Evidence before severity.
Endpoint, response, certificate, port, header or crawl signal is attached to the finding. Your team sees what the score saw.
Reproducible contextRead every signal your site emits. Act on what matters.
Security, search, AI visibility, accessibility and performance telemetry in one evidence-backed control plane.
Security posture, search integrity and AI discoverability share the same pages, infrastructure and business context. Sitelemetry reads them together, while keeping every finding independently verifiable.
TLS, headers, exposure, ports, identity and safe injection canaries are correlated into one evidence set.
| Observed signal | State | Evidence | Action |
|---|---|---|---|
| Content-Security-Policy | High | unsafe-inline observed | Harden policy |
| TLS protocol and certificate | Verified | TLS 1.3, trusted chain | Monitor |
| Public management surface | Medium | /wp-json user route | Restrict route |
| SQLi canary response | Stable | No error or 5xx delta | Retest nightly |
Every result carries the context needed to decide, repair and prove the repair. That makes Sitelemetry operational, not ornamental.
Endpoint, response, certificate, port, header or crawl signal is attached to the finding. Your team sees what the score saw.
Reproducible contextImpact, exploit narrative, guardrail and implementation guidance are written for the people who will actually ship the repair.
AI-ready remediation promptRun the same evidence path again, compare score history and keep a clean audit trail for clients, leadership and security teams.
Trend + audit historySitelemetry keeps authorization, target validation and low-impact behavior in the execution path, not in a disclaimer after it.
Inspect the consoleReal projects require a recorded ownership or explicit-permission attestation before background audits can run.
Private ranges are blocked by default. HTTP targets are revalidated on every redirect hop and pinned to the validated address.
Injection, rate-limit and resilience checks use bounded canaries and small samples. They detect control posture without generating destructive load.
Nmap, Nuclei, ZAP and WPScan run only when configured in operator-managed isolated workers; hosted audits report unavailable engines instead of claiming coverage.
Connect Sitelemetry to Codex and Claude Code without copying API keys. Both clients discover the OAuth server, open browser approval and receive account-scoped access to authorized audit tools.
Sitelemetry replaces the fragmented first pass, not every specialist. It unifies security, technical SEO, AI visibility, accessibility, performance and integration evidence, prioritizes one shared queue and re-audits the same controls after the fix.
Sitelemetry returns prioritized, structured evidence instead of making the agent repeatedly browse, infer and restate the site. Scope, proof, impact, remediation and verification arrive together, reducing exploratory tool calls and context churn. Actual token savings depend on the target and workflow.
Each audit can produce one implementation prompt containing validated findings, relevant evidence, constraints, acceptance criteria and retest steps. Codex or Claude Code gets a bounded repair plan for the full selected scope; human review and safe deployment remain required.
Remote MCP transport is available to every account. Free includes 30 security scans per month across 10 security modules, one project and one seat; Remote MCP exposes its security audit within that allowance. Starter fits one focused property and weekly baselines. Professional adds ten projects, daily monitoring and PDF reports. Enterprise expands to twenty projects, five seats, hourly monitoring, white-label reports and hosted ZAP/WPScan when available. Available audit tools and usage follow account limits.
A focused first look at your site's security posture.
A disciplined baseline for owners and focused web properties.
Deep intelligence for product teams, agencies and security operators.
Expanded capacity and hourly operations for larger security programs.
Annual prices are shown as monthly equivalents and billed annually. Remote MCP transport is available to every account; exposed audit tools and usage follow account limits. External engine availability depends on your deployment.
No automated scanner can guarantee that. Sitelemetry combines evidence-backed automation and coverage matrices with external engines only when hosted workers are available, then makes limitations visible so manual review can focus on business logic and multi-step authorization flaws.
Built-in checks are deliberately bounded. DDoS, brute-force and MITM topics are assessed through configuration, resilience and low-volume signals. External engines remain operator-controlled and should run in isolated workers.
Yes, only when the operator explicitly enables private-target scanning in an isolated deployment. Public SaaS deployments block private ranges by default to prevent SSRF and internal-network abuse.
Critical and high findings carry the most weight, lower severities are capped, and verified controls provide limited compensation. Unreachable or unresolved targets never receive a misleading perfect score.
Create an authorized project, run your first evidence-backed audit and give your team a repair queue they can actually close.
Open Sitelemetry