Your attack surface is already public.You just haven't read it.
Webcuris is a continuous security assessment platform for websites, repositories and AI-assisted code.
It reads what an attacker can see — certificates, headers, dependencies, code — ranks what they would reach first, and tells you whether last month's fix actually held.
- Missing HTTP Strict-Transport-Security9 assetshigh
- TLS 1.0 negotiated2 assetshigh
- CSP allows unsafe-inline6 assetsmedium
- SPF record missing1 assetmedium
The product's own dashboard components, rendered with a representative dataset — not a live account.
What every assessment reads
From nothing to a read surface in three steps.
No agents to install, no traffic to reroute. The first assessment is reading what you already publish.
Create an account
Free, no card. You get the same scanning engine as every paid plan — the tier changes scope, never quality.
Sign-up takes under a minute
Point it at a domain or repository
The standard scan starts immediately — the same requests a browser makes, so it is safe to point at production. Prove ownership with a DNS record and the deeper checks unlock.
Safe on production · nothing intrusive
Read, fix, verify
Every finding carries severity, confidence, and a remediation package. The next scan says whether your fix actually held.
Findings tracked across every scan
Two surfaces, read the same way.
What you expose to the internet and what you ship in your repositories are the same risk seen from two sides. Both get scanned, scored, and tracked in one history.
External checks send only the requests a browser makes. Anything beyond that stays locked until you prove you own the domain.
What's inside the engine.
Everything below is implemented and running today. Nothing on this page is a roadmap item wearing present tense.
Individual findings don't breach you. Paths do.
The correlation engine reads findings together — within a scan and across every asset you own — and names the compound risk no single row would have shown you.
A lifecycle, not a list
Every finding is fingerprinted and tracked across scans: new, persisting, fixed — and regressed, counted every time it comes back.
Confidence on every row
Confirmed, strong indication, potential, informational. A scanner that states how sure it is lets you tell a fact from a pattern.
EPSS on dependencies
Public exploit-prediction scores on dependency findings, so “critical” and “actually being exploited” stay distinguishable.
Alerts that cannot mask each other
Email and webhooks — Slack, PagerDuty, Datadog, Splunk — fire independently from one decision. A failing webhook cannot suppress the email.
Nine report types
Plus SBOM and JSON export for the tools that come after the read.
Your code calls models now.
That's attack surface too.
Prompts, agents, and the dependencies models hallucinate are read by the same engine, with the same severity-and-confidence discipline as every other finding.
AI usage, read from source
Code scanPrompts assembled from request input, agents wired to shells, and secrets inside prompt templates are flagged where they live — in your repository.
finding · LLM prompt built from unsanitised request body · potential
Red-team checks for LLM endpoints
Web scanInjection surface, system-prompt leakage, and tool abuse are exercised under the same authorisation rules as every other check — nothing intrusive until you prove ownership.
locked until domain ownership is verified
Hallucinated dependencies
Supply chainPackage names that models like to invent are checked against what actually exists in the registry. Slopsquatting is a supply-chain vector now; this is the check for it.
finding · dependency not present in registry · strong indication
Agents under guardrails
PlatformThe platform's own agent sessions run with least privilege, and destructive actions stop at a human approval checkpoint that an API key cannot satisfy.
approval required · api-key actors cannot approve their own actions
A row is only useful if it survives being opened.
Any scanner can produce a list. This is what one row looks like all the way down — and the four questions it has to answer before it has earned your afternoon.
Missing HTTP Strict-Transport-Security (HSTS) header
app.example.com · headers · CWE-319
A check fired, and it says how sure it is.
Response headers · CWE-319
A Strict-Transport-Security header on every HTTPS response, with a max-age long enough to survive between visits.
High — exploitable, but needs the attacker on the network path.
Confirmed — the header is absent in the response, not inferred.
Severity is how bad this is if exploited. Confidence is how certain the scanner is that it is real — a separate axis, printed on every row, so you can tell a fact from a pattern before you spend an afternoon on it.
One representative finding, with the wording this check actually emits — not a live account.
What it doesn't do, in writing.
A security vendor that lists only strengths is asking you to do the discovery yourself. The Security Policy documents the limitations in the same detail as the capabilities.
Trust Center →No SOC 2, ISO 27001, or third-party penetration test. Compliance mappings are situational context, not audit evidence.
Safe on production by default. Checks that go beyond an ordinary browser visit stay locked until domain ownership is proven by DNS record or hosted file.
Your data stays yours. Findings are exportable, and account deletion is self-service — no request queue, no retention you didn't choose.
Findings can be wrong. False positives and negatives both happen, which is exactly why confidence sits on every row.
Priced on how much you watch.
Every plan runs the same engine and the same checks. What changes is how many assets you cover.
Assess one thing properly.
- 1 domain and 1 repository
- The standard scan — the same requests an ordinary visitor makes, safe against production
- Severity, confidence and a fix for every finding
or $399/year — nearly 2 months free
Continuous assessment for a growing surface.
- 5 domains and 5 repositories
- Continuous monitoring on a schedule you set
- Cross-asset correlation — credential reuse, chronic regression
or $799/year — nearly 2 months free
The same product, with more room.
- 12 domains and 12 repositories
- Everything in Pro — every feature, at the same depth
- Room for a larger portfolio under one account
Asked, answered.
The questions people arrive with — including the ones about what this deliberately refuses to do.
Webcuris is a continuous security assessment platform for websites, code repositories and AI-assisted code. It scans a site the way an ordinary visitor's browser would — headers, cookies, TLS, DNS and redirect behaviour — analyses repositories and their dependencies for known vulnerabilities and committed secrets, and then re-runs those checks on a schedule so a finding that comes back is reported as a regression rather than as a new discovery. It is built for developers, DevOps and security engineers at small and mid-sized software teams. The free plan covers one domain and one repository at no cost; paid plans start at $39 a month. It is not a website builder and not a design agency.
Find out what you're publishing.
Run an assessment against a domain you own and read the result in a few minutes. Free tier, no card, nothing intrusive.
Safe on production · prove ownership to scan deeper