Skip to content
Glintwatch

External security monitoring

The problems are already there. Glintwatch finds them first.

Glintwatch checks your website from the outside every week and tells you exactly what to fix.

Hidden findings on this example surface: a .env file that anyone can download, a TLS certificate that expires in 3 days, and a domain with no DMARC record.

Move the light across the page

The problem

  1. 01 · Exposed files

    A forgotten .env file is a public list of your passwords.

  2. 02 · TLS

    An expired certificate turns every visit into a warning page.

  3. 03 · Email authentication

    Without DMARC, anyone can send email in your name.

Live demoDemo

Run a scan.

Six passive checks, the same ones Glintwatch runs every week. Enter any domain to see how a scan reads.

Results are example data. Nothing is sent from your browser and no website is contacted.

Enter a domain to start.

Example data
  • TLS certificate

    Validity, expiry, protocol

    –
  • Security headers

    HSTS, CSP, framing, MIME sniffing

    –
  • Cookies

    Secure, HttpOnly, SameSite

    –
  • Exposed files

    .env, .git, backups, dumps

    –
  • Email authentication

    SPF, DKIM, DMARC

    –
  • CMS version

    Platform and end-of-life releases

    –

The report

Every finding comes with the fix.

Each scan produces a report written for the people who run the website: a score you can track, findings ranked by severity, and step-by-step fixes your developer or host can follow.

  1. 01

    A score you can track

    One number from 0 to 100, with the calculation shown.

  2. 02

    Ranked by severity

    Critical issues first. Informational notes never cost points.

  3. 03

    Fixes, not jargon

    What was found, why it matters, and exactly how to fix it.

How it works

Three steps. Nothing to install.

  1. 01

    Verify your domain

    Add one DNS record to prove you own it. Glintwatch only scans domains its owners have verified.

  2. 02

    Weekly scans

    Passive checks every week: TLS, headers, cookies, exposed files, email authentication and software versions. Nothing intrusive.

  3. 03

    Clear fixes

    A report ranked by severity, with step-by-step fixes. Hand it to your developer or host as it is.

Early access

Request early access.

Glintwatch is opening to a small number of teams first. Leave your work email to request a place.

One email when your access is ready. Nothing else.