Agent-Native Web Assurance

Sitelemetry

Read every signal your site emits. Act on what matters.

Security, search, AI visibility, accessibility and performance telemetry in one evidence-backed control plane.

Safe probes by default Evidence attached Protected scans require authorization
https://sitelemetry.com / continuous audit Live product preview
Unified posturesitelemetry.com
Audit complete
87Health
Security92
SEO84
AI visibility76
Accessibility95
Priority evidence04
CSP policy driftscript-src allows unsafe-inlineHigh
Citation surface gap12 prompts lack owned answersAI
Schema entity mismatchOrganization sameAs incompleteMedium
TLS posture verifiedTLS 1.3 + HSTS observedOK
NmapNucleiOWASP ZAPWPScanPageSpeedSearch ConsoleWCAG 2.2OSCP / OSWE / TSE coverage

Turn every web signal into evidence.

Security posture, search integrity and AI discoverability share the same pages, infrastructure and business context. Sitelemetry reads them together, while keeping every finding independently verifiable.

Security posture92/100
Strong controls, two gaps

TLS, headers, exposure, ports, identity and safe injection canaries are correlated into one evidence set.

Verified controls34+8 since baseline
Attack surface11ports + endpoints
Priority findings02no critical findings
Evidence confidence96%direct observation
Observed signalStateEvidenceAction
Content-Security-PolicyHighunsafe-inline observedHarden policy
TLS protocol and certificateVerifiedTLS 1.3, trusted chainMonitor
Public management surfaceMedium/wp-json user routeRestrict route
SQLi canary responseStableNo error or 5xx deltaRetest nightly

A finding is only useful when your team can close it.

Every result carries the context needed to decide, repair and prove the repair. That makes Sitelemetry operational, not ornamental.

01 / Observe

Evidence before severity.

Endpoint, response, certificate, port, header or crawl signal is attached to the finding. Your team sees what the score saw.

Reproducible context
02 / Repair

Fix instructions at engineering depth.

Impact, exploit narrative, guardrail and implementation guidance are written for the people who will actually ship the repair.

AI-ready remediation prompt
03 / Verify

Retest the control, not the checkbox.

Run the same evidence path again, compare score history and keep a clean audit trail for clients, leadership and security teams.

Trend + audit history
27Security modules
6Web intelligence pillars
4External engine adapters
1Evidence-backed posture

Security tooling should not become the risk.

Sitelemetry keeps authorization, target validation and low-impact behavior in the execution path, not in a disclaimer after it.

Inspect the console
01

Authorization gate

Real projects require a recorded ownership or explicit-permission attestation before background audits can run.

Scope first
02

SSRF and redirect controls

Private ranges are blocked by default. HTTP targets are revalidated on every redirect hop and pinned to the validated address.

Safe fetch
03

Low-intensity adversarial signals

Injection, rate-limit and resilience checks use bounded canaries and small samples. They detect control posture without generating destructive load.

Bounded
04

Isolated engine adapters

Nmap, Nuclei, ZAP and WPScan run only when configured in operator-managed isolated workers; hosted audits report unavailable engines instead of claiming coverage.

Observable

One endpoint. Native OAuth for Codex and Claude Code.

Connect Sitelemetry to Codex and Claude Code without copying API keys. Both clients discover the OAuth server, open browser approval and receive account-scoped access to authorized audit tools.

Codex · OAuthClaude Code · OAuthClaude.aiCursorOAuth 2.1 + PKCEStreamable HTTP
GUIDE / CODEX + CLAUDE Read the MCP setup guide
oauth gateway / sitelemetry
01
CodexOPENAI CLIOAuth ready
codex mcp add sitelemetry --urlhttps://sitelemetry.com/mcpcodex mcp login sitelemetry
registerbrowser approvalconnected
02
Claude CodeANTHROPIC CLIOAuth ready
claude mcp add --transport http sitelemetryhttps://sitelemetry.com/mcp/mcp → Authenticate Sitelemetry
discoverPKCE approvalconnected
account scope verifiedauthorized tools 7 availabletoken storage client managedstatus ready

Why choose Sitelemetry over separate audit tools?

Does Sitelemetry replace separate security, SEO and AI-readiness tools?

Sitelemetry replaces the fragmented first pass, not every specialist. It unifies security, technical SEO, AI visibility, accessibility, performance and integration evidence, prioritizes one shared queue and re-audits the same controls after the fix.

How does Sitelemetry reduce MCP token usage?

Sitelemetry returns prioritized, structured evidence instead of making the agent repeatedly browse, infer and restate the site. Scope, proof, impact, remediation and verification arrive together, reducing exploratory tool calls and context churn. Actual token savings depend on the target and workflow.

What does the agent-ready fix prompt contain?

Each audit can produce one implementation prompt containing validated findings, relevant evidence, constraints, acceptance criteria and retest steps. Codex or Claude Code gets a bounded repair plan for the full selected scope; human review and safe deployment remain required.

Which Sitelemetry plan fits my team?

Remote MCP transport is available to every account. Free includes 30 security scans per month across 10 security modules, one project and one seat; Remote MCP exposes its security audit within that allowance. Starter fits one focused property and weekly baselines. Professional adds ten projects, daily monitoring and PDF reports. Enterprise expands to twenty projects, five seats, hourly monitoring, white-label reports and hosted ZAP/WPScan when available. Available audit tools and usage follow account limits.

Choose your operating depth.

00 / Free

Free

A focused first look at your site's security posture.

$0/ month
  • 30 security scans per month
  • 10 security modules
  • 1 project and 1 seat
  • Remote MCP security access
Start free
01 / Starter

Starter

A disciplined baseline for owners and focused web properties.

$49/ month
  • 1 monitored project and 1 seat
  • Passive and baseline security profiles
  • Security, SEO and AI visibility
  • JSON exports and weekly monitoring
Start with Starter
03 / Enterprise

Enterprise

Expanded capacity and hourly operations for larger security programs.

$249/ month
  • 20 projects and 5 seats
  • All profiles; hosted ZAP and WPScan when available
  • Hourly monitoring and expanded limits
  • White-label reports and highest MCP capacity
Start with Enterprise

Annual prices are shown as monthly equivalents and billed annually. Remote MCP transport is available to every account; exposed audit tools and usage follow account limits. External engine availability depends on your deployment.

Before you scan.

Can Sitelemetry find every vulnerability?

No automated scanner can guarantee that. Sitelemetry combines evidence-backed automation and coverage matrices with external engines only when hosted workers are available, then makes limitations visible so manual review can focus on business logic and multi-step authorization flaws.

Does it run destructive attacks?

Built-in checks are deliberately bounded. DDoS, brute-force and MITM topics are assessed through configuration, resilience and low-volume signals. External engines remain operator-controlled and should run in isolated workers.

Can I audit local or private environments?

Yes, only when the operator explicitly enables private-target scanning in an isolated deployment. Public SaaS deployments block private ranges by default to prevent SSRF and internal-network abuse.

What makes the score trustworthy?

Critical and high findings carry the most weight, lower severities are capped, and verified controls provide limited compensation. Unreachable or unresolved targets never receive a misleading perfect score.

Turn invisible signals into action.

Create an authorized project, run your first evidence-backed audit and give your team a repair queue they can actually close.

Open Sitelemetry