Checks browser-level protections that stop attacks like clickjacking and script injection.
SPF / DMARC / DNSSEC
Checks whether someone could send fake emails pretending to be from your company.
Insecure cookie flags
Checks whether login/session data could be intercepted by an attacker.
Exposed endpoints & debug leaks
Finds hard-coded API paths and console.log statements left in your page source that shouldn't be public.
Outdated JS libraries (CVE-matched)
Fingerprints the JavaScript your site actually serves against known vulnerabilities — a real CVE tied to a real script, not a generic "update your stuff" warning.
Exposed source maps
Checks whether your unminified source code and internal file paths are sitting publicly reachable next to your production JavaScript.
Known-vulnerable server software
Cross-checks the server software your site reveals against a list of versions with publicly known security holes.
SEO & performance
Title, meta tags, headings, sitemap.xml, response time, and compression — the basics that quietly affect visibility and speed.
Free if this domain is included in your Starter, Pro, or Business plan
Cross-Site Scripting (XSS)
Tests if an attacker could inject malicious code that runs in your visitors' browsers.
SQL Injection
Tests if an attacker could manipulate your database through a form or search box.
Full site crawl, OWASP Top 10 coverage
Tests every page and form it can find — not just your homepage.
Ranked, exploitable findings
Each issue is ranked by real-world risk, with remediation steps included.
Broken access control checks
Tests whether restricted pages or admin areas can be reached without proper permissions.
CORS misconfiguration
Tests whether your site reflects any website's origin back with credentials allowed — the kind of bug that lets another site quietly read your logged-in visitors' data.
Risky HTTP methods (TRACE/PUT/DELETE)
Checks whether your server accepts write or trace requests it shouldn't — usually left on by accident, not by design.
Path traversal & local file inclusion
Tests if an attacker could read files outside the intended directory by manipulating a file path parameter.
Command injection & RCE patterns
Tests if user input reaches a system command, which could let an attacker run arbitrary code on your server.
Server-side request forgery (SSRF)
Tests if your server can be tricked into making requests to internal systems it shouldn't be able to reach.
Passive subdomain discovery
Finds forgotten dev/staging subdomains via certificate transparency logs and DNS records — the ones nobody remembers still exist, which often run outdated software nobody's patching.
Known-CVE & misconfiguration scan
Checks your site against a community-maintained database of thousands of known vulnerabilities and misconfigurations, so a public CVE affecting your stack gets flagged before an attacker's automated scanner finds it.
Found something you'd rather not fix yourself? Our team resolves it for you — remotely and safely, usually within 72 hours. You approve first; nothing on your server changes without your say-so. One-off, no subscription.
Remote, within 72 hours
We connect the way you approve — through your Solvbeat Agent if it's installed, or a one-time secure session — and resolve it, often the same day.
You approve before any change
We tell you exactly what we'll change and wait for your go-ahead. Every change is reversible.
Fixed, or your money back
If we can't safely fix it remotely, you pay nothing — no questions asked.
One-off, no subscription
Pay per fix. No plan required — Pro & Business customers get priority.
Not sure it's fixable remotely? Ask us first — real people answer.
INCLUDED WITH YOUR ACCOUNT · GITHUB SECRET SCANNER
Free, any Solvbeat account
Paste a public GitHub repo URL from your dashboard and Solvbeat clones and scans it for leaked API keys, tokens, and credentials left in the code or its history — nothing is kept on disk after the scan. No card required, no separate plan.
Cloud provider keys
AWS, GCP, and Azure access keys committed by mistake, including old ones still sitting in git history.
API keys & tokens
Stripe, GitHub, Slack, and other service tokens hardcoded instead of pulled from environment variables.
Private keys & certificates
SSH private keys and TLS certificates that should never have left a local machine.
Database & service credentials
Connection strings and passwords baked into config files instead of secrets management.
On the free plan? Get it on its own for £38/mo per server — no need to subscribe to external scanning first. Install it on a server from your dashboard. Runs continuously, read-only, source published. Already included in Pro & Business — this standalone price is only if you want it on the free plan. How it works →
Pending security patches
Flags OS and package updates that haven't been installed yet.
SSH / RDP hardening
Checks for weak remote-access settings like password-only login or missing Network Level Authentication.
Local firewall & antivirus status
Confirms the server's own firewall and (on Windows) Defender are actually turned on.
File permissions & local accounts
Flags world-writable system files, the Guest account being enabled, and other local misconfigurations a remote scan can't see.
Encoded PowerShell & LOLBAS abuse NEW
Hunts the last 24h of the server's own event log for obfuscated commands and abuse of tools like mshta, wevtutil, or certutil.
Pass-the-Hash, RID hijacking & brute force NEW
Detects stolen-credential lateral movement, hidden admin accounts, login brute-force bursts, and new scheduled tasks — each finding mapped to its MITRE ATT&CK technique with a response playbook.
Real-time process monitoring NEW
Watches every process the instant it starts — catching a malicious binary or script the moment it executes, even one that runs for a few seconds and disappears before a scheduled scan would ever see it. Flags execution from temp directories, reverse shells, and download-and-run patterns as they happen.
Live log-based threat detection NEW
Your server's own security logs are streamed through a detection engine running thousands of continuously-maintained rules — intrusion attempts, privilege escalation, credential attacks, log tampering — in real time, each alert mapped to its MITRE ATT&CK technique. The engine runs entirely inside Solvbeat; your server only sends outbound, never opens a port.
BUILT ON THE AGENT · SOLVBEAT SHIELD SOC
£78 /mo
Needs the Solvbeat Agent to work — groups its alerts into incidents, draws an investigation graph connecting hosts/IPs/accounts, tracks trends, and maps real MITRE ATT&CK coverage. Flat price, no per-GB ingestion charges. An add-on to any plan — not the same thing as the Pro subscription, even though the price matches. How it works →
Incidents, not a flat alert list
Alerts sharing a server, IP, or account get grouped into one incident automatically.
Investigation graph
Click any host, IP, or account to see how it connects to everything else — no separate tool needed.
Alert trends over time
See whether things are getting better or worse, not just today's snapshot.
Real MITRE ATT&CK coverage
Cross-referenced against what's actually been detected in your environment — not a theoretical chart.
Full case management NEW
Every incident carries a status (open → investigating → resolved), an assigned owner, a resolution, and a complete timeline of who did what and when — a real investigation workflow with an audit trail, not just a wall of alerts.
Threat-intelligence enrichment NEW
Every IP and domain in your alerts is cross-checked in real time against continuously-updated feeds of known-malicious infrastructure — so a connection to a known botnet command-and-control server or phishing host is flagged the moment it appears.
SUBSCRIPTIONS
Prefer ongoing monitoring?
Starter
£38/mo
1 verified domain
Full Advanced Scan & Exposure Scan reports (unlocked, unblurred)
We set up and run Microsoft Sentinel and Microsoft Defender for your business: real-time detection, correlated alerts, and a certified team watching for what matters, not just noise.
We hold Cyber Essentials and ISO 27001 ourselves — we know exactly where businesses get stuck. We'll walk your team through the self-assessment, fix the gaps our scanner already found, and get you certified.
Most breaches start with a person, not a firewall gap. We train your team to spot phishing, handle passwords properly, and know what to do when something looks off — no boring slideshow required.