Free security scan

Find it. Fix it. Prove it.

Run a free, read-only security scan on any Linux server in about a minute. See exactly what's wrong, why it matters, and how to fix it.

  • Read-only — nothing is changed
  • Results in about a minute
  • Secrets stay masked

Free, read-only, no credit card. Deletes automatically after 30 days.

How it works

From command to report in three steps

No signup required to see your score.

1

Paste one command

Run the one-line script on your server over SSH. Review it first — it's just a shell script.

2

We run read-only checks

Dozens of hardening checks across OS, network, web server, SSH and more — nothing is changed.

3

Get your A–F report

See exactly what's failing, why it matters, and the one-click fix if you import it into OpsDeck.

Platform

Everything after the scan

When you're ready to go further, OpsDeck manages the whole fleet — not just one server.

Multi-tenant server management

Bring every client's servers into one dashboard, organised by organisation, environment and client tag.

SSH-based provisioning and remediation blueprints

The OpsDeck Engine provisions stacks and fixes findings over SSH (or our outbound-only agent) with our own declarative Blueprint DSL — no third-party automation tool involved.

Scheduled security audits with A–F scoring

Recurring hardening audits score every server from A to F, with a full history so you can prove drift is fixed, not just flagged.

One-click fixes

Turn a failing check into a queued remediation job in a single click, with a full run log.

Three ways to add a server

Plain SSH connection details, an AWS or DigitalOcean cloud import, or claiming the results of a free scan you already ran.

Activity and audit log

Every mutation — who did what, when, from where — kept for your organisation's retention window.

Role-based access control

Owner, admin, engineer and viewer roles with scoped permissions across the dashboard.

Two-factor authentication

TOTP-based 2FA with recovery codes, optionally required org-wide.

Encrypted secrets storage

SSH keys, passwords and tokens are encrypted at rest and masked everywhere they could otherwise leak — logs, job output, variables.

Metrics and alert rules

CPU, memory, disk and load samples per server, with threshold-based alert rules and notification channels.

Pricing

Simple plans that grow with you

Free

For trying OpsDeck on a couple of servers.

Free

  • Vulnerability scanning
  • Backups

Pro

For startups running a fleet of servers with automation.

$49.00 / month

  • Agent mode
  • Vulnerability scanning
  • Patch management
  • Backups
  • CIS compliance
  • Cloud provisioning

Agency

For agencies and MSPs managing many clients from one dashboard.

$199.00 / month

  • Agent mode
  • Multi-client workspaces
  • Approval workflows
  • PDF audit reports
  • Single sign-on (OIDC)
  • Vulnerability scanning
  • Patch management
  • Backups
  • CIS compliance
  • Cloud provisioning

Enterprise

Self-hosted with SLA. Contact sales.

Custom

  • Agent mode
  • Multi-client workspaces
  • Approval workflows
  • PDF audit reports
  • Single sign-on (OIDC)
  • Vulnerability scanning
  • Patch management
  • Backups
  • CIS compliance
  • Cloud provisioning

FAQ

Common questions

No. Every check is read-only — it reads configuration files, running processes and package versions. It never edits a file, installs a package or restarts a service.

See your server's score right now

Free, read-only, and ready in about a minute.