FAQ
Frequently asked questions
The straight answers. If yours isn't here, email help@vantyris.com and we'll add it.
Product
Yes. Every finding is written in plain English: what's wrong, what it means for your business and how to fix it. Each one also names who does the fix (your web host, your developer, your DNS administrator) and roughly how long it takes. The technical detail sits one click away for your developer, and you don't need to read any of it to act on the report. If a finding doesn't make sense within a minute, that's our editorial bug, not yours. Email help@vantyris.com and we'll rewrite it.
Vantyris checks your business website the way an attacker would, then tells you in plain English what's wrong and how to fix it. You point it at a website or domain you own and get a report you can hand to whoever maintains your site. It isn't a penetration test or a compliance certificate. It's the security health check most small businesses don't have the time, or the security person, to do themselves.
Nine questions, one per category. Is your padlock real (TLS and HTTPS)? Is your visitor's browser being told how to protect them (web hygiene headers)? Can someone hijack your domain name (domain and DNS)? Can a stranger send email pretending to be you (email security)? Is anything reachable on your server that shouldn't be (exposure)? What does your stack give away about itself (technology)? Is your domain on anyone's blocklist (reputation)? Could a third-party script turn on your visitors (supply chain)? And do your trackers and cookie banner meet the baseline regulators expect (privacy)?
At two speeds. The free teaser reads only what anyone on the internet can already see, needs no ownership check, and gives a partial answer in seconds. Treat it as a sample. The verified scan (1 credit) runs after you prove the site is yours with a one-time DNS record, file upload or HTML meta tag, and adds the checks that need your authorisation under computer-misuse law. Its first answer arrives within about 90 seconds.
No. A pentest is a creative human attacker looking for paths into one specific system. Vantyris is automated hygiene scanning, and it checks the same broad set of things on every target. If a regulator or a client requires a pentest, book one. Vantyris is what you run before and between pentests.
Vantyris is not a Cyber Essentials certifying body. Every verified report has a Cyber Essentials section (the UK government's baseline security scheme, a sound checklist in any country) that maps each finding to its five control areas (firewalls, secure configuration, security update management, user access control, malware protection). It shows which controls an external scan can speak to and which need internal evidence, such as endpoint posture and policy. That section makes a good starting checklist for a CE submission.
A teaser reads only what's already public about your site: the TLS connection and the browser-protection headers. It's a sample of the report, with no ownership check, and it gives a partial answer in seconds. A verified scan runs every module across all nine categories and adds the workspace around the report: the triage workflow, a score trend over time, attack surface discovery through Certificate Transparency, continuous monitoring, share links and the PDF in three layouts. The verified scan costs one credit. The teaser is free.
Nine: TLS & HTTPS, web hygiene, domain & DNS, email security, exposure, technology, reputation, supply chain and privacy. Each category gets its own score and grade on the report, with a count of findings by severity. The report also says which categories it assessed.
Every finding from your verified scan that needs work goes into one of four buckets. Today holds the 5-10 minute and 30-minute fixes you can do in your hosting panel. This week holds the 1-2 hour and developer-day fixes that need coordination. Later holds fixes tied to a lifecycle event, like waiting for a certificate renewal. Acknowledged holds findings that need a check rather than a fix. Inside each bucket, findings are grouped by owner (web host, developer, DNS admin, domain registrar, email provider, site owner), so each person can pick up their own list. Severity always wins: Critical and High findings go in Today, however long they take.
Two things. First, Google Safe Browsing v4: we check your homepage URL against Google's lists of malware, phishing and unwanted-software sites. Second, the DNS-based blocklists (RBLs): we query Spamhaus ZEN and DBL, the Barracuda Reputation Block List, SpamCop, SURBL and URIBL for your resolved IP and apex domain. It matters because an old subdomain that was compromised once can sit on a blocklist for months, quietly sending your email to spam, even when your site is clean today.
It answers the first question in the NCSC's attack surface guidance: what does the internet see when it looks at this domain? The section lists your IPv4 and IPv6 addresses, your nameservers and who runs them (Cloudflare, AWS Route 53 and so on), the MX hosts that receive your email, DNSSEC state, CAA issuers, the registrar and whether the domain is locked, domain age, and subdomains found in Certificate Transparency logs. It's built from the structured data the scanner saves, not scraped out of evidence text.
Yes, that's the Privacy category. We detect trackers that load before consent, whether there's a cookie banner at all, whether there's a link to a privacy notice, and the IAB TCF consent signal. We don't give a GDPR or ePrivacy compliance verdict. We show the surface a regulator or a sharp-eyed visitor notices first. A full data-protection audit is a different kind of project. Vantyris tells you whether the obvious red flags are visible from outside.
Billing
You buy a pack of credits. One credit is one verified scan of one target. Packs start at $10 for 5 scans, or €10 in the EEA, £10 in the UK, A$15 in Australia, ¥1,500 in Japan or AED 40 in the UAE, and credits last 60 days. There's no subscription. Buy when you need to and scan when you want.
The one for where you are: US dollars in most of the world, euros in the European Economic Area, pounds in the UK, Australian dollars in Australia, yen in Japan and dirhams in the UAE. We work it out from the country of your internet connection, and checkout uses the same answer. Each currency has its own fixed price list, so prices do not move with exchange rates, and there is no conversion fee from us.
No. Nothing on Vantyris is a subscription. You buy credit packs when you need them, every feature works on credits, and nothing renews.
Unused credits are refundable within 14 days of purchase. Email refunds@vantyris.com or use the contact form. Refunds are processed within 5–10 business days. Used credits aren't refundable. The full refund policy is at /legal/refunds.
Delivery
The report appears in your Vantyris workspace within seconds of the scan finishing, and you get an email confirmation too. The downloadable PDF shows the same content as the workspace, so the developer or accountant you forward it to sees exactly what you see.
A teaser scan returns a partial grade in seconds. A verified scan returns its first report quickly, and most are complete in under 90 seconds. Deeper checks then fill in the rest in the background. You'll see the first answer the moment it lands.
Two formats with the same content. A web view in your Vantyris workspace, where you can filter by severity and click into the evidence, and a PDF in the paper-cream layout, ready to forward to your web host, accountant or insurer.
Data & Security
Your account and scan data live in our database on a Hostinger server in the Netherlands. Every connection to Vantyris is encrypted with TLS, and HSTS keeps browsers on HTTPS. Passwords are stored as bcrypt hashes, never in plain text. Server keys never reach the browser. And we run the same checks against vantyris.com that we run against your site. See /methodology for the full account.
Read it at /legal/privacy. The short version: we collect only what's needed to run the product (contact details, billing and scan history), we operate under UK-GDPR and EU-GDPR, we keep scan PDFs for 12 months and raw scan output for 30–90 days, and you can ask for an export or deletion at any time.
Only with the processors we need to run the product. Hostinger hosts the service and Stripe handles card payments. Our email-sending provider delivers transactional email, and Google Analytics runs only if you accept it on the cookie banner. We never sell or rent your data. The list of processors and what each one sees is in /legal/privacy.
Only with your explicit consent. On your first visit, a banner asks whether you accept Google Analytics. If you click 'Reject' or close the banner without choosing, gtag.js is never loaded and no analytics cookies are set. If you click 'Accept', we load GA4 configured with IP anonymisation enabled, Google Signals disabled, and ad personalisation disabled. You can change your mind any time via the 'Cookies' link in the footer.
In our database on a Hostinger server in the Netherlands, inside the EU. Personal data doesn't leave the UK or EEA except where transactional email needs it, and our email provider works under Standard Contractual Clauses for that.
PDF reports: 12 months from generation. Raw scanner artefacts (intermediate output): 30–90 days. Account data: as long as your account is active, plus 90 days after deletion for account revival. Audit logs: 12 months. Billing records: the minimum period required by UK tax law (currently six years).
Yes. Settings → Your data → Export. We send you a JSON copy of your account, your targets, your scans, your findings, your workflow history, your share links, your monitoring enrollments. GDPR Article 20 right to data portability.
Settings → Your data → Delete account. Account data is removed from the live system within 24 hours, from backups within 90 days. GDPR Article 17 right to erasure. Anything we are required by UK tax law to retain (billing records) stays for six years from the last transaction.
Legality & Safety
Yes. Vantyris only runs scans against targets where you've proven ownership, through DNS, a file you place on your site, or a meta tag. That verification step is the legal foundation of the service. Until you verify, only the harmless passive teaser is available.
Yes, but only with written authorisation from the client. Our Acceptable Use Policy (/legal/acceptable-use) requires you to certify you have permission. If you're an agency, we recommend keeping a signed authorisation letter from each client on file.
The verification gate is built to stop that. Active checks only run against verified targets. The teaser is the only scan that runs without verification, and it's passive on purpose: it doesn't interact with the target system.
It might. The verified scan requests about 70 known sensitive paths, such as .env and backup files, and some WAFs flag that pattern even at low volume. Every request carries the User-Agent Vantyris-Scanner/1.0 (+https://vantyris.com/methodology), so you can recognise the traffic or allowlist it. The teaser is a single page load and is unlikely to trip anything.
Yes. Vantyris scans what's exposed on the public internet, never inside a network. The data we collect is technical scan output (TLS, headers, DNS, email authentication) plus your account information. No personal data about your visitors passes through us. We work under UK-GDPR and EU-GDPR, and our processor list is on /legal/privacy.
Workflow & Sharing
On any finding card, click the status pill, choose 'Assigned', and enter your contractor's email and, if you like, a due date. Vantyris records the assignment in the audit history, which is only ever added to. You can also post comments on the finding, so the conversation stays in one place instead of in email threads.
You write a reason, which is required. The finding stays visible in the report, flagged as accepted. Every status change adds a row to the audit history with who made it, when, and the reason. That's what an auditor reads when they ask 'when did you decide this was acceptable, and why?'
Yes. Enrol any verified target in continuous monitoring from its page, at a daily, weekly, biweekly or monthly cadence. Vantyris re-runs the scan on that schedule and emails you about three things only: a new high or critical finding, a security score drop of ten points or more against the previous scan, or a TLS certificate within fourteen days of expiry. Alerts go to the workspace owner by default. You can send them somewhere else per target, to your web host for example.
Two ways. A time-limited share link with an optional watermark, in full, executive or evidence-redacted mode, which lasts from 1 to 90 days and can be revoked any time. Or a public trust page at a slug you choose, where you pick which sections show (current grade, last scan date, the checklist of controls in place). The trust page is off until you switch it on. An insurer who wants evidence of an external scan in the last 12 months can read it there, so you don't have to forward a PDF.
It's an optional text overlay rendered as a band at the top and bottom of the shared report. Use it for confidentiality ('Confidential: for J. Smith, ACME Insurance') or to make screenshots traceable. View count is visible to you so you can see whether the recipient actually opened the link.
No. The trust page shows your current grade (A+ to F), the date of the last scan, and the controls Vantyris has verified as healthy, such as 'HSTS in place', 'DMARC enforcing' or 'CAA records pin certificate issuance'. It doesn't list open findings. The point is to show a third party that you scan regularly and what's known to be good, not to publish what's broken.
Yes. Go to Settings → Trust page and untick 'Make this trust page publicly visible'. The page stops serving straight away, and your settings are kept, so you can switch it back on whenever you're ready. The slug stays reserved either way.
Yes. Each monitoring scan costs one credit, charged when it starts. If your balance is too low, that scheduled scan is skipped. Top up and the next scheduled scan runs as normal.
Reports & integrations
Yes, in three. Every verified scan downloads as the full editorial report for your files (it opens with a one-page executive summary for a board pack), a single-issue work order to forward to whoever does the fix, or a compliance report for an auditor or insurer. Same data, one click each. All three carry the audit-trail footer with the scan ID and methodology version.
Yes, two ways. Per scan: every finding on that scan with its rule_id, severity, business impact, fix, owner, time to fix, workflow status, confidence, KEV listing, CVE IDs and priority score. Workspace-wide: every finding across every scan, as either the latest scan per target or the full history. Files follow RFC 4180 with a UTF-8 BOM, so they open cleanly in Excel.
Yes. Create a workspace API key under Settings → API keys. There are two endpoints today: GET /api/v1/targets lists targets, and GET /api/v1/findings lists findings, which you can filter by severity, by target or by workflow status. Bearer-token auth, JSON responses, paginated. Full docs and curl examples are on the API-keys settings page. Each workspace can have up to ten active keys.
Yes. /app/portfolio ranks every target worst first (by critical and high count, then by average score) and shows workspace totals: target count, average score, and the number of criticals, highs and mediums. A 'Scan all' button starts a verified scan for every verified target your credits can pay for. Two CSV exports cover the workspace, either the latest scan per target or the full scan history.
Severity is the standard ordering (critical → high → medium → low). Priority is a composite score from 0 to 100 blending the severity, whether the underlying CVE (if any) is in the CISA Known Exploited Vulnerabilities catalogue (+15 if listed), and the history state (regressed +10, recurring +5). A finding that was new last month and got worse this month sorts above a finding of the same severity that just appeared. Toggle from the findings list toolbar.
Get a first check in seconds.
Free account, free passive teaser, no card. A verified scan from $10€10£10A$15¥1,500AED 40. No contracts.