Your site, graded A to F.

One letter anyone understands without a security briefing. Scan yours free, then get the report that explains how to move it up.

Free, no account, no email. Reads only what your site broadcasts publicly.

  • Security headers7 checks
  • SSL / TLSchain · ciphers
  • DNS records7 record types
  • Email securitySPF · DKIM · DMARC
  • Technology5,000+ stacks
  • Subdomainscrt.sh · OTX
  • Open portsservice ID
  • Service banners8 protocols
SECURITY LABEL✓ OWNERSHIP VERIFIED
boulangerie-dupont.fr
Audited for Studio Kraft · white-label
76
out of 100
  1. A+
  2. A
  3. BTHIS SITE
  4. C
  5. D
  6. E
  7. F
Security headers1 criticalTechnology2 mediumSSL / TLScleanDNS recordsclean
sha256:9f2b7c41e8a0d35b··6e14af90signed 03.08.2026 14:22 CET

What your agency will notice.

Reports, reframed.

Every scan exports a PDF dressed in your agency's colors, voice, and logo. Your client sees you — not us. Recommendations are copy-paste, not philosophy.

Built for Europe.

Data stored in France, VAT invoices, and a compliance narrative aimed at the FR/EU market rather than bolted on for it.

Set & forget.

Weekly or daily scans across your whole portfolio. An email lands the moment a grade drops. You stay ahead of the phone call.

Four steps, then it runs itself.

  1. Add a target.

    Paste a client domain and label it. Every site you maintain sits in one list, with its grade and the date it was last looked at.

    ~30 seconds per site

  2. Verify ownership once.

    Passive modules run immediately — they read publicly broadcast data, exactly like a browser does. Active modules need a DNS TXT record or an HTML file first. Two minutes, and it persists.

    ~2 minutes · one-time

  3. Fire the scan.

    The scan runs as a background job, so you keep working. When it lands you get the grade, the issues ranked by priority, and fix snippets you can paste straight into a config.

    ~2 minutes end-to-end

  4. Then stop thinking about it.

    Weekly or daily runs, each diffed against the last. You are emailed only when something new appears — an expiring certificate, a header removed, a grade that dropped. Silence means the portfolio is still clean.

    runs in background

What moves a B to an A.

The report does not stop at the letter. Every finding carries the fix and what it is worth, so the conversation with your client is about work to be done rather than a score to be argued with.

  • Security headersAdd X-Frame-Options and a CSP
    +8 pts
  • SSL / TLSDrop TLS 1.0/1.1, enforce HSTS
    +6 pts
  • Email securityMove DMARC from none to quarantine
    +5 pts
  • TechnologyUpdate the three outdated plugins
    +5 pts

Questions agencies ask.

Is it legal to scan my clients' sites?

Yes, provided you have a mandate — a maintenance contract, a signed audit agreement, or an explicit email from the client. For active-tier scans we enforce a technical ownership check on top of that contractual mandate.

Where is my data stored?

In France. Supabase eu-west-3 (Paris), backed by AWS. Customer data never transits to non-EU regions during normal operation. Stripe handles billing from Ireland, transactional email goes through Resend in the EU.

What does white-label actually mean here?

You upload your logo and a brand colour in Settings. Every generated PDF renders with your identity — no Mythos Scan logo, no Mythos Scan footer, no mention of us anywhere on the page your client reads.

What happens if a scan finds nothing?

A clean report is as valuable as a long one. Your client pays you for the confidence that nothing changed, and you get the same white-label PDF with an all-clear summary — your retainer justified in one artifact.

Your next client report is two minutes away.

Add a domain, run the scan, hand over a PDF with your logo on it. No install, no agent, no calendar invite.