- What does Vantyris check on my website?
- Nine axes of cyber hygiene: TLS / HTTPS, web hygiene headers, DNS and domain plumbing, email authentication (SPF / DKIM / DMARC / MTA-STS / BIMI), exposure (sensitive files, WordPress hardening, subdomain enumeration), technology fingerprint, reputation lists, supply chain (third-party scripts + SRI), and privacy posture (consent, trackers, EDPB reject-parity, Consent Mode v2). Each axis is scored independently with its own grade.
- Is a Vantyris scan legal? Can I scan my own website?
- Yes. You can scan domains you own or have written authorisation to scan. Every Vantyris scan requires verified ownership (a DNS TXT record, a file on the server, or an HTML meta tag) before any active probe runs. The gate is there because computer-misuse laws in most countries, such as the US Computer Fraud and Abuse Act and the UK Computer Misuse Act, treat unauthorised scanning as an offence.
- How much does it cost?
- The starter pack of 5 verified scans is $10, or €10 in the EEA, £10 in the UK, A$15 in Australia, ¥1,500 in Japan or AED 40 in the UAE, and credits last 60 days. There's no subscription and no annual contract. Create a free account, add a domain, and run the free passive teaser as often as you like for a partial grade in seconds.
- What does the report actually contain?
- A cover page, a one-page executive summary for non-technical readers, the top urgent actions, a score for each of the nine categories, and an attack surface map with a severity and an exact fix for every exposed file. Then the Fix Roadmap (Today, This Week, Later, Acknowledged), every finding with a one-line business impact and a fix to paste, and an appendix on methodology and the audit trail. It comes as three PDFs: the full report, a single-issue work order and a compliance pack.
- Why is HSTS not flagged as a High urgent item in your report?
- HSTS controls how long browsers remember to stay on HTTPS for your site. Provided HTTPS is working, there's no mixed content, and the certificate is valid, a short HSTS max-age is a hardening gap, not an emergency on its own. We treat a very short HSTS (under one day) as Medium severity, anything else as Low. It's scored under TLS rather than Web Hygiene so the grades agree with each other.
- Will a Vantyris scan slow my website down?
- No. The teaser is a single page-load. The verified scan reads what's already publicly visible about your domain (DNS records, response headers, CT-log entries) and checks a short list of common sensitive paths, with time-limited, spaced-out requests. We don't fuzz, brute-force or run exploit frameworks.
- How is Vantyris different from SSL Labs or Security Headers?
- Those are excellent free single-purpose tools. They answer one question well. Vantyris answers nine in one report, plus adds an attack-surface map, a Fix Roadmap grouped by who does the work, a one-page executive summary, Cyber Essentials A1-A5 alignment, CISA KEV priority scoring, share links, a public trust page, a portfolio dashboard, continuous monitoring, and a workspace API. Free tools answer 'is my config right?'. Vantyris answers 'how do I run a security baseline as a business owner, and how do I prove it?'
- What's the Acknowledged bucket?
- A bucket in the Fix Roadmap for findings that need a check rather than a fix. Example: your resolved IP is on a shared Cloudflare edge that Spamhaus has listed. The listing is real, but it's shared-tenancy noise from another tenant on that IP, not something you can or should fix. Acknowledged sits below Today / This Week / Later so it doesn't make the report feel like an emergency over informational items.