Glarion

The client finds out when the site stops loading.

A certificate expires on a date somebody could have known about six weeks earlier. Glarion watches the sites you look after and writes to you only when something changes.

No account, no email. This reads only what the site already publishes to every visitor.

Why this exists

Running the scanner is the easy part.

The open-source tools are free and good. Point one at a client site and it returns thirty-odd findings, most of them informational, none of them in an order. That output is not something you can put in front of the person paying you.

Deciding what matters is the work.

Glarion re-ranks everything against what it means for a live business — a missing content policy is informational to a scanner and serious to us — then splits it into what to fix, what to look at, and what is merely on record. A real scan of thirty-two findings came out as three things to do.

Priced for a portfolio, not a project.

Tools in this category charge per application, from about ninety dollars each. That is a sensible price for a company with one product and an absurd one for an agency looking after twenty client sites. One subscription here covers all of them.

The report has your name on it.

Findings come out as a numbered worklist with a plain-English reason and a fix, under your agency's name and logo, printable to PDF. It is written for the client to read, not for the person who ran the scan.

What the client receives

Weekly security review
Northstar Studio · example.com
Sanitised sample
3Actions to take
2Items to review
27Checked, no action
01
Renew the TLS certificateExpires in 18 days · owner: hosting provider
Fix
02
Add a content security policyReduces the impact of injected browser code
Review
03
Ownership remains verifiedDNS proof rechecked before the scheduled scan
Clear
  • A worklist, not raw output.Every finding includes the business reason, the next action and enough context to assign it.
  • Your identity stays in front.Paid reports carry your agency name and logo, ready to print or save as PDF.
  • Nothing is staged for this preview.The layout mirrors the report model used by Glarion; the client and domain above are deliberately fictional.

Trust, in verifiable terms

Ownership before active scanning
DNS or hosted-file proof is required and checked again before every scheduled scan.
Constrained scanning
Tools and templates are allowlisted; attacking tags, callbacks and private-network targets are refused.
Change-focused reporting
Weekly monitoring surfaces what changed instead of making clients reread the same inventory.
Tested release gates
Backend, frontend, formatting and static-route checks run before production deployment.

The arithmetic

Twenty client sites.

Per year Glarion Priced per application
Twenty sites, monitored weekly €750 €20,000 +
What you can bill for one audit ~€300 ~€300
Audits before it has paid for itself 3 67

The monitoring is the part you resell. A one-off audit is a job; a site that is watched every week, with a note when something changes, is a retainer.

Pricing

Create an account The free plan does not ask for a card.

What we will not do

A full scan probes: it requests paths a site never advertised and tries known vulnerability fingerprints against them. Doing that to a domain uninvited is the thing computer-misuse law was written to describe.

So Glarion will not run one until the domain's owner has proved control of it, by DNS record or by a file on the host. The proof expires and is re-checked before every scheduled scan, because domains change hands. A scanner that points itself anywhere on request is a different product, and we would rather refuse the work than be it.

The check at the top of this page is exempt for a reason that survives scrutiny: it reads only what the site broadcasts to every visitor and to every search engine. Nothing is probed, no path is guessed.