Two modules under one roof. A one time audit that runs 70 probes and hands you the report. Continuous monitoring that watches uptime, attacks and every file that changes, and explains every alert in plain words.
30 sFastest check interval, with DNS, connect, TLS and first byte timed separately
70Probes in an audit, across 15 categories, on every single scan
1 fileThe monitoring agent is one PHP file. No SSH, no root, PHP 7.2 and up
13 May 2027DPDP penalties begin. Readiness checks are built into monitoring
One umbrella, two jobs
They answer different questions and they do not replace each other. Most sites that are live and earning need both, in this order.
Module one
Audit
“Is my site safe right now?”
Automated black box testing. Every finding carries the exact HTTP request that triggered it, the response, a CVSS 3.1 vector and the CWE and OWASP reference.
15 categories, 70 probes, up to 200 URLs crawled
CVSS 3.1 vectors, CWE and OWASP references
A 40 to 70 page PDF, AES-256 encrypted
One free rescan within 7 days
Two prices, two jobs
$19.99 per target, one time
The full scan on any website. No subscription.
$5.99 per report, for consultants
Already ran your own tests? Bring the findings and get a branded, client ready PDF.
25 modules in one console, from uptime to code audit. Checks as often as every 30 seconds from the outside, and much deeper with one PHP file in the web root.
Your site isn’t built on Growthzi? Both modules still work.
The audit only needs a URL, so you can run one right now. Monitoring runs anywhere PHP 7.2 or newer runs, including WordPress on shared cPanel hosting with no SSH, so that one starts with a demo on your own sites instead of a signup form.
Run the audit. Every finding ranked Critical to Info, with the request that proved it and a remediation step with code.
2
Fix it
Do it yourself with the report, or hand it to our team. We close the findings and rerun the scan so you watch the severity count drop.
3
Watch it
An audit goes stale the next time anyone touches the site. Monitoring is how the next problem reaches you as an alert, not as a customer complaint.
Which one do I need?
The honest version.
Attribute
Audit
Monitor
The question
Is it safe right now?
Did something just change?
Method
Black box. Probes the site from outside the way an attacker would
White box. Reads the server’s own log, files and repository
How often
Once, when you ask. 5 to 10 minutes
Continuously. As often as every 30 seconds
What you get
A 40 to 70 page PDF you can hand to a client, a bank or a buyer
A console, alerts routed by severity, and reports you can send on
Code scanning
Secrets in the JavaScript you ship to browsers
The whole repository, on every push
Install
Nothing. Enter a URL
Nothing from outside. One PHP file to see inside
Best for
A launch, a handover, a compliance ask, due diligence
Any site that is live and earning
Price
$19.99 one time
Free on Growthzi sites. Any other site, book a demo and the price is agreed after you have seen it
Every site we build is monitored, not just hosted
Publish with Growthzi and the outside in checks switch on by themselves within a minute. Bring a site from anywhere else and we add it on the demo call. Either way, how much deeper it sees is up to you, and moving deeper takes about two minutes and never needs SSH.
Depth 1, free
Agentless
Nothing to install
Point it at a URL. Everything measured from the outside, the way a visitor or a regulator sees it. No CPU, traffic or attack data, because none of that is visible from outside.
Depth 2
PHP agent
One file in your web root
Works on shared hosting. No SSH, no root, no extensions, PHP 7.2 and up. It never runs as root, and you can read it before it goes anywhere.
Depth 3
WordPress connector
A plugin, installed the usual way
The same agent packaged as a plugin, plus plugin and theme inventory and the database hardening checks that only make sense inside WordPress.
From outside
Availability
Up, 212 ms, checked 12 s ago
Certificate
Valid, 58 days left, chain complete
DNS
No record changes in 30 days
Security headers
Grade A, one header missing, with the line that adds it
Blocklists
Clean on every list we check
With the agent
Server
CPU 23%, memory 42%, disk 61%, inodes fine
Traffic
1,284 requests today from 312 people, 97 bots
Attacks
42 blocked today, mostly brute force on the login page
Files
One web shell in uploads/, two changed files since Tuesday
Stack
PHP 8.2, WordPress 6.6, three plugins with known vulnerabilities
Example values for one shop.
India, DPDP Act
Compliance is about to be billable
Which trackers fire before anyone consents. Whether a grievance officer is named. Whether your forms record what people agreed to. Free, no sign up, about fifteen seconds.
Findings and fixes, never a compliance verdict. That is a legal opinion and it stays with your lawyer.
DPDP penalties begin. This part of the product exists because of that date.
Weekly
Rechecked, and emailed only when something actually changed.
For agencies and web teams
You are responsible for sites you don’t own
On hosting you did not choose, running plugins somebody else installed, for clients who will call you and not their host when it goes down.
The report has to have your name on it
A monthly PDF with somebody else’s brand across the top tells your client you resell a tool. The same data with your logo tells them you run monitoring. Entirely different conversation at renewal.
One client never sees another
Separate companies, separate logins, separate data, enforced in every query rather than hidden in the interface. It is the part of the schema with tests written specifically to try to break it.
A retainer line item you can deliver
A per site readiness report, rechecked weekly, with the exact fix for each finding. Deliverable in an afternoon rather than subcontracted.
Run the free check on every client domain
No account needed. You will have a list of specific problems across your whole book by the end of an afternoon, and something to take to each client whether or not you ever pay us anything.
What this does not do
Worth knowing before you buy rather than after a month.
It does not fix things for you
Monitoring tells you a file changed, what changed in it and when. Restoring it is your call, or ours if you ask us.
It is not a CDN or an edge firewall
The firewall runs inside your site, on your server, and refuses the request after it arrives.
The audit is not a human pentest
It is automated black box testing. It catches what humans test for first, fast and cheap, but business logic flaws and chained exploits need a person. We sell that separately.
One probe location
Monitoring tells down from slow. It does not tell you slow in Sydney.
No SMS or phone calls yet
Alerts go to email, Slack, Teams, Telegram and webhooks. If someone has to be woken by a ringing phone, we are not the whole answer yet.
Compliance findings are not legal advice
Every readiness line is something observed from outside your site. No field in the data model holds a verdict.
Don’t want to fix it yourself?
Send us the report. We’ll close the findings.
Our team takes the findings, fixes them, and reruns the scan so you can watch the severity count drop. Fixed price against a written scope, not an hourly guess.
Remediation
We close the findings in your report and prove it with a rescan. Quoted per report.
Manual pentest
A human picks up where the scan’s Not Tested items leave off. Scoped and fixed price, delivered in 4 to 7 days.
Three ways to start, pick the one that fits
You do not need a Growthzi site for any of them.
Free DPDP check
Fifteen seconds, no account, no card. Works on any domain you own. The fastest way to find out whether any of this is worth your time.
For every site you did not build with us. Tell us which sites, where they are hosted and what prompted it. Two minutes, no card.
Questions about Growthzi Secure
The audit, the monitoring, and where one stops and the other starts.
If your site is live and making money, yes. The audit tells you what is wrong today. Monitoring tells you about tomorrow. An audit on its own goes stale the next time anyone touches the site, and most sites get touched weekly.
Yes, both work on any website. The audit only needs a URL, so you can run one right now. Monitoring runs anywhere PHP 7.2 or newer runs, including WordPress on shared cPanel hosting with no SSH, and that one starts with a demo on your own sites.
Because what an estate costs to watch properly depends on how many sites you have, how often they need checking, whether the agent goes on them and how long history has to be kept. We set it up on your real sites first, you see your own data, then the price is agreed. Nothing is charged before that.
No. Every probe is non destructive and rate limited to about 10 requests a second, and it backs off on server errors. Nothing is modified and nothing is deleted.
No. You must own the domain or hold written authorisation to test it, and you confirm that at checkout. Scanning without permission may be illegal.
Audit reports auto delete after 30 days. Monitoring keeps traffic and security records to your retention setting, 30 days by default. Everything is encrypted in transit and at rest, and we never sell it or share it for advertising.
Build it here and the watching is free
Every site published on Growthzi gets uptime, certificate, DNS, header and blocklist monitoring from the minute it goes live.