Your website has problems
you can't see from the outside.

VigiLayer scans it, finds them, and explains each one the way a person would, not the way a security tool would.

  • Scans your certificates, security headers, DNS, email records and uptime
  • Translates every finding into plain English, with the exact fix
  • Emails you the moment something changes, day or night
One website free, forever. No card needed.

Nobody is going to target your bakery. That's not how this works anymore.

Attacks are automated. Software crawls the entire internet looking for the same handful of weaknesses, and it does not check how big you are first.

51%

of all web traffic is now bots, and roughly 37% of it is malicious. Your site is being probed whether or not anyone has heard of you.

Imperva, 2025 Bad Bot Report
30-90

days is how long a website compromise typically goes unnoticed by its owner. By the time something looks wrong on screen, it has been wrong for months.

Industry incident-response averages, 2026
96%

of WordPress vulnerabilities come from plugins and themes, not WordPress itself. Every plugin you installed and forgot is a door someone else maintains.

Patchstack vulnerability data

more confirmed breaches hit small and mid-sized businesses than large organisations. Small is not the same as safe.

Verizon Data Breach Investigations Report, 2025

So the question isn't whether something will go wrong with your website. It's whether you'll find out from a dashboard, or from a customer who couldn't check out.

Certificate renewals just got three times more frequent

The CA/Browser Forum voted in 2025 to shorten how long certificates stay valid. Since 15 March 2026 the maximum is 200 days, down from 398. It halves again to 100 days in March 2027, and reaches 47 days by 2029.

If renewing was a once-a-year thing you vaguely remember doing, it is about to happen three or four times a year. Every one of those is a chance to forget. Forgetting looks like a browser warning on your checkout page.

CA/Browser Forum Ballot SC-081v3

What VigiLayer watches

Every check is passive. Nothing here touches your site's data, slows it down, or asks you to take anything offline.

Certificates

Validity, strength, and the expiry date nobody wrote down anywhere.

Security headers

The browser-level protections most sites are missing without knowing.

Uptime and speed

Outages and slow responses, tracked so you see the pattern, not just the moment.

Domain and DNS

Misconfigurations, plus the domain renewal date that has ended businesses.

Email security

SPF, DKIM and DMARC, so nobody can email your suppliers pretending to be you.

Reputation

Malware flags and blacklist warnings, ideally before your customers meet them.

Four steps, then you can stop thinking about it

Setup takes about five minutes, most of which is waiting for DNS. After that VigiLayer runs on its own and only interrupts you when something has actually changed.

01

Add the website you look after

Type the domain. That is the whole step. No plugin to install, no code to paste into your theme, nothing that can break a site already working fine.

domain harbourbakery.co.uk
status awaiting verification
02

Prove the site is yours

One TXT record to paste into your DNS settings. This is the part that keeps us honest: no deeper checks run on any domain until its owner proves control. We ask two independent DNS providers and only accept it when both agree.

host _vigilayer
value vigilayer-verification=…
check both resolvers agree
03

Read your score, in plain English

Not a wall of raw output. Each finding says what is wrong, how serious it is, and the specific thing to change. "Missing HSTS header" becomes a sentence about someone on public wifi being sent to a fake copy of your site.

score 72 / 100
issue cert expires in 6 days
fix renew in your host panel
04

Get told before your customers notice

VigiLayer rechecks on a schedule and emails you when something changes: a certificate nearing expiry, a header that vanished in last night's update, a site that stopped answering at 3am on a Sunday. The alert is the product. Everything else is how we know when to send it.

14:02 all checks passed
03:11 site unreachable
03:12 email sent to you

The situations this is built for

VigiLayer is new, so rather than invent reviews, here are the real failures it exists to catch.

Placeholder section. These are illustrative scenarios, not customer quotes. Swap them for genuine testimonials once you have beta users, with real names and roles.
"The certificate on our booking page expired over a bank holiday weekend. We found out on Tuesday, from a customer who could not check out. Three days of bookings, gone."
Illustrative scenario
Small hospitality business
"We manage 40 client sites. Checking them used to mean 40 tabs and squinting at padlock icons. Now it is one dashboard and I only look at what changed."
Illustrative scenario
Web development agency
"Someone spoofed our domain and emailed our suppliers asking them to change bank details. We had no DMARC record. I did not know what a DMARC record was."
Illustrative scenario
Independent retailer

Cheaper than one bad weekend

Start free with one website. Move up when you are responsible for more than you can keep in your head.

Free
$0
One website, manual scans, and your full list of findings. Enough to know where you stand.
Get started
Pro
$19/mo
Daily automatic scans, email alerts the moment something changes, and detailed reports.
Get started
Agency
$79/mo
Every client site in one dashboard, with branded reports you can send on as your own work.
Get started
One-time audit
$49
A single branded assessment you can download, hand to a client, or keep on file.
Get started

Find out what your website is telling the internet.

Verification takes about five minutes. Your first scan runs the moment it clears, and you will know more about your site in ten minutes than you have all year.

Scan my website free