hostcloak.com · defensive only · guides
If the VPS has a public IP, some of it is on the internet by design. The real question is: what is reachable that you did not intend — SSH wider than planned, a database port, an admin panel, a forgotten service bound to 0.0.0.0.
That gap between “I think it’s locked down” and “here is what answers from outside” is what an outside-in check is for.
Authorized hosts only. Not a pentest. Not a compliance certificate. No root password.
HostCloak Surface Guard does an outside-in read of a DNS name or public IP you own:
No root password. Not a pentest. Free: $0 · 1 host · 1 successful scan/day.
Maybe. Rules drift. Panels lie by omission. An outside-in scan is how you verify what still answers.
Surface Guard is presence/hygiene, not a load test and not an exploit run. Only scan systems you are allowed to assess.
Work the fix order top-down. Re-scan on Free when the daily limit allows. Pro ($19/mo) adds history, alerts, PDF, and Live Deck.
Next step: name a DNS name or public IP you own at /scan. Quiet what's loud on a host you own.
Defensive posture only — presence, hygiene, and fix order. Not a pentest. Not a compliance certificate. HostCloak never asks for a root password. Scan only hosts you own or have written authorization to assess.