stack behind every scan.

    Cross-referenced against VirusTotal, Shodan, Have I Been Pwned, Google Safe Browsing, crt.sh and 25+ blacklists. Every finding attributed to its source — full audit trail, no black boxes.

    L01

    Email Security

    SPF, DKIM, DMARC, MX configuration

    Native DNS inspection
    L02

    DNS Security

    DNSSEC, CAA, NS consistency, wildcard detection

    Google DNS API
    L03

    TLS & Certificates

    Certificate validity, expiration, issuer trust, CT log monitoring

    Direct connection + crt.sh
    L04

    Security Headers

    HSTS, CSP, X-Frame-Options, Permissions-Policy

    Direct HTTP inspection
    L05

    Domain Health

    HTTPS redirect, www consistency, redirect chains

    Direct HTTP inspection
    L06

    Attack Surface

    Subdomain discovery + open ports, CVEs, tech fingerprinting

    crt.sh CT logs + Shodan InternetDB
    L07

    Reputation & Threats

    70+ AV engines, 25+ blacklists, look-alike domain detection, public source-code leak monitoring

    VirusTotal, Google, Spamhaus, URLhaus + Firecrawl OSINT
    L08

    Data Breaches

    Domain emails in known breaches + public paste-site leak detection

    Have I Been Pwned + Firecrawl OSINT
    L09

    People & Phishing Exposure

    Team page parsing, WP user enum, exposed admin panels, public-document metadata leakage

    Site crawl + HIBP + Firecrawl OSINT
    L10

    External Services

    Third-party dependencies, CDN, SaaS, analytics detection

    DNS, CNAME & HTTP analysis

    Real-time · Under 60s · Source attribution on every finding

    Intelligence Network · Live
    /01
    VirusTotal
    VirusTotal
    70+ AV engines
    Verified
    /02
    Google Safe Browsing
    Google Safe Browsing
    Threat detection
    Verified
    /03
    Have I Been Pwned
    Have I Been Pwned
    Breach database
    Verified
    /04
    Shodan
    Shodan
    Port & CVE intel
    Verified
    /05
    crt.sh
    crt.sh
    Certificate Transparency
    Verified
    + DNSBL feedsSpamhausSpamhausURLhausURLhausBarracudaBarracudaSpamCopSURBL+20 more feeds · cross-referenced on every scan
    Domain intelligence

    Know your domain inside out.

    Every scan automatically detects your technology stack, infrastructure providers, and DNS configuration — giving you a complete picture of your domain's attack surface.

    • Auto-detect CDN, CMS, web server, and frameworks
    • IP address, MX provider, and DNS infrastructure
    • SPF, DKIM, and DMARC record visibility
    • Subdomain discovery with security analysis
    • Updated with every scan — zero configuration
    Domain intelligence
    CDNCloudflare
    Web serverNginx
    CMSWordPress
    MX providerGoogle Workspace
    IP address104.21.xxx.xxx
    Uptime & performance

    Track availability and speed.

    Monitor response times and uptime across all your domains. See performance trends, detect slowdowns, and get alerted when your domain goes down — all built into every scan.

    • Response time tracking with trend graphs
    • Uptime monitoring on every scan
    • Performance sparklines per domain
    • Alerts when response time degrades
    • Historical performance data for SLA reporting
    Uptime & performance
    Response time142ms
    7 days agoToday
    99.9%
    Uptime
    142ms
    Avg response
    ↓ 18%
    Faster
    AI Analysis

    AI-powered executive summaries

    Generate board-ready security reports in one click. Our AI analyzes all findings across categories and produces a clear, actionable narrative.

    • Written for executives & compliance teams
    • Covers all 10 security categories
    • Highlights critical risks with remediation priority
    • Regenerate anytime after rescans
    AI Executive SummaryPowered by AI

    acme-corp.com scores 72/100 with 3 critical findings requiring immediate attention.

    Email security is the weakest area — SPF and DMARC are misconfigured, leaving the domain vulnerable to spoofing attacks. Web headers are partially configured but missing CSP.

    Recommendation: Prioritize SPF/DMARC fixes and deploy Content-Security-Policy headers.

    GDPR Compliance

    See where your data flows

    Automatically map all third-party data processors, geolocate their servers, and assess GDPR adequacy — Art. 44-49 compliance at a glance.

    • Interactive world map with service pins
    • GDPR adequate vs non-adequate country flags
    • Connection lines from your domain to each service
    • Actionable findings for non-compliant transfers
    Data Flow Map2 non-adequate
    Netherlands
    Cloudflare, Stripe
    Germany
    Google Analytics
    United States
    AWS, Intercom
    Singapore
    DigitalOcean
    People & Dark-Web Exposure

    See who attackers will target — and whose passwords are already leaked

    Phishing and account takeovers don't start with your firewall — they start with your people. We map your team from open sources and cross-reference every email against known dark-web breaches, so you see the attack before it lands.

    • LinkedIn, X, Facebook & Instagram profiles tied to your domain
    • WHOIS / RDAP registrant, sister domains & contact emails
    • WordPress user enumeration (exposed admin logins)
    • Staff portals & remote-access subdomains (VPN, OWA, intranet)
    • Dark-web breach matches per employee, with source & date

    Why this matters: 80%+ of breaches start with stolen credentials or social engineering. Knowing which of your people are already exposed turns guesswork into a remediation plan.

    People & Dark-Web Exposure2 breached
    Sarah Janssen — CTO⚠ LinkedIn 2021 · Adobe
    LinkedIn
    admin@acme-corp.com⚠ Collection #1
    WP Enum
    t.bakker@acme-corp.com — IT Lead
    WHOIS
    vpn.acme-corp.com
    Staff Portal
    Cross-referenced against Have I Been Pwned · LinkedIn · WHOIS · WordPress API
    Visual Intelligence

    Your attack surface, visualized

    An interactive force-directed graph that maps every entity connected to your domain — services, subdomains, personnel — revealing relationships and risk clusters at a glance.

    • Interactive zoom and hover for details
    • Color-coded by entity type and risk
    • Shows connections between domains, services & people
    • Automatically generated from scan data
    Attack Surface Graph12 connected entities
    acme-corp.com
    Domain
    Services
    Subdomains
    Personnel

    Ready to take control?

    Start monitoring your domains today. No credit card required.

    No signup requiredResults in under 60s170+ checks
    Team collaboration

    Security is a team sport.

    Invite your team to collaborate on security findings. Assign signals, share reports, and track remediation progress together — with role-based access to keep things organized.

    • 5 team seats included in Business plan
    • Admin and Member role management
    • Shared access to all domains and reports
    • Collaborative signal workflow management
    • Invite team members by email

    Business plan feature: Team collaboration is available on the Business plan. Pro users can manage domains solo with all scanning and monitoring features.

    Team collaboration
    3 of 5 seats
    SJ
    Sarah Janssen
    Admin
    MB
    Mark van der Berg
    Member
    TB
    Thomas Bakker
    Member
    Invite team member

    Built as a system, not a tool.

    Every feature works together to keep you continuously in control.

    Instant scanning

    Enter a domain and get results in under 60 seconds. No signup required for your first scan.

    Signal normalization

    Findings from 10 security layers are merged, de-duplicated, and normalized into one severity scale.

    Control Score

    One number that shows your domain's security posture at a glance. Track it over time.

    Smart alerts

    Get notified only when something meaningful changes — not for every minor fluctuation.

    Audit trail

    Every scan, change, and resolution is timestamped. Export for ISO 27001, SOC 2, or NIS2.

    Tech stack detection

    Automatically identify CDN, CMS, web server, and infrastructure behind each domain.

    Performance tracking

    Track response times and uptime trends across all your domains with visual sparklines.

    Breach detection

    Check all domain email addresses against Have I Been Pwned's database of known data breaches.

    External services

    Automatically detect third-party services your domain depends on — email, CDN, analytics, payment, and more.

    Team collaboration

    Invite team members, assign signals, and manage remediation together with role-based access.

    Built for compliance-driven teams.

    Whether you're preparing for an audit or maintaining ongoing compliance, Security Monitor has you covered.

    ISO

    ISO 27001

    Continuous monitoring evidence and audit-ready exports for information security management.

    SOC

    SOC 2

    Automated security posture tracking with timestamped proof of continuous monitoring.

    NIS2

    NIS2

    Network and information security compliance with daily automated assessments.

    AVG

    AVG / GDPR

    Technical security measures documentation for data protection compliance.

    Security Badge

    Prove your security posture. Publicly.

    Embed a live security badge on your website that shows your real-time control score — verified by 10 independent security layers. Build trust with customers, partners, and auditors at a glance.

    • Live score updated after every scan
    • Three embeddable badge variants
    • Links to your public security report
    • One-click HTML snippet to copy
    Secured by
    Security Monitor
    87
    Shield · Pill · Detailed variants

    See what your current tools are missing.

    Run a free scan and discover signals that single-source tools overlook.

    No signup requiredResults in under 60s170+ checks

    No signup required · Results in under 60 seconds

    See it in 30 seconds

    From scan to score to resolution.

    Watch how Security Monitor turns a single domain into a continuous picture of your external attack surface.

    securitymonitor.io / scan
    Security Monitor — Continuous External Security in 30 Seconds. Demonstration of scanning acme-corp.com, surfacing findings, and tracking them to resolution.
    00:00 Scan·00:09 Findings·00:15 Score·00:21 Resolution