hostcloak.com · defensive only
HostCloak is the calm flight deck for solo operators: a defensive posture grade, a clear fix order, and live host metrics — without pentest theater or exploit kits.
Free surface scan View sample report Join waitlistMVP building now. Free scans → Pro monitoring. Not a compliance certificate. Not a pentest. Waitlist is email until checkout is live.
TLS, headers, loud ports, mail auth, obvious admin exposure — scored with a severity-ranked fix order.
CPU, memory, disk, and inbound/outbound bandwidth from an optional metrics agent. No root password. Sample deck · trust.
Optional later enrichment so SSH hammers look like internet background radiation — or something worth a closer look.
Add a DNS name or IP you control. We never ask for a root password. Scanning someone else’s box is out of scope and against the rules.
Presence checks only: what ports answer, what the certificate says, which headers arrived, whether an obvious login page is sitting on the internet.
You get a posture grade and a short list of what to quiet first. Later, an optional agent streams live CPU, RAM, disk, and net — still no root password in our cloud.
| Sev | Finding | Fix order |
|---|---|---|
| High | Admin-style HTTP service reachable on public address | Bind localhost / private net; put behind VPN or reverse proxy auth |
| High | SSH authentication surface broader than key-only baseline | Verify key login, then disable password auth; enable fail2ban |
| Med | TLS certificate expires within 21 days | Renew / fix auto-renew; confirm HTTP→HTTPS redirect |
| Med | Missing strong security headers on primary site | Add HSTS (when ready), CSP baseline, frame protections |
Intent, not a live checkout. Free stays limited. Paid billing is Stripe — Jarvis swap from this waitlist.
$0 / limited
~$19 / month
~$49 / month
HostCloak is defensive security information: presence, misconfiguration, hygiene, and a harden order. We do not ship exploit kits, reproduction steps, or “how to break in” language. We never store or request customer root passwords. A grade is not a compliance certificate and not a pentest report. You must own the target or have written authorization. Authorized targets only.
No. We report what is visible and what to tighten. We do not prove exploitability and we do not provide attack procedures.
Never. Account login is yours. Hosts have no password field. The optional Live Deck agent authenticates with a per-host bearer token, not a shell password.
Systems you own or have written authorization to assess. Scanning third-party networks is prohibited and will get the account closed.
No. Not PCI, not SOC 2, not an audit letter. It is a defensive posture snapshot for operators.
Free is a limited external scan and a fix-order report. Pro (~$19/mo) adds history, alerts, PDF, and Live Deck. Agency (~$49/mo) adds more hosts and a white-label PDF.
Optional Pro agent sends heartbeats (CPU, RAM, disk, net counters). Your deck shows gauges plus inbound/outbound bandwidth history — not DPI. Outbound only, no shell, revoke anytime. Sample · trust details.
Today the CTA is a waitlist email. Checkout via Stripe is the next swap — Pro ~$19/mo, Agency ~$49/mo. Prefer nearly hands-off after setup.
Same product, less theater. Tell us the kind of VPS you actually run. We will not ask for root.
Join waitlist Read the SAMPLE reportPrivacy-protected waitlist inbox · until checkout exists