External security monitoring
The problems are already there. Glintwatch finds them first.
Glintwatch checks your website from the outside every week and tells you exactly what to fix.
Hidden findings on this example surface: a .env file that anyone can download, a TLS certificate that expires in 3 days, and a domain with no DMARC record.
Move the light across the page
The problem
- 01 · Exposed files
A forgotten
.envfile is a public list of your passwords. - 02 · TLS
An expired certificate turns every visit into a warning page.
- 03 · Email authentication
Without DMARC, anyone can send email in your name.
Live demoDemo
Run a scan.
Six passive checks, the same ones Glintwatch runs every week. Enter any domain to see how a scan reads.
Results are example data. Nothing is sent from your browser and no website is contacted.
Enter a domain to start.
Example dataTLS certificate
Validity, expiry, protocol
–Security headers
HSTS, CSP, framing, MIME sniffing
–Cookies
Secure, HttpOnly, SameSite
–Exposed files
.env, .git, backups, dumps
–Email authentication
SPF, DKIM, DMARC
–CMS version
Platform and end-of-life releases
–
The report
Every finding comes with the fix.
Each scan produces a report written for the people who run the website: a score you can track, findings ranked by severity, and step-by-step fixes your developer or host can follow.
- 01
A score you can track
One number from 0 to 100, with the calculation shown.
- 02
Ranked by severity
Critical issues first. Informational notes never cost points.
- 03
Fixes, not jargon
What was found, why it matters, and exactly how to fix it.
Website security report
example.com
Scanned on 9 October 2026, 08:00 UTC
Security score: 39 out of 100
At risk
Fix the critical problems today: they could let someone steal data or take over your website.
- 1 Critical
- 0 High
- 3 Medium
- 2 Low
- 0 Info
Where to start
- Critical Your secret settings file (.env) can be downloaded by anyone
- Medium Your security certificate expires in 9 days
- Medium No protection policy against malicious scripts
Critical 1 issue
Critical: fix today. These can directly expose your data or let attackers into your website.
Critical Your secret settings file (.env) can be downloaded by anyone
What we found
A file called .env is publicly available on your website. This file usually holds the passwords and keys your website uses to connect to its database, payment provider and other services.
Why it matters
Anyone who downloads it can use those passwords to read or change your data, send email in your name, or run up bills on your accounts.
How to fix it
- Ask your developer or hosting provider to block public access to files and folders whose names start with a dot (such as .env or .git).
- Move the .env file outside the public website folder if possible.
- Change every password and key that was in the file. Assume they have already been copied.
- Run Glintwatch again to confirm the problem is gone.
Who can fix this
Your web developer or hosting provider.
Where we found it
https://example.com/.env
Medium 3 issues
Medium Your security certificate expires in 9 days
+ 4 more findings, each with its own fix
How it works
Three steps. Nothing to install.
- 01
Verify your domain
Add one DNS record to prove you own it. Glintwatch only scans domains its owners have verified.
- 02
Weekly scans
Passive checks every week: TLS, headers, cookies, exposed files, email authentication and software versions. Nothing intrusive.
- 03
Clear fixes
A report ranked by severity, with step-by-step fixes. Hand it to your developer or host as it is.
Early access
Request early access.
Glintwatch is opening to a small number of teams first. Leave your work email to request a place.
One email when your access is ready. Nothing else.