← Back to home
PRICING

Start free. Scale when it matters.

ONE-TIME SCANS

Pay only for what you need — no subscription

L1 · REGULAR SCAN
Free
TLS/SSL certificate check
Confirms your site's padlock (HTTPS) is valid and not about to expire.
HTTP security headers (HSTS, CSP, X-Frame-Options...)
Checks browser-level protections that stop attacks like clickjacking and script injection.
SPF / DMARC / DNSSEC
Checks whether someone could send fake emails pretending to be from your company.
Insecure cookie flags
Checks whether login/session data could be intercepted by an attacker.
robots.txt & DNS records
Checks for accidentally exposed admin/backup paths and how your DNS is set up.
L2 · ADVANCED SCAN
£14.99 one-time
Free if this domain is included in your Starter/Business plan
Cross-Site Scripting (XSS)
Tests if an attacker could inject malicious code that runs in your visitors' browsers.
SQL Injection
Tests if an attacker could manipulate your database through a form or search box.
Full site crawl, OWASP Top 10 coverage
Tests every page and form it can find — not just your homepage.
Ranked, exploitable findings
Each issue is ranked by real-world risk, with remediation steps included.
Broken access control checks
Tests whether restricted pages or admin areas can be reached without proper permissions.
L3 · EXPOSURE SCAN
£9.99 one-time
Free if this domain is included in your Starter/Business plan
Exposed accounts & PII
Finds accounts, usernames, or personal data linked to your domain that are publicly discoverable.
Cloud storage buckets
Checks if company files are sitting in a misconfigured, publicly-accessible cloud storage bucket.
Open ports & service banners
Finds which doors into your servers are left open, and what software is listening.
Typosquat / similar domains
Flags lookalike domains that could be used to impersonate your brand in phishing.
Blacklist / malicious associations
Checks if your IP or domain has already been flagged as malicious elsewhere.
INTERNAL SCAN · SOLVEBEAT AGENT
Included with Starter & Business
On the free plan? Get it on its own for £19/mo per server — no need to subscribe to external scanning first. Install it on a server from your dashboard. Runs continuously, read-only, source published. How it works →
Pending security patches
Flags OS and package updates that haven't been installed yet.
SSH / RDP hardening
Checks for weak remote-access settings like password-only login or missing Network Level Authentication.
Local firewall & antivirus status
Confirms the server's own firewall and (on Windows) Defender are actually turned on.
File permissions & local accounts
Flags world-writable system files, the Guest account being enabled, and other local misconfigurations a remote scan can't see.
Encoded PowerShell & LOLBAS abuse NEW
Hunts the last 24h of the server's own event log for obfuscated commands and abuse of tools like mshta, wevtutil, or certutil.
Pass-the-Hash, RID hijacking & brute force NEW
Detects stolen-credential lateral movement, hidden admin accounts, login brute-force bursts, and new scheduled tasks — each finding mapped to its MITRE ATT&CK technique with a response playbook.
SUBSCRIPTIONS

Prefer ongoing monitoring?

Starter
£39/mo
  • 1 verified domain
  • 1 monitored server (SolveBeat Agent included)
  • Full L2 Advanced Scan & L3 Exposure Scan reports (unlocked, unblurred)
  • Active scans, weekly
  • Cyber Essentials report
  • Email alerts
Business
£149/mo
  • 5 verified domains
  • 5 monitored servers (SolveBeat Agent included)
  • Full L2 Advanced Scan & L3 Exposure Scan reports on all 5 domains (unlocked, unblurred)
  • Continuous monitoring
  • Priority alerts + Slack
  • Quarterly expert review call
Enterprise / MSP
Custom
  • Unlimited domains, white-label
  • Unlimited monitored servers (SolveBeat Agent)
  • API access
  • Manual penetration testing
  • Dedicated remediation team
  • SLA-backed support