The teaser scan
Create a free account, add a domain to your workspace and run a teaser. Vantyris reads what's publicly visible (the TLS handshake, security headers, MX records, basic DNS) and returns a partial grade in seconds. The teaser needs no card and no proof of ownership.
The teaser is passive on purpose. It doesn't knock on doors, attempt logins or send anything the target would notice as a probe. We never run an active module against a domain nobody has verified.
Verify ownership
Before any verified scan runs, you prove the domain is yours. Pick one of three methods:
- DNS TXT. Add a TXT record with Host _vantyris and the token we give you in the Value field. Your DNS panel adds your domain on the end, the same way it does for your _dmarc record. About five minutes if your registrar's panel is any good.
- File. Put a small text file containing the token at /.well-known/vantyris-verification.txt. Good if you don't have DNS access.
- Meta tag. Add a <meta name="vantyris-site-verification" content="…"> tag to your homepage <head>. Easiest if you control the site code, or your CMS has a “site header code” field.
Each token works once and then expires. It covers that one target only. Verification is the legal and operational core of the service. Vantyris will not run a verified scan without it.
The verified scan
One credit. The scan scores your site in nine categories:
- TLS & HTTPS: how private the connection between your visitor and your site really is.
- Web hygiene: whether your site sends the response headers that tell the browser to protect your visitor.
- Domain & DNS: whether the basic DNS controls (CAA, DNSSEC, registrar lock) are set up.
- Email security: whether your domain blocks email impersonation (SPF, DKIM, DMARC, MTA-STS).
- Exposure: whether services or files that should be private are reachable from the public internet.
- Technology: what your stack advertises to the world (versions, CMS, frameworks).
- Reputation: whether Google Safe Browsing, Spamhaus, SURBL or another major list has flagged your domain.
- Supply chain: whether the third-party scripts on your site could compromise your visitors.
- Privacy: whether your trackers and consent banner meet the baseline GDPR and ePrivacy rules expect.
The first answer appears in your workspace within about 90 seconds. Each finding comes with a plain-English explanation, a concrete fix, an owner (web host, developer, DNS admin, domain registrar, email provider or site owner) and an effort estimate: 5-10 minutes, about 30 minutes, 1-2 hours, a developer day, or at next renewal.
You see live progress in the report view. If a third-party service is rate-limiting us, we mark that module as deferred instead of pretending the scan finished. All nine categories run on every verified scan.
The report
Every finding has the same shape: what it means for your business in plain English, how to fix it (with who should do it and roughly how long it takes), and the technical evidence one tap below. The report also maps each finding to the five NCSC Cyber Essentials control areas, links each check to the IETF RFC or NCSC guidance behind it, and ends with an audit-trail footer carrying the scan ID and methodology version.
You can filter findings by workflow status (open, fixed, accepted, ignored, assigned). You can sort by priority instead of severity: a score that blends severity, whether the CVE is on CISA's Known Exploited list, and what changed since the previous scan. Or group by category to work through one area of your stack at a time. CSV export is one click.
Above the findings list sits the Fix Roadmap. Every finding that needs work goes into Today, This Week or Later, grouped by owner inside each bucket. The DNS admin gets one list, the developer gets another, and you get the short “fix it in your hosting panel today” list. Severity always wins: anything Critical or High goes in Today, however long it takes. Findings that need a check rather than a fix go in a fourth bucket, Acknowledged.
Above the Fix Roadmap, the Attack Surface map answers the first question in the NCSC's external attack surface guidance: what does the internet see when it looks at this domain? It lists your IPv4 and IPv6 addresses, your nameservers and who runs them, MX hosts, DNSSEC state, CAA issuers, the registrar and whether the domain is locked, domain age, and subdomains found through Certificate Transparency.
The same data produces three PDF layouts. The full report for your files opens with a one-page executive summary for the board pack. The work order covers one issue, ready to forward to whoever fixes it. The compliance report is sized for an auditor or insurer. All three are built server-side from the same scan, by the same pipeline as the web view and the sample report.
Triage and track
Each finding has a workflow status. Mark it fixed once you've closed it. Accept it as a known risk with a written reason. Assign it to a contact email with a due date. Post a comment to record what your IT contractor said.
Every change is written to a history that can only be added to, never edited, so an auditor can see who decided what, when and why.
Re-scan and watch the trend
Each verified scan costs one credit. Re-scan whenever you've made a fix. The target page charts your score over time, one dot per scan, with a ring around any dot where a critical or high finding appeared. You can see whether the fixes moved the number.
For continuous coverage, enrol a verified target in monitoring: daily, weekly, biweekly or monthly. Vantyris re-runs the scan on schedule and emails you about three things only: a new high or critical finding, a security score drop of ten points or more, or a TLS certificate within fourteen days of expiry.
Show it to someone else
There are three ways to put a scan in front of someone who doesn't have a Vantyris account. A share link with an optional watermark, in full, executive or evidence-redacted mode, that lasts from 1 to 90 days and can be revoked any time. A public trust page at a slug you choose, showing the controls in place, which the reader can refresh themselves. Or the PDF.
For workspaces with several targets (an agency, a business with a few brands, a handful of clinics under one owner), the portfolio dashboard ranks every target worst first and shows the average score. A bulk re-scan covers every verified target your credits can pay for, in one click. Workspace API keys, read-only or read-write, let your CI pipeline or SOC dashboard pull the same data.
What we deliberately don't do
- We don't run exploit frameworks, brute force, credential stuffing or fuzz testing.
- We don't make formal compliance claims (“PCI-compliant”, “HIPAA-compliant” and so on).
- We don't run any active module against an unverified target.
- We don't share your data with advertisers, and we don't sell it.
- We don't auto-renew, and we don't sell subscriptions. Credits are valid for 60 days from purchase.
Read the full methodology.