hostcloak.com · defensive only · guides
You stood up Hermes — or another AI agent stack — on a VPS because it was the fast path. Then the worry hits: is this box quietly public in ways I did not mean?
Agent dashboards, API ports, admin UIs, and SSH tend to land on the same public IP. From inside the machine it can feel private. From the internet it may not be.
Authorized hosts only. Not a pentest. Not a compliance certificate. No root password.
Hermes is one example. The same worry shows up on OpenClaw-class and other AI agent stacks on a cheap VPS: dashboards, API ports, and SSH sharing one public IP. HostCloak is about that VPS surface — not affiliation with any agent vendor. Name the DNS or public IP you own and get a posture grade plus what to quiet first.
HostCloak Surface Guard reads a DNS name or public IP you own and reports what strangers can already see:
You get a posture grade and a severity-ranked fix order — what to quiet first. No root password. Not an exploit kit.
Free: $0 · 1 host · 1 successful scan/day. Sign in with Google or a magic link at /login.
No. Surface Guard looks at the public network surface of a host you name — presence and hygiene, not your private files.
No. Optional Live Deck (Pro) is an outbound agent for CPU/RAM/disk and bandwidth later — still no root password.
Follow the fix order: bind services to localhost or a private net, put admin UIs behind VPN or authenticated proxy, tighten SSH. Then re-scan when your Free daily limit allows, or use Pro ($19/mo) for history, alerts, PDF, and Live Deck.
Next step: name a DNS name or public IP you own at /scan. Quiet what's loud on a host you own.
Defensive posture only — presence, hygiene, and fix order. Not a pentest. Not a compliance certificate. HostCloak never asks for a root password. Scan only hosts you own or have written authorization to assess.