Capabilities and limits
A clear description of what the product can and cannot tell you.
Attackers are getting faster. RemedyProof helps you detect external security regressions, fix them, and prove the fix—with AI-assisted guidance and deterministic verification.
What RemedyProof does
- Deterministic checks for DNS, TLS certificates, HTTPS behaviour, selected security headers, mail posture, certificate transparency signals, and bounded WordPress metadata.
- Change detection with repeated observation before an alert, so one transient response is not presented as a finding.
- Plain-English, provider-aware remediation guidance that can be assigned to an owner with a due date.
- Verified fixes when the same deterministic rule passes again, with before-and-after evidence attached.
- Client-ready evidence ledgers that preserve the observed result and its content hash.
- On-demand AI-assisted briefs for actionable findings, grounded in the observed facts and reviewed remediation guidance.
Where it stops
- Checks describe what deterministic rules observed at a point in time; they do not prove a website is secure.
- The product does not certify compliance and is not a penetration test.
- Probes are read-only and bounded: no form submission, credentials, exploit payloads, broad crawling, or port scanning.
- A hostname must be explicitly authorized and technically verified before it is contacted.
- AI does not close findings; only a subsequent deterministic rule pass can mark a finding verified_fixed.
- AI briefs are guidance only: they do not run probes, change infrastructure, or replace deterministic verification.
Public Snapshot
Public Snapshot is a one-time, read-only baseline. Its normalized results are retained for seven days, and it does not start recurring monitoring.
Availability and support
- Public B2B signup is open, with the existing per-plan quotas and an initial operating cap of 10 customer organizations or 200 total verified properties before a capacity review.
- One free Public Snapshot is available within the stated quotas; checkout availability is reported separately and does not prove a paid entitlement.
- Support and alerts are monitored by the founder on a best-effort basis. Urgent abuse or security reports are prioritized when noticed. There is no working-hours promise, response-time SLA, or 24/7 commitment.
Current product posture
Gate 4 provides specialist depth for mail posture, certificate transparency, and WordPress metadata while keeping conclusions limited to the inspected surface.
Gate 5 is enabled for one-shot, opt-in curated probes. Its recurring profile and scheduling remain disabled; it is not a general-purpose scanner, and no persisted paid entitlement or ingestion canary is claimed.
Read the crawler methodology or contact RemedyProof.