Signing in without a password
Sign in with a one-time code by email, or with a passkey on your own device. No passwords to forget or to leak.
SOC Dashboard
Explained part by part: what it checks, when you hear about it and why it matters. Not every feature is in every plan; the licence table shows what falls where.
6 areas, from news to alerts
01
Who gets in, how they sign in and what the screen looks like.
Sign in with a one-time code by email, or with a passkey on your own device. No passwords to forget or to leak.
Staff register with their work email on a verified domain. You do not have to add everyone by hand.
Kiosk accounts for screens that stay on all day: content only, no buttons and no sign-in screen.
Everyone drags the blocks where they want them. What one person needs daily, another never has to see.
02
Everything going on, on one screen, filtered down to what concerns you.
Advisories from the Dutch NCSC, alerts from CISA, updates from Microsoft and trade press news come together on one dashboard. No ten tabs and no newsletters left unread. Sources come from third parties: if a source disappears or its provider restricts access, access to that source may end.
Set per source which topics you want to see, which to hide and which words should stand out. What is left is what concerns you.
Look back at what came past earlier, for instance when a vulnerability turns out to matter only weeks later.
03
The checks you get as soon as you monitor a domain at all.
Continuous checking that your site responds, with an alert the moment it stops.
A warning well before a TLS certificate runs out. An expired certificate takes a site down and is always avoidable.
The same for the registration of the domain itself. A forgotten renewal is rare and expensive.
Checks SPF, DMARC and DKIM and says in plain language what is missing. Those three settings decide whether someone else can send mail in your name.
04
Deeper checks on your domains, released per plan.
Checks your website against the Dutch NCSC IT security guidelines, with the reasoning next to every finding.
Looks for domain names resembling yours: a letter swapped, a hyphen added, a different extension. Such names are used for fake invoices and phishing, and it helps to see them before a customer falls for one.
Records what your DNS looks like and reports unexpected changes. A changed MX or NS record is sometimes a migration and sometimes a takeover.
Checks whether files are reachable from the internet that should not be: backups, configuration files, database dumps.
Every issued certificate ends up in public logs. We follow them and report when a certificate appears for a name under your domain that we did not know about, or from a certificate authority you do not use.
Shows which names exist under your domains and where they point - often more than an organisation realises. If a reference is left behind to a cancelled service, we warn you: whoever registers that name there gets a working hostname under your domain, certificate included.
Receiving parties such as Google and Microsoft report daily which systems send mail on behalf of your domain, and whether that mail was trusted. We collect those reports and turn them into an overview. It regularly contains systems nobody had in mind any more. You keep receiving the reports at your own address and forward them to an address we set up for you; we do not have to publish anything in your DNS.
05
Where a finding ends up and how you deal with it.
What needs attention appears on screen and, if you want, in your inbox.
Alerts arrive where your team already is, without anyone having to watch a separate screen.
Every finding can be signed off with an explanation. Six months later you can still read why it was decided at the time that it was not a problem - which helps during an audit and when bringing a new colleague up to speed.
06
What else comes with it.
The state of your baseline measures alongside the rest, on the same screen.
For teams working across several time zones.
A day setting it up together, so it fits the way you work from day one.
An alert is only useful if you can rely on it.
The checks do not run from a single data centre. That is the difference between "the site is unreachable" and "the site is unreachable from one place".
Every check shows when it last ran and whether it is falling behind. A check that quietly stops is more dangerous than a check that finds nothing.
Request a demo and we'll walk through the dashboard with you, using your own domain as the example. No strings attached.