No credit card
No demo call and no invoice to begin. You see a real scan before anyone asks you to pay.
How it works
Most teams do not shop for GRC. They get asked to prove they are secure, and need an answer this week.
Step 1
Sign up with email and a password, name your organization, and you can add a domain right away. A customer questionnaire or a cyber-insurance renewal is the usual reason teams start this week.
No demo call and no invoice to begin. You see a real scan before anyone asks you to pay.
Subdomains stay free and uncounted, enough to answer the first questionnaire.
The first scan starts as soon as you add a domain.
Invite the team later. The owner role cannot be removed or demoted.
Step 2
Enter the hostname only: example.com, not a full URL. The scan starts immediately.
SPF and DMARC checks cover the email rows most questionnaires ask first.
HTTPS, HSTS, CSP, and related header grades show up on the same scan.
Risky services, SSH banners, and WHOIS or certificate expiry become findings.
Found hosts nest under the parent domain and are scanned automatically.
Step 3
The dashboard score is a severity-weighted average of Production domains, not a count of how many you added.
Staging, UAT, and Development issues do not pull the score down.
Critical and high findings move the number more than noise.
Each finding says what is wrong and how to fix it.
Search, filter, and sort findings across every domain in the organization.
Step 4
Work the list until the gaps that block the questionnaire or renewal are closed.
Open, acknowledge, or resolve each finding as you work it.
Bundle related findings so a teammate can finish one job, not twenty tickets.
Give a finding or project to the person who can actually change DNS or TLS.
Set a date and get notified before an item slips.
Step 5
Hand the customer, insurer, or client a report, not a screenshot of your dashboard.
Download the findings when a form wants an attachment.
Send a public report URL. The recipient does not need a login.
Turn the link off when the review is done.
Use it on a questionnaire, an insurance application, or a client QBR.
Step 6
Scanning stays useful on its own. Add-ons sit on Pro, are invoiced, and turn on only when the form asks for more.
Controls, policies, and a risk register across up to 12 frameworks.
A third-party inventory with criticality, reviews, and overdue dates.
Assign “Spot It. Stop It. Report It.” and track who passed.
A staff member enables the module after you are quoted. No in-app checkout.
Who it's for