Scan a client's site. Hand them a report they understand.
If you build or run websites for clients, security questions land on you. MySecScan lets you check any client or prospect domain from the outside and turn the result into a clear, prioritized report — free, with no agent and no signup.
How agencies use it
Scan the client's domain
Run the free checkers or request a full external scan. No agent, no access to their servers — everything is read from the outside, the way an attacker sees it.
Get a ranked, plain-English report
Findings are prioritized by what's actually being exploited (CISA KEV), each with an observed value, the expected one, and a copy-paste fix — not a 200-item checklist.
Hand it to the client
Turn it into a short, board-ready summary: what's exposed, what it means in plain terms, and what to fix first. Findings a non-technical stakeholder can act on.
Why it fits agency work
Nothing to install on client infrastructure
Passive, external checks read only public configuration — TLS, headers, DNS, exposed files, email auth. You can scan a prospect before you even have credentials.
What's exploited, first
Findings are cross-referenced against the CISA Known-Exploited Vulnerabilities catalog, so the report leads with real risk instead of drowning the client in low-severity noise.
Plain-English, fix-first
Every finding pairs the technical detail with a one-line explanation and an exact fix, so the report works for both the client's developer and their decision-maker.
Start with a free check
Run these on any client domain right now — no signup:
- Security Headers checker — HSTS, CSP, X-Frame-Options and more, with exact fixes.
- Cookie Security checker — Secure, HttpOnly and SameSite flags on the client's cookies.
- All free tools — SSL, email/DMARC, website security score and more.
- How 376 agencies in Bulgaria and Italy score — our passive study of agency homepages: 81% send no CSP, 63% no HSTS, 27% enforce DMARC. Worth knowing where you stand before a client asks.
- Domain Monitor — watch client domains for clones, lookalike certificates and typosquats from one account (5 verified domains per account in the beta).
Agency Portfolio — €149 / month
Flat rate for up to 10 client domains (+€12 for each domain beyond that). No per-seat pricing, no per-scan credits — the two things every other scanner charges you for as your client list grows.
- Up to 10 client domains re-scanned every month — headers, CSP, cookies, TLS, exposed files, email posture
- A white-label PDF per client, carrying your agency's brand rather than ours
- Regression alerts between scans: a security header disappears after a deploy, a DMARC policy weakens, a certificate is about to expire
- Clone, lookalike-certificate and typosquat monitoring for every domain in the portfolio
- One call a quarter to go through the portfolio and what changed
- Flat rate: +€12 per domain beyond 10, no per-seat or per-scan charges
Start with a single client audit if you prefer; if you then sign up, that fee is credited against your first month.
How do your clients compare?
We passively checked 376 agency homepages in Bulgaria and Italy: 81% send no Content-Security-Policy, 63% no HSTS, and only 27% enforce DMARC. The same gaps show up on the sites those agencies deliver.