Passive by default · nothing intrusive
Your attack surface is already public.You just haven't read it.
Every certificate you issue, header you omit, and dependency you ship is observable from outside your perimeter. Webcuris reads all of it continuously, ranks what an attacker would reach first, and tells you whether last month's fix actually held.
- Missing HTTP Strict-Transport-Security9 assetshigh
- TLS 1.0 negotiated2 assetshigh
- CSP allows unsafe-inline6 assetsmedium
- SPF record missing1 assetmedium
The product's own dashboard components, rendered with a representative dataset — not a live account.
What every assessment reads
From nothing to a read surface in three steps.
No agents to install, no traffic to reroute. The first assessment is reading what you already publish.
Create an account
Free, no card. You get the same scanning engine as every paid plan — the tier changes scope, never quality.
Sign-up takes under a minute
Point it at a domain or repository
Passive external checks start immediately — the same requests a browser makes. Prove ownership with a DNS record and the deeper checks unlock.
Passive by default · nothing intrusive
Read, fix, verify
Every finding carries severity, confidence, and a remediation package. The next scan says whether your fix actually held.
Findings tracked across every scan
Two surfaces, read the same way.
What you expose to the internet and what you ship in your repositories are the same risk seen from two sides. Both get scanned, scored, and tracked in one history.
External checks are passive — the same requests a browser makes. Anything beyond that stays locked until you prove you own the domain.
What's inside the engine.
Everything below is implemented and running today. Nothing on this page is a roadmap item wearing present tense.
Individual findings don't breach you. Paths do.
The correlation engine reads findings together — within a scan and across every asset you own — and names the compound risk no single row would have shown you.
A lifecycle, not a list
Every finding is fingerprinted and tracked across scans: new, persisting, fixed — and regressed, counted every time it comes back.
Confidence on every row
Confirmed, strong indication, potential, informational. A scanner that states how sure it is lets you tell a fact from a pattern.
EPSS on dependencies
Public exploit-prediction scores on dependency findings, so “critical” and “actually being exploited” stay distinguishable.
Alerts that cannot mask each other
Email and webhooks — Slack, PagerDuty, Datadog, Splunk — fire independently from one decision. A failing webhook cannot suppress the email.
Four report types
Plus SBOM and JSON export for the tools that come after the read.
Your code calls models now.
That's attack surface too.
Prompts, agents, and the dependencies models hallucinate are read by the same engine, with the same severity-and-confidence discipline as every other finding.
AI usage, read from source
Code scanPrompts assembled from request input, agents wired to shells, and secrets inside prompt templates are flagged where they live — in your repository.
finding · LLM prompt built from unsanitised request body · potential
Red-team checks for LLM endpoints
Web scanInjection surface, system-prompt leakage, and tool abuse are exercised under the same authorization rules as every other check — passive until you prove ownership.
locked until domain ownership is verified
Hallucinated dependencies
Supply chainPackage names that models like to invent are checked against what actually exists in the registry. Slopsquatting is a supply-chain vector now; this is the check for it.
finding · dependency not present in registry · strong indication
Agents under guardrails
PlatformThe platform's own agent sessions run with least privilege, and destructive actions stop at a human approval checkpoint that an API key cannot satisfy.
approval required · api-key actors cannot approve their own actions
A row is only useful if it survives being opened.
Any scanner can produce a list. This is what one row looks like all the way down — and the four questions it has to answer before it has earned your afternoon.
Missing HTTP Strict-Transport-Security (HSTS) header
app.example.com · headers · CWE-319
A check fired, and it says how sure it is.
Response headers · CWE-319
A Strict-Transport-Security header on every HTTPS response, with a max-age long enough to survive between visits.
High — exploitable, but needs the attacker on the network path.
Confirmed — the header is absent in the response, not inferred.
Severity is how bad this is if exploited. Confidence is how certain the scanner is that it is real — a separate axis, printed on every row, so you can tell a fact from a pattern before you spend an afternoon on it.
One representative finding, with the wording this check actually emits — not a live account.
What it doesn't do, in writing.
A security vendor that lists only strengths is asking you to do the discovery yourself. The Security Policy documents the limitations in the same detail as the capabilities.
Trust Center →No SOC 2, ISO 27001, or third-party penetration test. Compliance mappings are situational context, not audit evidence.
Passive by default. Checks that go beyond a browser visit stay locked until domain ownership is proven by DNS record or hosted file.
Your data stays yours. Findings are exportable, and account deletion is self-service — no request queue, no retention you didn't choose.
Findings can be wrong. False positives and negatives both happen, which is exactly why confidence sits on every row.
Priced on how much you watch.
Every plan runs the same engine and the same checks. What changes is how many assets you cover.
Assess one thing properly.
- 1 domain and 1 repository (intended limit, not yet enforced)
- Every check the engine runs — nothing held back
- AI/LLM usage risk detection on every code scan
or $399/year — nearly 2 months free
Continuous assessment for a growing surface.
- 5 domains and 4 repositories
- Continuous monitoring on a schedule you set
- Cross-asset correlation — credential reuse, chronic regression
or $799/year — nearly 2 months free
The whole portfolio, watched together.
- 12 domains and 12 repositories
- Everything in Pro
- Compliance mapping: OWASP, NIST 800-53, CIS v8, ISO 27001, SOC 2
Asked, answered.
The questions people arrive with — including the ones about what this deliberately refuses to do.
A passive scan only makes requests an ordinary visitor's browser would make: fetching pages, reading response headers, resolving DNS and inspecting published JavaScript. It sends nothing designed to change the target's behaviour, so it can be run against a site without prior arrangement. Active checks — which send requests a visitor would not — require proven ownership of the domain.
Find out what you're publishing.
Run an assessment against a domain you own and read the result in a few minutes. Free tier, no card, nothing intrusive.
Passive checks only · prove ownership to go deeper