Every check, from response headers to AI usage

Passive scanning, repository analysis, AI-usage checks, monitoring, and reporting — built as one connected platform, not separate tools bolted together.

webcuris.com

What this shows: A silent screen recording moving through the product: the dashboard's posture score and fix-first queue, the attack-surface view, the findings explorer, a scan's detail page with a finding opened, dependency risk with EPSS scores, AI usage risk, compliance mapping, the four report types, and the integrations page.

Real product footage on a representative dataset — not a mock-up.

Website scanning

Security headers & CSP

Checks for missing or misconfigured headers and Content-Security-Policy directives.

TLS & certificates

Certificate validity, chain, and configuration issues on the live endpoint.

DNS hygiene

SPF, DMARC, CAA, and DNSSEC posture for the target's domain.

Cookies & mixed content

Insecure cookie flags and HTTP resources loaded on HTTPS pages.

Subdomain visibility

Passive discovery of related subdomains as part of attack-surface context.

Repository & code scanning

Dependency vulnerabilities

Known-vulnerable packages across 8 package ecosystems, resolved via OSV.dev.

Secrets detection

Hard-coded credentials and tokens caught before they ship.

Dockerfile & Kubernetes

Common container and manifest misconfigurations.

Pattern-based SAST

Rule-based static analysis for risky code patterns.

LLM / AI usage risk

Flags patterns associated with unsafe LLM integration.

Monitoring & alerting

Scheduled re-scans

Set a monitoring interval per asset and let it run unattended.

Change tracking

Every finding is tagged new, persisting, fixed, or regressed since the previous scan.

Webhook delivery

Generic JSON, or pre-formatted for Slack, PagerDuty, Datadog, or Splunk.

Cross-scan correlation

Patterns visible only across multiple scans or assets, not a single run.

Risk & compliance

Attack-path correlation

Findings chained into narrative risk paths within a scan.

Security maturity ladder

A 5-level model tracking how your program's coverage evolves over time.

Framework situational mapping

Best-effort mapping to OWASP Top 10, NIST 800-53, CIS v8, ISO 27001, and SOC 2 — not a certification.

Exportable reports

Printable scan reports, including a compliance-audience variant.

Trust & access control

Tamper-evident audit log

Hash-chained event log you can verify end-to-end at any time.

Multi-factor authentication

TOTP-based MFA with backup codes.

Scoped API keys

Bearer tokens for CLI and CI usage, independent of session cookies.

Role-based visibility

Owner and user roles, plus organization-scoped shared visibility.

Developer workflow

CI/CD gating CLI

Fail a pipeline on score thresholds with the bundled CLI.

SBOM export

Software bill of materials generated per repository scan.

In-toto attestations

Evidence that a scan ran, for supply-chain record-keeping.

Organizations

A shared scanning scope for a team, alongside personal scans.

See it on your own targets

Create an account and run your first scan in minutes.

Contact

Talk to us.

Questions about what the engine checks, whether it fits your estate, or what it deliberately refuses to do. A person reads every message.

  1. 01You writePlain form, no qualifying call, no obligation. The marketing checkbox is optional and unticked.
  2. 02A person reads itMessages land with the team, not a queue-bot. Nothing is auto-replied.
  3. 03You get an answerTo the address you gave — including “this product is not the right fit”, when that is the honest answer.
Prefer email?
Use the form — no address is published on this deployment.
Reporting a vulnerability?
Read the disclosure policy first — it tells you what is in scope and what to expect.
New messagereplies go to your email

Personal addresses (gmail, outlook, and similar) are not accepted.

+91

0 / 4000