hostcloak.com · defensive only
HostCloak is the calm flight deck for solo operators: a defensive posture grade, a clear fix order, and live host metrics — without pentest theater or exploit kits.
Free surface scan View sample report Sign in · upgrade ProFree scans first. Pro/Agency via Stripe Checkout after sign-in. Not a compliance certificate. Not a pentest.
TLS, headers, loud ports, mail auth, obvious admin exposure — scored with a severity-ranked fix order.
CPU, memory, disk, and inbound/outbound bandwidth from an optional metrics agent. No root password. Sample deck · trust.
Optional later enrichment so SSH hammers look like internet background radiation — or something worth a closer look.
Add a DNS name or IP you control. We never ask for a root password. Scanning someone else’s box is out of scope and against the rules.
Presence checks only: what ports answer, what the certificate says, which headers arrived, whether an obvious login page is sitting on the internet.
You get a posture grade and a short list of what to quiet first. Later, an optional agent streams live CPU, RAM, disk, and net — still no root password in our cloud.
| Sev | Finding | Fix order |
|---|---|---|
| High | Admin-style HTTP service reachable on public address | Bind localhost / private net; put behind VPN or reverse proxy auth |
| High | SSH authentication surface broader than key-only baseline | Verify key login, then disable password auth; enable fail2ban |
| Med | TLS certificate expires within 21 days | Renew / fix auto-renew; confirm HTTP→HTTPS redirect |
| Med | Missing strong security headers on primary site | Add HSTS (when ready), CSP baseline, frame protections |
Self-serve Stripe Checkout after magic-link sign-in. Free stays limited. Keys vaulted on app VPS when live.
$0 / limited
$19 / month
$49 / month
HostCloak is defensive security information: presence, misconfiguration, hygiene, and a harden order. We do not ship exploit kits, reproduction steps, or “how to break in” language. We never store or request customer root passwords. A grade is not a compliance certificate and not a pentest report. You must own the target or have written authorization. Authorized targets only.
No. We report what is visible and what to tighten. We do not prove exploitability and we do not provide attack procedures.
Never. Account login is yours. Hosts have no password field. The optional Live Deck agent authenticates with a per-host bearer token, not a shell password.
Systems you own or have written authorization to assess. Scanning third-party networks is prohibited and will get the account closed.
No. Not PCI, not SOC 2, not an audit letter. It is a defensive posture snapshot for operators.
Free is a limited external scan and a fix-order report. Pro (~$19/mo) adds history, alerts, PDF, and Live Deck. Agency (~$49/mo) adds more hosts and a white-label PDF.
Optional Pro agent sends heartbeats (CPU, RAM, disk, net counters). Your deck shows gauges plus inbound/outbound bandwidth history — not DPI. Outbound only, no shell, revoke anytime. Sample · trust details.
Sign in, open the app, choose Pro ($19/mo) or Agency ($49/mo). Stripe Checkout handles card + subscription; manage billing from the app portal when linked.
Free scan first. Upgrade when you want Live Deck and multi-host glass. We will not ask for root.
Sign in Free surface scan Read the SAMPLE reportQuestions still welcome via the privacy-protected inbox if you need a human — checkout is self-serve.