Free today — here's exactly what that means
SecScan's checkers are free and open with no signup, and the full external scan is free during the pilot. There is no paid self-serve tier yet — when one launches it will be priced here transparently.
Free checkers
Free
Run the passive security checkers as often as you like. Each reads only public configuration and returns findings with copy-paste fixes.
- Eight checkers: subdomains, headers, CSP, cookies, TLS, email/DMARC, login rate limit, A–F score
- Results shown instantly, never stored or indexed
- Domain Monitor: clone, lookalike-certificate and typosquat alerts for up to 5 verified domains
- No account needed for the checkers; the monitor needs a free one
External Security Audit
€290
The whole domain rather than one page: every subdomain we can find, the configuration on each, exposed files, leaked secrets and email posture — reviewed by a human and sequenced by what to fix first.
- Subdomain discovery, then per-host headers, CSP, cookies and TLS
- Exposed files, leaked secrets, known-exploited (CISA KEV) context
- PDF report in three business days + a 30-minute walkthrough
- Free re-check of the fixed items within 30 days
- Active checks (open redirect, path traversal, default credentials, XSS) +€200, under written authorization
Agency Portfolio
€149
For agencies and studios that answer for someone else's websites. Every client domain re-scanned monthly, reported under your brand, with an alert when something regresses.
- Up to 10 domains (+€12 per extra domain)
- Monthly re-scan of each domain, white-label PDF per client
- Regression alerts between scans (a header disappears, DMARC weakens)
- Clone, lookalike-certificate and typosquat monitoring for every domain
- Your first audit fee is credited against month one
Questions about what the tools do or don't test? See how we scan and the FAQ.