For agencies
A security review you can run on every project you deliver
Compatible with
- GitHub
- GitLab
- Bitbucket
- WordPress
- WooCommerce
- Shopify
What it is for
Four jobs it does well
Show your work before handover
A report with the findings, the evidence and the checks that ran is a far better answer to “is it secure?” than a reassurance. It also documents what was out of scope, which protects you later.
Prove a fix landed
Scan, fix, re-scan. The comparison shows what disappeared, what is still there and what came back — so the conversation about whether something was fixed has an answer instead of an opinion.
Check the work you shipped last year
Dependencies go stale on their own. Running a scan across the projects you still maintain finds the ones that need attention, which is a maintenance conversation rather than an incident.
Give colleagues the access they need
Four roles. A developer runs scans and works through findings; a viewer can read a report without being able to change anything; only owners and admins manage people.
How the Agency plan works today
One organization, 25 projects, unlimited colleagues
If one client’s work must be invisible to the rest of your team, create a second organization for it. One account can belong to as many organizations as you like, and switching between them is a menu at the top of the sidebar. It is a workaround rather than the feature, and we would rather describe it that way than pretend the feature is here.
€99 per month, excluding VAT. Compare the plans.
Client workspaces — on the roadmap, not in the plan
A client area with its own members, its own projects and its own reporting, plus a client-manager role that can run reviews without touching your agency’s settings or billing. The role already exists in our permission model; the workspace around it does not.
It is written here as a plan rather than a feature because both of our own specification documents describe it, and the honest thing is to say which parts have been built. If it is the reason you would buy the Agency plan, wait — or tell us, so we know how much it matters.
Tell us what you need from itQuestions
What agencies ask
Can I keep each client's projects separate?
Today, a project is the unit of separation: each client's application is its own project with its own findings, scan history and reports, inside one organization. Everyone you invite to that organization can see all of it. If a client needs a genuinely isolated workspace, create a second organization for them — the same account can belong to as many as you need.
Is there a separate client workspace with its own members?
Not yet. It is on the roadmap and it is not in the Agency plan, so please do not buy the plan for it. When it ships, existing projects move into it rather than needing to be recreated.
Can I put my own name on a report?
On the Agency plan, yes — reports carry your name rather than ours. They are shareable in-app views with a print stylesheet; a downloadable PDF is a later addition.
Can my client see the findings directly?
Invite them as a viewer and they can read everything without being able to change a status or start a scan. Whether that is a good idea is your call: a findings list with no context is easy to misread, which is why every finding leads with a plain-language explanation.
What if a client wants the remediation done, not just reported?
You can do it, or we can. Remediation is one of our services and it is priced per piece of work — send us the finding and we will tell you what it takes.
Try it on one client project
The free plan covers a single project, which is enough to see whether the findings are the kind you would put in front of a client.
Start free. No automatic changes to your code.