Capabilities and limits

A clear description of what the product can and cannot tell you.

Attackers are getting faster. RemedyProof helps you detect external security regressions, fix them, and prove the fix—with AI-assisted guidance and deterministic verification.

What RemedyProof does

  • Deterministic checks for DNS, TLS certificates, HTTPS behaviour, selected security headers, mail posture, certificate transparency signals, and bounded WordPress metadata.
  • Change detection with repeated observation before an alert, so one transient response is not presented as a finding.
  • Plain-English, provider-aware remediation guidance that can be assigned to an owner with a due date.
  • Verified fixes when the same deterministic rule passes again, with before-and-after evidence attached.
  • Client-ready evidence ledgers that preserve the observed result and its content hash.
  • On-demand AI-assisted briefs for actionable findings, grounded in the observed facts and reviewed remediation guidance.

Where it stops

  • Checks describe what deterministic rules observed at a point in time; they do not prove a website is secure.
  • The product does not certify compliance and is not a penetration test.
  • Probes are read-only and bounded: no form submission, credentials, exploit payloads, broad crawling, or port scanning.
  • A hostname must be explicitly authorized and technically verified before it is contacted.
  • AI does not close findings; only a subsequent deterministic rule pass can mark a finding verified_fixed.
  • AI briefs are guidance only: they do not run probes, change infrastructure, or replace deterministic verification.

Public Snapshot

Public Snapshot is a one-time, read-only baseline. Its normalized results are retained for seven days, and it does not start recurring monitoring.

Availability and support

  • Public B2B signup is open, with the existing per-plan quotas and an initial operating cap of 10 customer organizations or 200 total verified properties before a capacity review.
  • One free Public Snapshot is available within the stated quotas; checkout availability is reported separately and does not prove a paid entitlement.
  • Support and alerts are monitored by the founder on a best-effort basis. Urgent abuse or security reports are prioritized when noticed. There is no working-hours promise, response-time SLA, or 24/7 commitment.

Current product posture

Gate 4 provides specialist depth for mail posture, certificate transparency, and WordPress metadata while keeping conclusions limited to the inspected surface.

Gate 5 is enabled for one-shot, opt-in curated probes. Its recurring profile and scheduling remain disabled; it is not a general-purpose scanner, and no persisted paid entitlement or ingestion canary is claimed.

Read the crawler methodology or contact RemedyProof.