Active Monitoring
Your agents will ship again this week. A one-off scan tells you what was true when you ran it. This is the same read, running on its own, so the receipt is ready for handoff instead of explained after.
Early access is free and handed out by key, so nobody is charged yet. The prices below are what Active Monitoring will cost when it opens. See the tiers.
Deploy proof
$25one deployment
A verifiable receipt when you hand the site over.
- One read of what is actually being served
- Proof of Read with a public verify link
- Shareable with a client or buyer, no account needed to check it
- Not a subscription and not a cadence
- Does not include ongoing monitoring
Builder
$99per month, unlimited domains
The read keeps running without you.
- Unlimited domains on one account
- Hosts found from each domain, through certificate transparency
- New hosts read as they appear
- Cadence you set, from six hours to monthly
- Read within minutes of a push or pull request, once a repository is watched
- Deploy hook: your release step can start a read
- Findings that only exist across hosts
- False positives you can dismiss, with the reason kept on the record
- A dated record of every read, and Proof of Read on demand
- Receipts a post-market monitoring file can cite (EU AI Act evidence, not compliance)
Enterprise
Customper organisation
Your source never leaves your network.
- Everything in Builder
- Engine runs inside your network
- Findings leave. Source does not
- Self hosted GitLab
- Model integration on your side of the boundary, or none at all
- Named reviewer attestation
Need a free one-off before you ship? That is Ship Read (npm), a different product.
How it runs
- 1Connect one domain. We read certificate transparency and your sitemaps for names under it, then check which still resolve. That is a floor and not an inventory: a host behind a wildcard, a private authority, or off the sitemap never appears.
- 2It reads, on its own. An hourly job takes the projects that are due, on a cadence you set from six hours to monthly, and reads the hosts that have gone longest without one.
- 3You hear only when it matters. A signed webhook, and only when something changed: a new finding, a new host, or a finding that is no longer observable. Silence means it ran and nothing moved. Email and Slack are not built yet.
Nobody stopped reading code on purpose
The volume outran the habit, and it happened to professionals, not beginners.
+31%more pull requests are merged with no review at all, human or agentic, at the teams that adopted AI hardest.Faros AI, 2026 · telemetry from 22,000 developers
48%of professional developers always check AI-written code before committing it. 96% say they do not fully trust it.Sonar, Jan 2026 · 1,100+ professional developers
10.5%of AI-generated code passes a security review, though 61% of it runs correctly.OX Security, 2026
Automations
Six automations can start a read on their own. Each one waits on a short setup step first.
- On a schedule
- Six hours to monthly, per project. An hourly job checks what is due, and a domain nobody has proved control of is never read.
- On a new host
- Discovery stores a subdomain the first time it sees it, and the next run reads whatever has never been read.
- On push
- A push to a repository you watch queues a read, and it runs within minutes. Ten commits at once are one read, not ten.
- On pull request
- The same read, on the branch under review. Nothing is posted on the diff yet, so you get it in the console rather than as a comment.
- On deploy
- Your deploy step calls us with a token, and we read what is actually being served.
- On a new detector
- A new engine version reads your estate again rather than waiting for the cadence, and rather than replaying an old read, because we do not keep your source.
We do not keep your source once a read finishes: it is unpacked, read, and the whole directory is removed, so the redacted report is the only thing that stays. What leaves your machine, and what does not.
Why it works this way
Why unlimited domains, and never per host
One database credential, served from production, staging and dev, with row policies enforced on exactly one of them. No single scan sees that. Products that bill per host make you pay three times to find it, or skip staging and never find it.
Builder is one monthly price for every domain you connect. Hosts under those domains stay free to add, including the ones certificate transparency surfaces later. The moment you hesitate to add staging. because it costs more, we have priced ourselves out of the thing we exist to find.
Deploy proof is the other shape: one receipt for one go-live, not a cheaper way to get the same watch. If you need the read to keep running, that is Builder.
What you get from us running the engine
- Nothing to maintain. No version to bump, no rule set to keep current. The day a detector improves, your next read uses it.
- Detectors come from measured work. Each is scored against a corpus of real applications before it ships, so the list grows on evidence rather than recollection.
- Findings map to published standards. OWASP, a CWE identifier, and the AIUC-1 crosswalk. No score we invented.
- The method is published. What gets read, and how. The engine is deterministic, so anyone can re-run the same check.
What you are buying when we find nothing
Most months, nothing is wrong. You are not buying findings. You are buying the fact that somebody looked, at a stated frequency, on a stated method, and wrote down what they saw. Nobody asks their uptime checker to justify a green week.
What is left is a record: dated, scoped, and repeatable by anyone who wants to check our work. A pile of Seatbelt reports is not proof your app is secure. It is proof you checked.
The standard already puts a number on how often
AIUC-1 is the assurance standard for AI systems. ElevenLabs and Harvey are certified under it. Harvey's certificate is legal-agent assurance, not a scan of coding-agent output. Every requirement in it carries a frequency, printed next to whether it is mandatory.
| Requirement | Applies | Frequency |
|---|---|---|
| A008 Prevent leakage of credentials and secrets | Mandatory | Every 12 months |
| C006 Prevent output vulnerabilities | Mandatory | Every 3 months |
| C008 Monitor AI risk categories | Optional | Every 12 months |
Nobody who writes a standard thinks a control that ran in March is still running in November. What we map to, and the one requirement we refuse to claim.
Where this sits under the EU AI Act
Regulation (EU) 2024/1689 (the AI Act) is in force. Banned practices and general-purpose model duties already apply. Transparency rules for certain systems are live. High-risk operators still need a post-market monitoring trail once those obligations bind them.
Seatbelt is not your AI Act programme. Classification, fundamental rights impact assessments, and CE marking live elsewhere. What we produce is the layer those programmes file evidence into: continuous reads of what is live, and a Proof of Read anyone can verify without an account.
GRC tools own the register and the narrative. The receipt is what proves a read happened after the system shipped.
The Proof of Read
When a buyer asks what your public surface looks like, send a receipt they can verify, not a slide that says you take security seriously.
What it states:
- What was read. The domain, whether you proved control of it, every host found and which of them were actually read, the date, and the engine version that read them.
- All seven risk surfaces. What each one showed, and for the ones a read from outside cannot reach, that it could not reach them. Coverage is stated rather than implied.
- Every finding, and what was dismissed. Named hosts and redacted cues, plus who judged a finding not real and why.
- Named checks this read produced (AIUC-1). Output for four code-relevant requirements. Not certification and not an audit pass.
- A fileable receipt under the EU AI Act. Dated and scoped evidence that a post-market or transparency programme can cite. Not conformity, not a CE mark, and not a claim that the Act is satisfied.
It carries a reference that resolves to a page anyone can open. That page is the point: a document nobody can check is a document anybody can write, which is why there is no seal on it and never will be.
It is not a certificate, not a compliance attestation and not a penetration test, and the document says so in its own body rather than in a footnote. It is signed as a statement that the read happened and that these were its results, which is a thing that can be true. Nobody can sign that software is secure.
What this does not do
- A URL alone reaches two or three of the seven surfaces. Login, payments, customer data and code execution cannot be seen from outside at all, and the ones a URL does reach, it reaches only in part. Connect the repository for the rest.
- No score. A number is honest only if it is calibrated against real loss data, and we have none.
- It reads and reasons. It does not attack. This complements a penetration test rather than replacing one.
- Authorization still needs a human. Whether a route belongs to the person calling it is the review, not the monitor.
- Not a compliance certificate. That comes from a licensed auditor. What you get is the evidence underneath one: a dated record of what was read and what it found, signed as a read performed on your behalf, with a public reference the person you hand it to can check without an account.
For agencies
The urgency is their calendar, not a countdown on this page. Receipt ready before handoff, or you are explaining why it is not.
- Posture at handoff. Deploy proof is a line item for the go-live week: one read of what is live, plus a Proof of Read with a public verify link. Not a pen test. Not a certificate.
- AI relevance without theater. You can say you run an independent read on what agents ship, and hand a verifiable receipt into an EU AI Act monitoring file. You cannot say the app is certified, Act-compliant, or secure. The document refuses that language on purpose.
- One seat, every client domain. Builder is $99 a month with unlimited domains, so staging stays in scope instead of becoming a cost you skip.
Early access is still by key. Pick one real handoff this month and run Deploy proof on it. Leave an address below.
Getting in early
Setup is one field: connect a domain and we find the rest. Early access is free, so a key costs you an address. Leave one and we will send a key back. If you think the price is wrong, say so in the second field, because that is worth knowing before it is set.
