How the app works

Keep the evidence.
See what changed.

Check a public hostname or import a signed check from one Linux server. Keep the evidence, compare later checks, and export a readable report.

Run a free checkOpen workspace →

The free check needs no account. Create an account, verify your email, then create your own workspace.

From a free check to a useful history

  1. 1. Check one hostname

    Get ten bounded observations. Download the source or save a PDF before leaving; the free result is not stored in an account.

  2. 2. Create your workspace

    Verify your email and create your workspace. To join someone else’s workspace, accept an invitation from its Owner. Add your hostname and explicitly authorize a new check. Your public snapshot is not automatically imported.

  3. 3. Return after a change

    Open the same asset and run again. Compare recorded changes, revisit the original evidence and export a report. Checks run only when you request them.

Choose what to check

Public hostname

External Exposure Check

Observe one public hostname from the outside, after you explicitly authorize a run.

  • Run the current ten bounded observations.
  • Keep attention flags, unknowns and the recorded evidence.
  • Compare saved observations and export reports or PDFs.
Try the free snapshot →

Linux server

One Server Security Check

An authorized operator collects locally on one Linux server. Import the signed source into your workspace.

  • Import a Local Audit 1.2.2 Proofpack ZIP and its matching detached signature.
  • Open findings, collection gaps, evidence and the report.
  • Import a later check to compare; download the original signed files.

Linux setup is operator-assisted. The app does not connect by SSH or run a collector on your server.

Ask about Linux setup →

Ready to keep your checks?

Creating an account and your own workspace is free. Verify your email first; no card is required. An invitation is needed only to join another workspace.

Create an account →

Already have an account? Sign in to your workspace.

External Attack Surface Review: a separate, human-reviewed investigation of one authorized public-facing system, with findings, evidence and a buyer report.

€1,900 · excluding VAT. We agree fit and scope before work begins.

See the review scope →

What this establishes

External Exposure records public hostname observations only. Not a penetration test, complete attack-surface discovery, or security certification. A Clear observation applies to that check, not the security of the whole hostname.

Linux package verification does not establish that a server is secure, uncompromised or compliant. The report is derived; the signed ZIP remains the source.

Saved hostname sources are unsigned. Linux imports retain the signed ZIP and matching detached signature. Product actions and optional feedback help us learn; they are separate from evidence. Automatic retention/deletion is not implemented yet. Data handling

WitnessOps checks and workspace | WitnessOps