Skip to main content

For digital agencies, web studios & freelancers

One workspace, every client site, worst-first.

One Vantyris workspace covers ten client domains or fifty. The portfolio dashboard ranks them by Critical and High findings, a bulk re-scan runs the lot in one click, and a time-limited share link gives each client a read-only view of their own report. A read-only API feeds your own dashboard. Credit packs start at $10€10£10A$15¥1,500AED 40, with no annual contract to defend at finance.

67Security score,
grade C
2Fixes for
today

Each panel mirrors a screen in your workspace, shown with our demo clinic. After your first scan, it's your sites and your findings.

The reality

What agency leads worry about

You've inherited a dozen client sites over the years and can't say what's exposed on any of them.

A retainer client got a phishing email impersonating 'the web design agency' and asked what you're going to do about it.

You quote for a security audit and the client wants something to show their insurer, not a PDF that lives on your hard drive.

Enterprise scanner pricing made you laugh, then made you sad.

One of your old client WordPress sites turned up on a Spamhaus list, and it took two hours to work out which of forty domains it was.

What a typical agency scan surfaces

One finding, shown in plain English.

Every finding in your Vantyris report is shaped the same way: what it means for your business, how to fix it, who to ask, and the technical evidence one tap below.

high

WordPress REST API exposes user slugs on a legacy client site

A client site you handed off four years ago still runs WordPress, and /wp-json/wp/v2/users returns the public slug of every author account. With /wp-login.php reachable and no visible CAPTCHA, that hands credential-stuffing bots a clean list of usernames to try.

How to fix it

Add the rest_endpoints filter (the full PHP snippet is in the report's Exact Fix section) to the client theme's functions.php or to a small must-use plugin. About 30 minutes, including the check. Mark it fixed in Vantyris and the next monthly re-scan records the closure as a dated row for the client's retainer file.

What Vantyris gives agencies

What changes after the first scan.

Every client in one workspace, worst first

The portfolio dashboard ranks targets by Critical and High count and shows the workspace's average score. One click re-scans everything you have credits for, and a CSV export covers the monthly review. Each report has a nine-category grid, so you can see whether the portfolio's weak spot is TLS, email security, supply chain or WordPress hardening.

A Fix Roadmap per client, grouped by owner

Each client report sorts findings into Today, This Week, Later and Acknowledged, then groups every bucket by owner (web host, developer, DNS admin, email provider). Forward each contractor their slice. They open the work-order PDF and see one list. The compliance PDF goes to the client's insurer or auditor as the dated record.

An executive summary the client can read

Each report opens with a one-page summary for non-technical readers: the headline grade, the three biggest wins, the projected score after fixes and a plain-English table of business impact. Page two goes to the marketing director. Page seven onward goes to the IT contractor.

An API that fits in two lines of curl

Create a read-only workspace key and drop it into your monitoring dashboard or CI pipeline. GET /api/v1/targets and GET /api/v1/findings take severity and category filters, with bearer-token auth. There are no webhooks to wire up, just polled GETs. Post to Slack when a new High lands, or open a Jira ticket from CI.

Monitoring that only pings you when it matters

Enrol every retainer site in weekly re-scans. Vantyris emails you when a new High lands, when the score drops ten points, or when a TLS certificate is close to expiry. Acknowledged items never trigger an alert, so a ping means a client needs your call.

Credits, not a seat licence

The 100-scan pack covers a hundred client scans with no seat licence and no renewal call. Credits belong to the workspace, not to a target, so they follow the client mix. Top up when you run low.

Long read

12-minute read

The 30-minute monthly playbook for an agency's client portfolio security.

A plain-English playbook for agencies from the Vantyris editorial team. It takes positions, which a generic checklist won't.

Read the full playbook

FAQ for agencies

Common questions from agency owners

How do I get authorisation to scan a client's domain?
Each target requires the client to set up verification: DNS TXT, a file on the server, or an HTML meta tag. The client puts the token in place, which is the documented authorisation computer-misuse laws expect, such as the US Computer Fraud and Abuse Act and the UK Computer Misuse Act. Email us for a template authorisation letter if you want a paper trail in the retainer file before the client configures verification.
Can I give clients a permanent URL to check posture themselves?
Each workspace has one public trust page, and it covers every domain in the workspace. For a view of one client's site, send a share link for their latest scan: read-only, watermarked if you like, and valid for up to 90 days. You can see how many times it was opened.
Do credits roll over between clients?
Credits belong to the workspace, not to individual targets, so any pattern works: 5 scans of one client this month, 20 of another next month. Credits last 60 days from purchase.
Can my SOC dashboard pull findings programmatically?
Yes. Version 1 has GET /api/v1/targets and GET /api/v1/findings, filterable by severity, category, status and owner, with bearer-token auth on a workspace key. The API-keys settings page shows a two-line curl example.
What about findings on client sites we don't host?
Vantyris doesn't care where a site is hosted. It scans anything on the public internet and names each fix in terms the host's support team will recognise: the Cloudflare panel path, the Nginx directive, the Apache .htaccess block or the GoDaddy DNS field, whichever the finding needs.
How do I tell which client sites need attention this morning?
Open the portfolio dashboard. It sorts worst first by Critical and High count, then by score drop since the last scan. Acknowledged items get their own column, so the 'needs action' count stays honest. The CSV export for the monthly review is one click.
Full FAQ

Ready when you are.

Free account, free passive teaser, no card. A verified scan from $10€10£10A$15¥1,500AED 40. No contracts.