Skip to content

WEBSITE SECURITY, WITH A NEXT STEP

Build fast.
Protect what
you ship.

Whether you’re vibe coding, building with AI, or writing every line yourself, your site’s security matters. Find gaps, understand the risks, and see what to fix next.

Start with a free public scan. Verify ownership for deeper scans on eligible plans.

QOURBY / FINDINGS WORKBENCHACTUAL APP · SAMPLE DATA
Qourby’s actual findings screen: asset navigation, issue and observation filters, severity and status columns, and a finding inspector with overview, evidence, and remediation tabs.
Real interface. Illustrative local demo data, not a live customer scan.View full capture (new tab)

Evidence beside the finding

Ownership before active scanning

A workflow beyond detection

How it works

A first look is just
the starting point.

Move from a public baseline to a verified assessment, then into the work of fixing what you find.

01

Start with the surface.

Run a free public scan of a domain you own or are authorized to review. Get a preview of externally visible security signals.

02

Verify. Then go deeper.

Add your site and verify ownership with a DNS TXT record or verification file. Standard and Deep active scans require verification and an eligible plan.

03

Investigate. Fix. Retest.

Work through findings with severity, confidence, evidence, and remediation context. Request a retest after making a change and review the result.

Choose the right depth

Public first.
Deeper once verified.

The free preview and active scans serve different purposes. Know what you are running and what the result can tell you.

A first look

Free public scan

A bounded check of what your website exposes publicly.

  • HTTP security headers and cookie flags
  • Public DNS and HTTPS signals
  • Technology and response metadata

No account required to start. The preview limits technical finding details; workspace access is required for the full detail.

Start a free scan

Verified ownership

Standard scan

Active checks for the sites you control.

  • TLS configuration and exposed services
  • Path discovery and exposure checks
  • Automated vulnerability checks

Requires verified ownership and an eligible active plan. Available checks depend on your configuration and target.

Create a workspace

Verified ownership + eligible plan

Deep scan

A broader assessment with more room to investigate.

  • Expanded discovery and larger scan budgets
  • Additional application security checks
  • Evidence to investigate potential weaknesses

Requires verified ownership and a plan with Deep access. A scan reports the coverage achieved, including incomplete checks.

Explore scan plans

Non-invasive checks apply to the free public scan. Active profiles make additional requests to your verified site. Read our security approach

When one scan becomes a workflow

A finding is useful.
Context makes it actionable.

The findings queue and inspector keep the question, the evidence, and the next step together.

  1. 01

    Prioritize with context

    Filter by severity, status, or asset. Review confidence and distinguish issues from informational observations.

  2. 02

    Inspect what was observed

    Open recorded evidence beside the finding, then review remediation guidance and the full scan context.

  3. 03

    Follow through on the fix

    Use assignments and review states where your plan allows. Request a retest after a change; the request itself does not mark a finding fixed.

Explore a sample public report
Actual Qourby evidence inspector with a selected sample finding, Assign, Retest and Dismiss actions, and recorded sample request and response headers.
Captured from the app’s evidence inspector.
Illustrative data; availability varies by finding.

Simple starting points

Start free.
Build your workflow from there.

Choose the scan depth, history, scheduling, exports, and collaboration your sites need. Availability and usage limits vary by plan.

Compare plans and limits

Security and scope

Good questions.
Clear boundaries.

What gets checked, what verification unlocks, and how to read the result.

Can I check an app I built with AI?

Yes, if it is deployed on a public domain you own or are authorized to assess. Qourby checks the running website over the network. It does not review your source code or certify AI-generated code. The same ownership verification and plan requirements apply to deeper scans.

Does Qourby only scan the public surface?

No. The free scan is a non-invasive public preview. After you verify site ownership, Standard and Deep profiles provide active scanning on eligible plans. Verification establishes control of the site; your plan and scan configuration determine which checks you can run.

How do I verify my website?

Add your site to a workspace, then publish the supplied DNS TXT record or place the verification file at the specified path on your site. Qourby checks the record or file before allowing Standard or Deep scans.

What do I get from the free scan?

A preview of public security signals, including headers, HTTPS, DNS, cookies, and exposed metadata. Some technical finding details are restricted in the public preview and require workspace access. It does not run the Standard or Deep active profiles.

Does a completed scan mean my website is secure?

No. Completion describes the scan run, not a guarantee of security. Review its findings, confidence, and coverage. Blocked, skipped, or incomplete checks leave gaps, and automated scanning does not replace a scoped manual security assessment.

Are all workspace features included in every plan?

No. Scan profiles, usage limits, history, scheduling, exports, and collaboration vary by plan. Review the pricing page before choosing a workspace plan. Ownership verification does not automatically grant paid features.

Your next step

Start with
your website.

A free public baseline for a domain you own or are authorized to review.

Free public scanNo account required

Public, non-invasive checks only. Run scans only against domains you own or are authorized to review.

See a sample report first