Pay as you go Free to start

ClickScan — Security checks anyone can run,
in plain language.

powered by clicksecure.ai

Keeping what you own online safe should not require a security team. Sign in with a one-time email code, add what you own, and pay only for the scans you run.

Sign up with your email address — there is no password and no card. New accounts get free starter credits, so your first check costs nothing.

How it works

From nothing to a clear answer in a couple of minutes.

1

Add what you own

A domain, an IP address or a mailbox. You confirm you're authorized to test it — and for the deeper checks you prove it's yours, in whichever way suits you.

2

Run it now, book it, or repeat it

Run a check on the spot, book it for a date and time in your own time zone, or repeat it daily, weekly or monthly at a discount. It costs a few credits; a scan that fails is refunded.

3

Read, fix, re-check

A plain-language report with a grade and exact fixes. Export it as a PDF, hand it to whoever needs it, and the next run tells you what changed.

What the platform checks

Every check below is built and running today. They all land in the same dashboard.

The ClickScan dashboard: asset grades, open findings and what changed since the last scan The ClickScan dashboard: asset grades, open findings and what changed since the last scan
Click the image to see it full size.

Website encryption (SSL/TLS)

Certificate expiry and trust chain, every protocol and cipher your server accepts, and named weaknesses probed actively rather than guessed.

Browser security headers

HSTS, CSP, X-Frame-Options and the rest — graded on how strict they are, not merely whether they exist.

Email authentication (SPF, DKIM, DMARC)

What stops somebody sending email as you. MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI, with the raw DNS answers in the report.

Live spoofing test

Delivers one forged message to an address at the domain under test and reports whether it was accepted. Proof rather than inference.

Brand Impersonation Monitor

Brand protection: thousands of variations of your name, resolved, with a verdict on what each domain found can actually do.

Brand impersonation — deep sweep

The same check, much wider: every country ending, two look-alike substitutions at once, every single-character typo.

Breach exposure check

Which known breaches an address appears in and what types of data each held. The breached values never reach us.

Port Scan

Which ports on a host are reachable from the internet and what is answering on them. An active check, so the asset has to be proven yours first.

It also reports what a public internet-wide index already publishes about the same addresses — what somebody learns about you before touching anything of yours.

Port Scan — full range

All 65,535 ports rather than the ones services are traditionally assigned to, and each open port is asked what it is running instead of being read off its number.

Subdomain discovery

The other names attached to your domain — the staging site, the old gateway, the thing a contractor left running — and the ones pointing at a cloud service you stopped paying for, which anybody can claim.

It also works out whether the domain is served through a filtering service — the kind that sits in front of a website to absorb attacks — and names the hosts that answer on their own address, around it. That is a way in that skips the protection you are paying for.

Subdomain discovery — deep sweep

A far wider list of names, one level deeper than your domain, and it reads each host’s icon to identify the software — turning “this name suggests Jenkins” into “this host is running Jenkins”.

It has a further way of recognising the filtering service in front of a host, so it can answer where the standard sweep can only say it cannot tell.

DNS record generator

Builds the exact records that fix an email report, ready to paste into your DNS. Runs in the browser and costs nothing.

More checks are on the way

A check appears here the moment it runs, not when it is planned — so this list is always what the platform can do today. If you need something that is not on it, ask us.

Brand protection, not just a domain list

Most phishing aimed at your customers starts with somebody registering a domain that looks like yours. Finding those is the easy half.

Existing is not the point — capability is

Nearly every domain resembling a known name is parked, for sale, or another company’s own trademark defence. A tool that lists all of them as threats is one people stop opening. Each is classified by what it can actually do — serve a website, receive email, sit on your own nameservers — and the report leads with how many are worth acting on rather than how many exist.

Impersonation avoidance, not just detection

The sweep also reports the variations nobody has registered yet, so you can take the ones worth defending before somebody else does. Findings export as STIX or YARA for your own blocklists, and a domain that turns out to be yours can be declared as such — which corrects the check rather than hiding what it said.

How brand protection works in ClickScan →

Not just scans — a platform

Manage what you monitor, work as a team, and prove it to management. The industry calls this external attack surface management (EASM): finding everything you expose to the internet and watching it continuously. We do it without the enterprise price tag, and without the jargon.

Assets & proven ownership

Keep an inventory of the domains, IP addresses and mailboxes you watch — imported and exported as CSV, with related addresses nested under the domain they belong to. For the deeper checks we ask you to prove an asset is yours, in whichever way suits it: a DNS TXT record, a file at /.well-known/, a code emailed to an address at the domain, a callback from the IP itself, or reverse DNS.

Groups & teams

Create organizations to group assets by client, project or brand, invite teammates with roles, and share assets, scans and reports. An owner can also let a member run scans on the owner's credits, for that organization's assets only. Included by default.

On demand, booked, or recurring

Run a check now, book it for a date and time in the time zone you pick, or repeat it daily, weekly or monthly — recurring runs are discounted, so continuous monitoring stays cheap. If a scheduled run can't be paid for, you're told; the schedule stays active.

Whole estate in one go

Select many assets and many checks at once and the wizard collects only what each one needs, skips the pairs that don't apply, and shows the total cost before you spend a credit.

Plain-language reports, with the evidence

Every scan gets an A+–F grade, a line saying which finding drove that grade, and "what you have / how bad it is / what to do" findings — each marked with how we know, whether we proved it or read it from a published record. Underneath sit the cipher tables, raw DNS answers and per-weakness verdicts for whoever wants them. PDF export for one scan, or one report covering every check on an asset.

Somebody else’s data never sets your grade

Part of what a report shows was observed by a third party rather than by us — what a public internet-wide index already publishes about your addresses, for instance. It belongs in the report, because it is exactly what an attacker learns for free before touching anything of yours. So we show it, and we keep it out of your grade: the grade reflects only what we tested ourselves, and those observations are counted on their own rather than folded into your finding count.

Every list we look things up in has a date on it

A check is only as good as the reference data behind it, so every list we did not write ourselves carries where it came from, when it was last refreshed and how far we trust it — and that limit is applied where the grade is worked out rather than at the end, so an exported report carries it too. Data we have not verified ourselves can add coverage; it is not allowed to raise the alarm on its own, and the report says when a finding was held back for that reason. Where a list is too old to rely on, the check says nothing instead of guessing.

Feed it to your own tools

Lookalike findings download as a STIX 2.1 bundle or as YARA rules, for the whole scan or for one domain. What goes in is narrower than what the report shows: a parked domain, another company's legitimate brand protection, a finding we could not confirm, and anything you have told us is yours are all left out — an indicator lands in a blocklist with nobody in the loop.

What changed since last time

Each scan is compared with the previous one for the same asset and check, and you're told only when something actually moved — leading with what got worse and naming it, rather than sending you an identical notice every morning.

It also says when it cannot tell, instead of guessing — if the list of lookalike names we sweep for is widened or narrowed, a comparison that did not know that would report a domain which is still registered and still able to receive mail as having been fixed.

Mark a finding as not applicable

"We know that port is open, it's our VPN." Hide a finding on one asset with a reason on the record. It always expires, it never changes the grade, and it's hidden rather than deleted — so the report you hand a client is still the truth.

One thing does move the grade, and it is a different act: if a domain we flagged as impersonating you is yours, say so and we stop treating it as an impersonation. Hiding a finding says the check was right and it does not matter to you; this says the check was wrong. Withdrawing it moves the grade back.

Your brand on the report

Consultants and agencies can put their own logo and colour on the PDFs, per workspace. Submissions are reviewed before they go live, and the contrast is adjusted so a report is always readable.

Alerts & notifications

Told before a TLS certificate expires — at 30, 7 and 1 day, and again if it lapses — when a scan finishes or fails, when something changed, and when a scheduled run was skipped because credits ran out. In the app and by email.

One view of your exposure

A dashboard that answers the questions worth asking: which assets are worst, how many open findings and how serious, how much of what you own has actually been checked, and whether your grades are getting better or worse over time.

Pay as you go

Buy credits, spend them on the scans you actually run. No seats, no subscription, no lock-in. A scan that fails is refunded, and so is one that found nothing to test. Recurring runs are discounted, and referrals earn credits for both sides.

No passwords, and your data is yours

Sign in with a one-time code sent to your email — there is no password to steal, reuse or reset. Reading everything the platform found is always free; only taking it out as a file needs a paid account. You can close your account yourself, from inside the app.

Organizations are your asset groups

An "organization" isn't only your company. Create as many as you need to organize assets the way you actually work — and share each with the right people.

  • Group by client, project or brand. One space per client or environment, cleanly separated.
  • Invite people with roles. Owner, admin, member or viewer — share assets, scans and reports; everyone sees the same picture.
  • Let the owner pick up the bill. Credits are personal by default; an owner can let a member run scans on the owner's balance for that group's assets.
  • Hand over a clear report. Give clients, management or auditors a plain-language PDF they can act on — with your own logo on it, if you want.

Roles, shared assets and scan history are included by default — no enterprise plan required.

Your organizations
Acme Ltd — production12 assets · A–
Client: Northwind5 assets · B
Project: new-store3 assets · C+
Personal2 assets · A

Who it's for

If you have something on the internet, you have an attack surface to watch — and you shouldn't need a security background to watch it.

Freelancers & solo makers

Check your own sites and your clients' without hiring a pentester — and look more professional doing it.

Startups

Ship fast without leaving security behind. Continuous checks on a startup budget, no security hire needed.

SMEs & IT teams

Keep an eye on your domains, certificates and email without a dedicated security team — with reports for management.

Agencies & MSPs

Monitor every client from one place using separate groups, and hand each a clear, branded report they understand.

Enterprise & security teams

Add lightweight, continuous external monitoring alongside your stack. Proven ownership keeps the active checks safe.

Bug bounty & researchers

Fast recon on authorized targets — TLS, email and exposure at a glance, graded and exportable.

Simple, credit-based pricing

Start free, pay only for what you run. Organizations, asset groups and referral bonuses are included at every tier. Indicative — final packages are set in the app at launch.

Starter

Free

to try

  • Free starter credits
  • Every check, at its normal credit cost
  • Organizations & asset groups
  • Referral bonuses
  • On-screen reports & grades
Get free access

Teams / Enterprise

Talk to us

for organizations

  • Volume credits & discounts
  • Pay by card or bank transfer, invoiced
  • Consolidated billing across groups
  • Priority support & SLA
  • Onboarding & training
  • Optional bundled expert pentest or review
Contact sales

No subscription and no seats: a credit is spent when a scan runs. Credits you buy don't expire; free ones — starter, referral and goodwill credits — last twelve months from the day they're granted, and are always spent first.

Questions

Can I use ClickScan yet?

Yes. ClickScan is live and open to everyone — no invitation, no waiting list. Create an account with your email address, and new accounts get free starter credits so the first check costs nothing.

Who is ClickScan for?

Anyone with something exposed online: freelancers and agencies checking clients, startups and SMEs without a security team, enterprise teams wanting lightweight external monitoring, and bug-bounty researchers doing fast recon on authorized targets.

Do I need to be technical?

No. Reports are written in plain language — what you have, how serious it is, and exactly what to do. No CVSS jargon in the main view, and where a fix means publishing a DNS record we write the record out for you, already filled in with your domain.

What is an "organization" in ClickScan?

A flexible group of assets — not necessarily your company. Create one per client, project, brand or environment, invite the right people with roles, and share assets, scans and reports within it. It's included by default.

How do I sign in?

With a one-time code emailed to you. There are no passwords to remember or reset.

What does ClickScan cost?

Pay-as-you-go credits — no subscription and no per-seat fee. New accounts get free starter credits; recurring scans are discounted; PDF exports and higher volumes come with paid credits. Final packages are set in the app at launch.

Do my credits expire?

Credits you pay for don't expire. Free credits — starter, referral and goodwill grants — expire twelve months after they're granted, and are always spent before the ones you paid for. We warn you before any expire.

Can I scan any website?

Passive checks (like TLS and email) run on public data. For active checks you confirm you're authorized to test the target; for certain checks — the live spoofing test, which delivers a real forged message; the port scan, which connects to your host; and the breach check, which looks up records about a person — we also ask you to prove the asset is yours, using whichever suits it: a DNS TXT record, a file at /.well-known/, a code emailed to an address at the domain, a callback from the IP, or reverse DNS. Exactly which checks require proof is subject to change as we add them.

Which IP addresses do your scans come from?

A small, published set, kept current at clickscan.ai/scanner/ips.txt. If your firewall, WAF or hosting provider blocks unknown scanners, allow those addresses and your scans complete instead of timing out. Read them from that page rather than copying them into a document — we add capacity as the platform grows, and a copy made today goes stale silently. You can confirm a scanner really is us before allowing anything: each address has forward-confirmed reverse DNS, so it resolves to a name like egress1.clickscan.ai and that name resolves back to the same address — both directions agree, which an impersonator cannot arrange. Customers get the per-check detail in the help centre. We never need an account, an agent, a VPN, or any inbound access beyond the service being checked.

Can another tool’s data change my grade?

No, and that is deliberate. Part of a report is observed by somebody else rather than by us — what a public internet-wide index already publishes about your addresses, for instance. We show it, because it is exactly what an attacker learns for free before touching anything of yours, and we keep it out of your grade: the grade reflects only what we tested ourselves, and those observations are counted separately from your findings. The same rule governs the lists we look things up in — each carries its source, when it was last refreshed and how far we trust it, and data we have not verified ourselves can add coverage but cannot raise the alarm on its own. Where a list is too old to rely on, the check says nothing rather than guessing.

What happens if a scan fails, or finds nothing to test?

You get the credits back. A scan that fails is refunded automatically, and a check that couldn't test anything — a spoofing test against a domain that receives no email, say — is graded "not applicable" and refunded rather than being passed off as a good result.

Can I put my own logo on the reports?

Yes. Agencies and consultants can brand the PDF reports per workspace with their own logo and colour. Submissions are reviewed before they go live, and a small "powered by ClickScan" line stays on the page.

Can I get the lookalike domains into my own tools?

Yes — as a STIX 2.1 bundle or as YARA rules, for a whole scan or for one domain. Only what is worth acting on is exported: parked domains, another company's legitimate brand protection, findings we could not confirm and anything you have told us is yours are all left out, because an indicator ends up in a blocklist with nobody reading it first.

What if a "lookalike" domain is actually mine?

Tell us, and we stop treating it as an impersonation of your brand — on that report and every future one. Our check decides ownership from your DNS, so it recognises a defensive registration sitting on your own nameservers and misses a subsidiary registered elsewhere. This corrects the check rather than hiding what it said, so it does move the grade; withdrawing it moves the grade back, and the record of what you declared is kept either way.

Are there limits on how much I can scan?

Light ones, to keep scans reliable and gentle on the systems you test: by default up to 2 scans against the same host at once, and up to 200 queued across your account. Beyond that you are limited only by your credit balance. Trying to bypass these limits — or pointing the scanners at our own systems — is not allowed.

Run your first check

ClickScan is live and open to everyone. Sign in with a one-time email code, add something you own, and read a plain-language report in a couple of minutes.

Get free access

Free starter credits, no card, no subscription. Questions first? Talk to us.