hostcloak.com · defensive only · guides

Harden a loud public VPS — SSH and admin surfaces first

A VPS gets “loud” in predictable ways: SSH open wider than you meant, an admin panel on a public address, extra services bound to 0.0.0.0, TLS or headers left for later. The hard part is not finding another 40-page hardening guide — it is knowing what to quiet first.

Get your fix order Sample report

Authorized hosts only. Not a pentest. Not a compliance certificate. No root password.

What HostCloak does

HostCloak Surface Guard scans a DNS name or public IP you own and returns a posture grade plus a severity-ranked fix order. SSH-class and admin-style exposure sit in that same list with TLS and header gaps, so you are not juggling three tools and a spreadsheet.

No root password. Not a pentest. Free: $0 · 1 host · 1 successful scan/day.

Get your fix order

What’s not included

Defensive patterns you apply yourself (examples of *categories*, not a guarantee of your report): bind admin services private / behind VPN or authenticated proxy; prefer SSH keys and tighten password auth once keys work; renew TLS; add strong headers when ready.

Compared to header-only graders

SecurityHeaders / Observatory-style tools help when the job is HTTP headers. Hardening a loud VPS usually starts with reachability (SSH, admin HTTP, unexpected ports). HostCloak is aimed at that ordered, outside-in pass.

FAQ

Will the report tell me exact sshd_config lines?

It gives defensive fix order and presence findings — not a pentest playbook. You still own the config changes.

One scan enough?

Free allows 1 successful scan/day per the Free limits — enough to baseline and verify after a change. Pro ($19/mo) adds history, alerts, PDF, deeper Surface Guard, Live Deck.

Who is this for?

Solo operators and VPS owners who want to stay off easy radar.

Get your fix order Sign in

Next step: name a DNS name or public IP you own at /scan. Quiet what's loud on a host you own.

Defensive posture only — presence, hygiene, and fix order. Not a pentest. Not a compliance certificate. HostCloak never asks for a root password. Scan only hosts you own or have written authorization to assess.

Guides