notra·
AI assisted security auditing

Security audits with inspectable evidence.

Notra audits your live site and returns a short list of security findings with saved request and response evidence, remediation steps, and plain-English explanations. No security hire required.

Hundreds of raw signals in  →  only findings with saved evidence out
https://
Free scorecard in about a minute. Prove you own the domain, and your first verified audit — the kind others charge $3,000 a year for — is on the house.
Notra - Website security audits with evidence you can inspect | Product Hunt
0.0%
reported dispute rate · n=4
14 min
median report time · n=6
8
completed audits observed
Saved evidence
included with each reported finding

Observed from up to 500 most recent completed customer scans; dispute rate from all recorded finding statuses. A dispute rate is not an accuracy measure.

What “verified” means
01

Evidenced

Reported findings include the saved request and response evidence behind the result.

02

Unsupported signals filtered

Candidates are checked and de-duplicated before reporting; unsupported signals stay out.

03

Explained

Written so your developer knows what to change, with relevant references where available.

See how the agent thinks →

Noise vs signal

Illustration: a scanner can hand you 800 signals. A handful may survive review.

Synthetic example for explaining the workflow. Not a customer scan or performance claim.

800 raw signals in
SQL injection (maybe?)Reflected XSS (unconfirmed)jQuery 1.12.4 outdatedDirectory listing?Server header presentDuplicate of #118X-Powered-By exposedMissing HSTS headerTLS 1.1 supportedCookie without Securerobots.txt foundClickjacking?Open redirect?Verbose 404 pageOutdated Bootstrap 3CORS header seenWordPress detectedLogin page foundEmail in HTML sourceMixed contentComment reveals pathDeprecated API in useSame as #204PHP 7.4 (info)+ 776 more
Verification gateCandidates pass saved-evidence checks before reporting.
0.8
confidence floor
12 proven, ranked by real risk
Unauthenticated remote code execution: WP File Manager 6.0 (CVE-2020-25213)KEVcritical· 9.8
Unauthenticated remote code execution: Bricks theme 1.9.5 (CVE-2024-25600)KEVcritical· 9.8
Backup file leaks live Stripe, SMTP and database credentialshigh· 8.6
CORS reflects any origin with credentials enabled on the Store APIhigh· 7.5
Reflected XSS in product filter 'sort_by' parametermedium· 6.1
+7 more, each with its evidence and fix

Reported findings carry inspectable evidence.

Notra checks candidate findings against saved request and response evidence before they appear in a report. The workflow filters unsupported signals, while novel or business-logic issues may require human review.

How the gate decides
Inside the console

This is the desk you work from.

The verified findings table, sorted by real risk — the same view your team gets after every scan.

The pipeline
How verification works

Nothing runs until you approve it. Four steps, start to finish.

01

Prove it's yours

Add a DNS record or drop a file. We don't touch your site until you do.

02

Live scan

We map the site, then run safe checks. Nothing destructive, and you watch it happen.

03

Evidence checks

Candidates are checked against saved evidence. Unsupported signals stay out of the report.

04

Evidence report

A ranked PDF with the evidence, severity context, and remediation for each reported finding.

See the evidence

Click a finding, read the request that triggered it.

One finding from the sample audit, with the exact request and response we captured.

Exhibit · request · responsepassed FP-gate
$ curl -s https://harborlanterngoods.com/wp-content/plugins/wp-file-manager/readme.txt | sed -n '1,6p'
=== WP File Manager ===
Contributors: mndpsingh287
Tags: file manager, wp file manager, filemanager
Stable tag: 6.0
Requires at least: 3.0

# 6.0 is < 6.9 -> CVE-2020-25213 (CISA KEV). The elFinder connector is exposed with no auth check.
# Notra's benign write probe (create a directory, no shell, no upload):

POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1
Host: harborlanterngoods.com
Content-Type: multipart/form-data; boundary=----vera7f3a

------vera7f3a
Content-Disposition: form-data; name="cmd"

mkdir
------vera7f3a
Content-Disposition: form-data; name="target"

l1_Lw
------vera7f3a
Content-Disposition: form-data; name="name"

vera_probe_7f3a
------vera7f3a--

HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8

{"added":[{"name":"notra_probe_7f3a","hash":"l1_dmVyYV9wcm9iZV83ZjNh","phash":"l1_Lw","mime":"directory","ts":1756142870,"read":1,"write":1,"locked":0}]}

# Unauthenticated directory creation succeeded -> the connector accepts commands with no nonce and no login.
# Verification gate stopped here. Notra did NOT upload a payload. The empty folder notra_probe_7f3a was left in place
# so your team can independently confirm and then delete it.
The receipts

Every raw signal comes in. Findings with saved evidence ship. The rest go here:

512

deduped

Same flaw across many paths/params, merged to one.

184

info-only

Real, but harmless on their own.

61

unverified

We couldn't reproduce them.

31

false-positive

False alarms: framework CSRF, ORM "SQLi", bot-blocked 403s.

Fits your workflow
EmailWhite-label PDFREST APICI/CD gateMCP server
Who it’s for
Agencies

White-label every audit under your brand. Rechecks are billable, and clients read a plain-English report, no security hire on their side.

Best on Agency
$499/mo
Solo founders

One honest answer before you launch: what on your site is actually exploitable today, and exactly what to change to fix it.

Best on Deep Audit
$149 once
Eng leads

Catch a regression before your customers do. Every monitored rescan emails you the current findings, so nothing sits unnoticed between deploys.

Best on Monitor / Pro
$49–199/mo
MSP / MSSP

Dozens of client sites in one console, white-label PDFs, and a verification gate that means far fewer false-alarm tickets.

Talk to us
$1k+/mo
Pricing

Pay per site, not per finding.

Priced per site, per month. Pay yearly and two months are free. Early customers keep launch pricing for a year.

Free Instant Scan
$0 / one-time, instant

A letter grade in under a minute. No account needed.

  • Passive scorecard: TLS, security headers, cookie flags, exposed files, email auth
  • Letter grade and one-line plain-English summary
  • No account, no card, no domain ownership required
  • Results in under a minute
  • Save the result and unlock one verified audit trial with a free account
  • No verified findings or evidence pack (that starts at Deep Audit)
Most popular
One-Time Deep Audit
$149 / one-time · standard site

A full pentest with inspectable evidence. Once.

  • Full active scan across every module (CVE xref, XSS, CORS, TLS, headers, exposed files, redirects)
  • Every finding passes the verification gate before you see it
  • Raw request/response evidence attached to each finding
  • Branded PDF + shareable web report, findings explained like a human wrote them
  • Unauthenticated deep budget: 360 requests · 60 min · 20-finding target
  • Domain ownership required (DNS TXT or file upload) — payment is for the active verified audit only
Monitor
$49/mo / per domain

One domain, watched. New criticals alert you.

  • 1 monitored domain — monthly deep audit + daily rescans included
  • Diff alerts: new, resolved and regressed findings between scans
  • Findings cross-referenced against real NVD + CISA KEV data
  • Email report on every rescan
Notra vs the scanners
CapabilityClassic scannersNotra
OutputHundreds of raw plugin & version matchesOnly the findings we can prove, ranked by real risk
EvidenceA version string and a guessSaved request/response evidence
False positivesYou triage themFiltered below a 0.8 confidence floor
DeliverableA CSV of noiseA branded, plain-language PDF
ContinuousOne-time snapshotScheduled rescans with email on every result
Who can read itA security engineer, if you have oneAnyone on the team
Questions
Is scanning my site safe?

Yes. Active probes use safe, non-destructive defaults with a per-target rate ceiling, and money-movement endpoints (cart, checkout, pay) stay untouched unless you agree to a sandboxed test. Every proof is a benign detection probe, never a weaponized exploit.

Do you need my passwords or source code?

No. Notra is black-box by default. It only sees what any visitor sees. Optional authenticated scans (Deep Audit) use a session cookie you paste in, encrypted immediately, used once for that run, deleted the moment it finishes, and called out plainly in the report.

How do you avoid false positives?

The verification gate checks whether a candidate has saved request/response evidence, applies a confidence floor, and de-duplicates signals before reporting. This reduces unsupported findings; it is not a claim of perfect accuracy.

Where do the CVEs come from?

When a component finding is in scope, we fingerprint the stack and cross-reference NVD, CISA KEV, GHSA and OSV with version-range logic. Findings without a relevant CVE are reported with the evidence and references that apply.

What stops someone scanning a domain they don't own?

A hard authorization gate. No active module runs until you prove control with a DNS TXT record or an uploaded file token, and every authorization is logged.

What if a scan fails?

It auto-retries once. If it still fails, it's automatically marked failed and refunded — no ticket to file. You never pay for a scan that didn't deliver.

See what’s actually exploitable.

Run the free scorecard in under a minute — sign in required, passive checks only. Upgrade to a verified deep audit whenever you’re ready.

https://