hostcloak.com · defensive only · guides
Observatory-style checks (including the MDN HTTP Observatory lineage) are good at teaching and grading web security configuration, especially headers and related policies.
Authorized hosts only. Not a pentest. Not a compliance certificate. No root password.
Clear teaching and grading for HTTP / web configuration — especially headers and related policies. Keep them when that slice is the job.
Many solo operators need the next question in the same sitting: what else is loud on this public IP — ports, TLS, obvious admin exposure — and what should I fix first? Header-only graders generally will not answer that. HostCloak overlaps on headers, then covers the wider public host surface with a severity-ranked fix order. No enterprise DAST pitch. No “talk to sales.” Scan a host you own.
HostCloak is built for solo operators and VPS owners:
Name a DNS host or public IP you own. No root password. Free: $0 · 1 host · 1 successful scan/day.
| Need | Observatory-style tools | HostCloak |
|---|---|---|
| HTTP headers / web config teaching | Strong fit | Headers included as part of Surface Guard |
| Public open ports + admin exposure | Usually out of scope | In scope (presence only) |
| Ranked harden order for a VPS | DIY | Built into the report |
| Live host gauges | No | Live Deck on Pro |
| Compliance letter | No | No (we say so up front) |
No. It is a product for authorized hosts: Surface Guard reports, optional Live Deck, Free/Pro/Agency. Door: /scan.
Never requested or stored.
Pro $19/mo. Agency $49/mo. Free stays limited.
Next step: name a DNS name or public IP you own at /scan. Quiet what's loud on a host you own.
Defensive posture only — presence, hygiene, and fix order. Not a pentest. Not a compliance certificate. HostCloak never asks for a root password. Scan only hosts you own or have written authorization to assess.