Run a free scan with no account required. Get deterministic findings for headers, TLS, exposed API surface, client artifact leaks, and more. Sign up when you need saved history, AI remediation, exports, monitoring, or audited MCP and AI agent automation inside your workspace.
ZeroWatch is not just a scanner. Paid workspaces can connect Claude Code, OpenClaw, or internal agents through a governed MCP server so agents can list verified targets, submit passive scans, review report summaries, and compare reports without touching your infrastructure directly.
Want an agent to help your team get started? Point it at ZeroWatch's MCP and public LLM guidance so it can explain the product, guide the human through account creation, and recommend the right subscription for agent access.
Evidence-first passive scanning across the public edge, plus bounded verified-target active checks and live DAST for higher-trust plans.
Protocol versions, cipher suites, certificate chain, expiry
CSP deep analysis, HSTS, X-Frame-Options, Permissions-Policy
Secure, HttpOnly, SameSite, prefix compliance, entropy
SPF lookup counting, DKIM, DMARC, MTA-STS, TLS-RPT, CAA
Origin reflection, wildcard, credential exposure
HTTP resources on HTTPS pages, subresource integrity
Frameworks, frontend libraries, secret-like values, source maps
Sensitive file probes, robots.txt, sitemap, and public exposure paths
CT log enumeration and DNS brute force discovery
S3, Azure Blob, GCS URL detection and header analysis
Cloudflare, AWS CloudFront, Akamai, Fastly detection
Swagger/OpenAPI exposure, GraphQL introspection, sensitive route inventory
Ports, HTTP methods, API discovery, auth flows, and live DAST (Pro only)
Paste any public website or domain. No login needed for your first scan.
Scanner modules inspect the public edge, client assets, and reachable API surface without relying on AI guesses.
See deterministic evidence, correlated findings, and optional AI remediation guidance separated clearly from the raw scan data.
Create a free account to save history. Upgrade when you need AI remediation, live DAST, verified-target active checks, scheduled monitoring, or audited MCP/agent automation that your team can actually use in production.
Create free accountEvery scanner module maps to established security standards.