Website exposure, made visible

Know what your website reveals.

Run a free, non-invasive scan of a domain you are authorized to review. Qourby turns public headers, TLS, DNS, cookies, and metadata into a clear, prioritized report.

Non-invasive checksNo credentialsPublic signals onlyResults in minutes
Free public scanStart your domain scan
Scanner ready
Free public scanNo account required

Non-invasive public checks. Only scan domains you own or are authorized to review.

example.comIllustrative report preview
Open sample report
82Posture scoreIllustrative
TLS postureStrong
Headers6 / 8
DNS records12
Cookies3 found
Metadata2 notes
Priority fixes3
Evidence, not alarm.Every finding links back to the signal observed.
5 surfaceschecked together
0 agentsor installs required
Read-onlypublic inspection
Actionablefix guidance included

How it works

From a domain to a defensible next step.

Start with one authorized domain and keep the path from observation to remediation clear.
01

Scan the public surface

Enter an authorized domain. Qourby reviews externally visible headers, TLS, DNS, cookies, and metadata.

02

Understand what matters

See prioritized findings, affected assets, evidence, and plain-English context without digging through raw output.

03

Track the fix

Move from one-off checks to saved history, scheduled scans, exports, and shared remediation workflows.

Built for the work after detection

From a finding to a confident next step.

Technical evidence stays attached to plain-English context, affected assets, and remediation guidance—so the result is useful beyond the security team.

Explore a sample report

Findings queue

12 open across 8 sites
Priority
Medium
Content-Security-Policy missing

app.example.com

Open
Low
HSTS policy not detected

www.example.com

Review
Info
Technology header exposed

api.example.com

Accepted
MediumHTTP headers

Content-Security-Policy missing

The response does not publish a CSP header, which can increase the impact of some content injection mistakes.

Observed responsecontent-security-policy: —
Recommended next step

Start with a report-only policy, review violations, then enforce the smallest required source list.

Free public scan

Useful signal without invasive testing.

See what a browser and public network observer can learn. Qourby keeps the free scan deliberately bounded.Read our security approach

Security headers

CSP, HSTS, framing, content-type, and referrer signals.

TLS signals

Certificate visibility, expiry windows, and public HTTPS behavior.

DNS basics

Public A, AAAA, CNAME, and other externally observable records.

Technology hints

Framework and server details exposed by responses and HTML.

Cookie flags

Browser-visible Secure, HttpOnly, and SameSite attributes.

Response metadata

Headers and public clues that deserve review or hardening.

No exploit testing

No password attacks, authenticated crawling, payload delivery, or internal discovery.

When one scan becomes a workflow

Keep the context. Track the progress.

A workspace turns a point-in-time result into recurring visibility for the sites and people you are responsible for.

History that shows change

Compare scans and see whether posture is improving or drifting.

Scheduled monitoring

Recheck public assets without rebuilding the same review every time.

Reports that travel

Turn technical findings into useful PDF and CSV review artifacts.

Shared remediation

Assign, filter, and track findings across the people fixing them.

Workflow integrations

Use API keys and webhooks to connect scan events to your tooling.

Multi-site visibility

Keep a consistent outside-in view across the sites you operate.

Simple starting points

Scan free. Add workflow when it helps.

Begin with a public baseline, then choose the level of monitoring and collaboration your sites need.

Free

For a fast public baseline.

$0
  • One domain scan preview
  • Public headers, TLS, and DNS
  • Plain-English issue summary
Scan a domain

Team

For shared remediation work.

$149/month
  • 25 monitored sites
  • Finding assignment and webhooks
  • Up to 10 team members
Explore Team

Security and scope

Clear boundaries are part of the product.

Qourby is built for authorized, public-surface visibility. These answers keep that boundary explicit.

Is the free scan a penetration test?+

No. It is a non-invasive review of externally visible security signals. It does not attempt exploitation, password testing, login testing, or internal network discovery.

Can I scan any website?+

Only scan domains you own or are explicitly authorized to review. The public flow is designed for legitimate outside-in visibility, not unsolicited testing.

What happens after the free scan?+

You receive a report preview with prioritized public findings. A paid workspace adds saved history, scheduling, exports, and team remediation workflows.

Does Qourby replace a manual security review?+

No automated public scan replaces a scoped penetration test or expert review. Qourby helps teams find and track visible baseline issues between deeper assessments.

Start with what is already public

See your website the way the outside world does.

Run a free, non-invasive scan for a domain you own or are authorized to review.

Public, non-invasive checks only. Run scans only against domains you own or are authorized to review.