Vulnerabilities
How Vantyris continuous monitoring works (without daily noise).
Published 2026-07-16 · Last updated 2026-07-16 · Vantyris editorial
A one-off scan answers 'what does my site look like today?' Continuous monitoring answers 'what changed since we last looked, and is it urgent?' Vantyris monitoring re-runs the same passive hygiene modules on a schedule you pick and compares each new snapshot with the last one. It emails you only when one of three specific thresholds trips. Everything else goes into the workspace trend chart and stays out of your inbox.
What this means for your business
- Monitoring applies only to verified targets (you proved DNS control). That stops scheduled scans being abused against domains you don't own, and it means active modules never run against strangers' sites.
- Each scheduled run uses one scan credit, the same as a manual re-scan. A weekly monitor on one domain uses roughly four credits a month. You buy credits as you need them. You don't have to take out a subscription to keep monitoring alive.
- Alerts are deliberately narrow: a new high or critical severity finding, a security score drop of ten points or more against the previous snapshot, or a TLS certificate inside fourteen days of expiry. Low-severity drift and informational changes build up quietly in the trend view.
- The comparison is snapshot-to-snapshot, not real-time intrusion detection. Vantyris watches hygiene posture (certificates, headers, DNS, email auth, exposed services, reputation lists), not live packet streams or endpoint agents on staff laptops.
How to fix
Verify a target and enrol it in monitoring from the target settings page. Pick a cadence that matches how often you actually fix things, and confirm the alert emails arrive. Keep enough credits in the wallet for the cadence you chose.
- Complete a verified scan first. Run a verified scan on the domain you want to watch. Verification proves you control the DNS, and a verified scan runs every module. You can't enable monitoring on a teaser-only target.
- Open target settings and enable monitoring. In the workspace, open the target → Settings → Continuous monitoring. Switch it on and pick a cadence (daily, weekly, biweekly, or monthly). Weekly is the default most clinics and agencies pick. Monthly is fine for a stable brochure site that rarely deploys.
- Set the alert email and confirm delivery. Alerts go to the workspace notification address. Add noreply@vantyris.com to your safe senders so the first real alert doesn't land in spam.
- Budget credits for the cadence. Each scheduled run spends one credit. Weekly ≈ 4/month, biweekly ≈ 2, monthly ≈ 1. If you run daily on multiple targets, top up credit packs before a long weekend. The portfolio dashboard shows upcoming runs and your remaining balance.
- Use the trend chart after each alert. When an alert fires, open the target's trend chart. It shows one dot per scan, with an outer ring on the dots where critical/high findings landed. Fix the root cause and run a manual re-scan (another credit) to confirm the score moved. Leave monitoring on to catch regressions.
Owner: Workspace owner enrols. IT contact or agency implements fixes when alerts arrive. · Time: Enrolment: 5 minutes. Ongoing: one credit per scheduled run.
Common gotchas
- Don't pick a daily cadence for a site you only patch monthly. You'll burn credits learning the same TLS and header facts over and over, with no capacity to act on them.
- Monitoring doesn't auto-fix findings. An alert means 'something changed in the external posture'. A human still has to patch, update DNS, or renew a certificate.
- Pausing monitoring during a major rebuild is fine. Write the pause down, so an auditor doesn't read the gap as neglect.
How to verify the fix
After enrolment, check the target page for the next scheduled run time. If you like, trigger a manual scan and confirm the trend chart gains a new dot. To see an alert threshold in action, fix a high finding and re-scan to watch the score move. The next regression should email you if that severity comes back.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
- A3. Security update management: software stays in vendor support, and high or critical patches go on within 14 days.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
How is this different from UptimeRobot or Pingdom?
Uptime tools ask 'is the site up?' Vantyris monitoring asks 'did the security posture change?' Certificate expiry, a new subdomain in CT logs, DMARC record edits, and reputation list appearances are invisible to pure uptime checks.
Can I monitor client sites as an agency?
Yes, within one workspace per billing account. The portfolio view ranks client targets worst-first, and you can bulk re-scan after Patch Tuesday. PDFs and share links export per client.
Will I get emailed about every low finding?
No. Only the three alert conditions above send an email. Everything else is visible in the workspace. That's deliberate. Inbox fatigue is how monitoring programmes die.
Does monitoring include active penetration testing?
No. Scheduled runs use the same passive external methodology as manual scans. Active testing needs a separate pen-test engagement with a written scope.
References
- NCSC: vulnerability scanning guidance NCSC
- Vantyris methodology Vendor
- Vantyris pricing (credit packs) Vendor
Related explainers
- What a passive security scan can and cannot prove about your site.
- Your TLS certificate has expired. Here's how to restore the site fast.
- Google Safe Browsing: how it flags sites and how to clear yours.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris