hostcloak.com · defensive only · guides
SecurityHeaders is a clear, focused way to grade HTTP security headers. If that letter is the only job, keep using it.
Authorized hosts only. Not a pentest. Not a compliance certificate. No root password.
Fast, focused grading of HTTP security headers — a strong letter when headers are the only job. Keep it in your toolkit for that slice.
Header-only graders generally will not answer ports, TLS, and obvious admin exposure on the same public IP — or what to quiet first. HostCloak overlaps on headers, then covers the wider public host surface with a severity-ranked fix order. No enterprise DAST pitch. No “talk to sales.” Scan a host you own.
HostCloak Surface Guard scans a DNS name or public IP you own. Headers are part of the read, alongside ports, certificate hygiene, and admin-style exposure. You get a posture grade and a severity-ranked fix order.
No root password. Not an exploit kit. Free: $0 · 1 host · 1 successful scan/day.
| Need | SecurityHeaders | HostCloak |
|---|---|---|
| Fast HTTP header letter | Strong fit | Headers included in Surface Guard |
| Public ports + admin exposure | Out of scope | In scope (presence only) |
| Ranked harden order for a VPS | DIY | Built into the report |
| Live CPU/RAM/disk/net gauges | No | Live Deck on Pro |
For header-only workflows, maybe not. For “headers + is this VPS quiet?” workflows, HostCloak is the wider pass.
Not for Free Surface Guard. Live Deck (Pro) is optional later.
Google or magic link at /login. Stripe in /app.
Next step: name a DNS name or public IP you own at /scan. Quiet what's loud on a host you own.
Defensive posture only — presence, hygiene, and fix order. Not a pentest. Not a compliance certificate. HostCloak never asks for a root password. Scan only hosts you own or have written authorization to assess.