What we check

Six checks, one question: did it change?

Each check looks at one part of what your domain tells the outside world. We record the answer, compare it with the last one, and only speak up when something moved.

TLS

Live

Every TLS endpoint makes promises: a chain a client will trust, a named owner, a date it stops being true. We handshake the way a browser does, write down what was presented, and compare it against what stood there last time.

What one scan records

alpn
h2
cipher
TLS_AES_128_GCM_SHA256
endpoint
api.example.com:443
expiry_bucket
lte_90d
group
X25519
ocsp_stapled
false
verified
true
versions
1.21.3

chain

1 item

leaf

fingerprint
51d8a3f6c0e9b2d7a4f1c8e5b0d3a6f9c2e7b4d1a8f5c0e3b6d9a2f7c4e1b8d5
issuer
Google Trust Services / WE1
not_after
2026-12-17T00:00:00Z
not_before
2026-09-18T00:00:00Z
sans
api.example.com
spki_sha256
b72e5d1c9a4f8e3b6d0c2a7f5e1b9d4c8a3f6e0b2d7c5a1f9e4b8d3c6a0f2e7b
subject
api.example.com

What we tell you about

Chain untrustedCertificate expiredIssuing CA changedKey rotatedNames changedExpiry approachingProtocol changedCertificate reissuedChain changedChain trusted againCertificate renewedALPN changedKey exchange group changedCipher changed

Security headers

Live

Security headers are standing orders from a site to every browser: use HTTPS, run only these scripts, never frame this page. They live in server config and vanish quietly in a deploy. We ask for the page once, as a named scanner, and compare its headers against what stood there last time.

What one scan records

headers

10 fields
content_security_policy
absent
cross_origin_embedder_policy
absent
cross_origin_opener_policy
absent
cross_origin_resource_policy
absent
permissions_policy
absent
referrer_policy
strict-origin-when-cross-origin
strict_transport_security include_subdomains
true
strict_transport_security max_age
31536000
x_content_type_options
nosniff
x_frame_options
deny

What we tell you about

Blocked or redirected awayAnswering againBlock changedStrict-Transport-Security removedContent-Security-Policy removedX-Content-Type-Options removedHSTS disabledStrict-Transport-Security changedContent-Security-Policy changedX-Content-Type-Options changedX-Frame-Options changedReferrer-Policy changedPermissions-Policy changedCross-Origin-Opener-Policy changedCross-Origin-Embedder-Policy changedCross-Origin-Resource-Policy changedStrict-Transport-Security addedContent-Security-Policy addedX-Content-Type-Options addedX-Frame-Options addedReferrer-Policy addedPermissions-Policy addedCross-Origin-Opener-Policy addedCross-Origin-Embedder-Policy addedCross-Origin-Resource-Policy added

PQC

Live

Traffic recorded today can be opened later, once the machine to open it exists. Hybrid key exchange closes that window. We ask your endpoint three questions in three handshakes, and record which answers it is willing to give.

What one scan records

classical_ok
true
endpoint
example.com:443
hybrid_group
X25519MLKEM768
hybrid_supported
true
leaf_sig_alg
ECDSA-SHA256
pq_certificate
false
preferred_group
X25519MLKEM768
tls13
true

What we tell you about

Post-quantum turned offTLS 1.3 removedPost-quantum certificatePost-quantum turned onHybrid group changedPreferred group changedTLS 1.3 addedSignature algorithm changedClassical key exchange changed

DNS

Live

A name is the front door, and everything follows it. We ask one record type at one name, write the answers down as a set, and compare that set with the last one. A TTL ticking down is not a change; the records are.

What one scan records

absent
false
name
example.com
records
192.0.2.34198.51.100.35
type
A

What we tell you about

Name vanishedName returnedRecords vanishedRecords appearedRecords changedRecord removedRecord added

MCP

Live

An MCP server tells agents which tools exist and what they do. A description rewritten quietly is a new instruction to every agent that reads it, and nothing else would show you. We speak the protocol, list what is on offer, and diff it.

What one scan records

capabilities
tools
endpoint
https://mcp.example.com/mcp
protocol_version
2025-06-18
transport
streamable-http

auth

1 field
required
false

server

2 fields
name
example-docs
version
1.4.0

tools

3 items

fetch_site_map

description
Fetch the site map as a list of page URLs.

list_resources

description
List the documents this server can read.

search_docs

description
Search the documentation by keyword.

What we tell you about

Authentication weakenedTool description changedTool schema changedTool removedTool addedTool changedAuthentication strengthenedAuthentication changedResources changedPrompts changedCapabilities changedProtocol version changedServer version changed

robots.txt

In build

robots.txt is the one place you tell crawlers and AI agents what they may take. It is edited by hand, rarely, and a deploy can replace it without anyone reading the diff.

What one scan records

  • Whether the file is served, and with what status
  • Allow and disallow rules, per user agent
  • Rules aimed at AI crawlers specifically
  • Sitemap and crawl-delay directives
  • Lines no crawler will honour

What we tell you about

  • The file went missing, or stopped parsing
  • A disallow rule was dropped
  • An AI crawler was newly allowed, or newly blocked
  • The sitemap now points somewhere else

Agent Card

In build

An agent card is what another system reads before it calls you: who you are, what you can do, where to send the request and how to authenticate. When it drifts, your callers are working from an older answer than you think.

What one scan records

  • Whether the card is served, and matches its schema
  • Declared name, version and provider
  • Skills, and what each one claims to do
  • Endpoint URLs, and the transports on offer
  • The authentication schemes it declares

What we tell you about

  • The card vanished, or stopped validating
  • A skill was added, removed or reworded
  • An endpoint moved to another URL
  • Authentication requirements were weakened

x402

Live

x402 turns HTTP 402 into a working handshake, so an agent can pay per call with no account to open first. The terms quoted there are money, so a change to them is a change to what your callers pay. We ask one path once and never pay, so the quote is all we ever hold.

What one scan records

code
402
method
GET
transport
body
url
https://api.example.com/api/data
version
2

accepts

1 item

eip155:8453|0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

amount
100000
asset
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
extra
{
  "name": "USD Coin",
  "version": "2"
}
network
eip155:8453
pay_to
0x4b7a2e9c1d3f5a6b8c0d2e4f6a8b0c2d4e6f8a0b
scheme
exact
timeout_seconds
300

cache

6 fields
cdn
""
directive
no-store
guarded
true
stored
false
validator
false
vary_on_pay
false

What we tell you about

Serving without paymentPayment address changedPayment token changedSigning domain changedEndpoint stopped answeringAnswer served from cacheCache guard lostQuote unreadablePrice changedNetwork changedPayment scheme changedPayment option removedPayment option addedPayment option changedEndpoint charging againCDN changedQuote transport changedProtocol version changedCache guard addedCache headers changed

The same method, every check

Record, compare, report

Every check runs on the schedule you choose, and behaves the same way once it does.

1

We record the answer

Each scan is written down in full, in one canonical shape, so two scans can be compared field by field.

2

We compare it with the last one

Only a real difference counts. Noise that means nothing — ordering, formatting — never reaches you.

3

We tell you what moved

A change arrives named and ranked, with the before and the after, and it stays as evidence.

One last thing

Run a check on your own domain.

If it comes back clean, you have lost nothing. If it does not, you found out today.

Run a free check

No card needed