ReadySECURE™ Scanning Service

Run a free scan See pricing

What ReadySECURE webscan is

ReadySECURE webscan is an authorized vulnerability scanning service for websites, APIs and internet-facing hosts you control. You add a domain, confirm in writing that you are authorized to have it tested, and we scan it with six industry-standard scanners on your schedule — returning a prioritized report of what was found, how serious it is, and how long it has been open.

It is built for people who want the real scanners — not a lightweight imitation of them — run continuously, with the authorization record kept alongside every result.

What do you scan for?

Six scanners, and every plan runs all six. Withholding one would mean telling you we found nothing on a class of problem we never looked for.

🛡

ZAP Passive

  • Safe, non-intrusive HTTP and WebSocket analysis
  • Flags missing headers, CSP, cookies, and cache issues
  • Great for baseline web security hygiene
Learn more →
🎯

ZAP Active

  • Authorized active testing against web applications
  • Probes for XSS, SQL injection, SSRF, and input flaws
  • Tunable scan policies and rate controls
Learn more →

OpenVAS

  • Broad CVE and misconfiguration coverage
  • Authenticated and unauthenticated network scanning
  • Feed-driven vulnerability tests for patch and service issues
Learn more →
🔒

TestSSL

  • Deep TLS and SSL inspection on any port
  • Enumerates protocols, ciphers, and certificates
  • Finds weak suites, expiry, and crypto flaws
Learn more →
👁

Nmap

  • Host discovery and port scanning
  • Service and version detection plus OS fingerprinting
  • NSE scripts for targeted security checks
Learn more →
🚀

Nuclei

  • Fast template-based scanning at scale
  • Checks CVEs, exposed panels, APIs, and cloud misconfigs
  • Continuously updated templates for new detections
Learn more →

What is included in a free scan?

One full scan of one target, with any of the six scanners, and the complete report that comes with it. No card, no plan, no call. A free scan is not a cut-down preview — it is the same scanner, the same depth and the same findings a paying customer gets.

What you do not get for free is repetition: scheduling, history and trend need a plan, because the cost of this service is the machine time it takes to run scanners over and over.

What assets can I scan?

The one rule: it has to be something you are authorized to have tested. That is a legal boundary, not a technical one, and it is the reason this service asks a question before it scans anything.

Is authorization required?

Yes, and it is enforced rather than assumed. Every target carries its own authorization record naming the person who approved it, the exact text they agreed to, and the date and time they agreed to it. A target without a current record cannot be scanned — the gate refuses it, and there is no setting that turns the gate off.

This matters more than it sounds. Unauthorized scanning is a legal problem in most jurisdictions, and "the tool let me" has never been a defence. When a complaint arrives about traffic to a host, the answer here is a signed record rather than a shrug.

How long does a scan take?

Most scans finish in a few minutes. Deep network scans can run for an hour or more, and are capped at three hours.

Scheduled scans run overnight on your clock, and can be told to spread across several nights rather than piling into one window.

How are results delivered?

  1. A report per scan — everything that run found, with severity, location and description.
  2. A risk register across every target — one list, with status you set yourself: open, accepted, mitigated, false positive.
  3. Aging — how long each finding has been open, and how the estate has moved month over month.
  4. Spreadsheet export — the whole thing as XLSX, whenever you want it.
  5. API and webhooks — pull results into your own tools, or be told the moment a scan finishes.

Findings are yours. Cancel a plan and your reports, history and exports stay available — scanning stops, the record does not.

How does it work?

  1. Add a target. A domain, host or URL you control.
  2. Authorize it. Read the statement, put your name and title to it. Bulk import takes one acceptance for a whole spreadsheet.
  3. Pick the scanners and, if you want them repeated, a schedule in your own timezone.
  4. Read the findings and set their status as you work through them. Re-scan to confirm a fix.

How is this different from a free online scanner?

Free one-off web tools are useful for a single look at a single page. They are a different kind of thing to this, in four ways:

If you only want to look at one page once, use a free tool — that is what they are good at. This is for an estate you are responsible for.

Scan something you own, free

One target, any scanner, the full report. No card and no plan.

Run a free scan See pricing