Security audits with inspectable evidence.
Notra audits your live site and returns a short list of security findings with saved request and response evidence, remediation steps, and plain-English explanations. No security hire required.
Observed from up to 500 most recent completed customer scans; dispute rate from all recorded finding statuses. A dispute rate is not an accuracy measure.
Evidenced
Reported findings include the saved request and response evidence behind the result.
Unsupported signals filtered
Candidates are checked and de-duplicated before reporting; unsupported signals stay out.
Explained
Written so your developer knows what to change, with relevant references where available.
Illustration: a scanner can hand you 800 signals. A handful may survive review.
Synthetic example for explaining the workflow. Not a customer scan or performance claim.
Reported findings carry inspectable evidence.
Notra checks candidate findings against saved request and response evidence before they appear in a report. The workflow filters unsupported signals, while novel or business-logic issues may require human review.
This is the desk you work from.
The verified findings table, sorted by real risk — the same view your team gets after every scan.
- Your siteAny public site
- AuthorizeDNS or file token
- Live scansafe, non-destructive
- Verification gateproof or it's cut
- Verified reportranked, explained, PDF
Nothing runs until you approve it. Four steps, start to finish.
Prove it's yours
Add a DNS record or drop a file. We don't touch your site until you do.
Live scan
We map the site, then run safe checks. Nothing destructive, and you watch it happen.
Evidence checks
Candidates are checked against saved evidence. Unsupported signals stay out of the report.
Evidence report
A ranked PDF with the evidence, severity context, and remediation for each reported finding.
Click a finding, read the request that triggered it.
One finding from the sample audit, with the exact request and response we captured.
$ curl -s https://harborlanterngoods.com/wp-content/plugins/wp-file-manager/readme.txt | sed -n '1,6p' === WP File Manager === Contributors: mndpsingh287 Tags: file manager, wp file manager, filemanager Stable tag: 6.0 Requires at least: 3.0 # 6.0 is < 6.9 -> CVE-2020-25213 (CISA KEV). The elFinder connector is exposed with no auth check. # Notra's benign write probe (create a directory, no shell, no upload): POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1 Host: harborlanterngoods.com Content-Type: multipart/form-data; boundary=----vera7f3a ------vera7f3a Content-Disposition: form-data; name="cmd" mkdir ------vera7f3a Content-Disposition: form-data; name="target" l1_Lw ------vera7f3a Content-Disposition: form-data; name="name" vera_probe_7f3a ------vera7f3a-- HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 {"added":[{"name":"notra_probe_7f3a","hash":"l1_dmVyYV9wcm9iZV83ZjNh","phash":"l1_Lw","mime":"directory","ts":1756142870,"read":1,"write":1,"locked":0}]} # Unauthenticated directory creation succeeded -> the connector accepts commands with no nonce and no login. # Verification gate stopped here. Notra did NOT upload a payload. The empty folder notra_probe_7f3a was left in place # so your team can independently confirm and then delete it.
Every raw signal comes in. Findings with saved evidence ship. The rest go here:
deduped
Same flaw across many paths/params, merged to one.
info-only
Real, but harmless on their own.
unverified
We couldn't reproduce them.
false-positive
False alarms: framework CSRF, ORM "SQLi", bot-blocked 403s.
White-label every audit under your brand. Rechecks are billable, and clients read a plain-English report, no security hire on their side.
One honest answer before you launch: what on your site is actually exploitable today, and exactly what to change to fix it.
Catch a regression before your customers do. Every monitored rescan emails you the current findings, so nothing sits unnoticed between deploys.
Dozens of client sites in one console, white-label PDFs, and a verification gate that means far fewer false-alarm tickets.
Pay per site, not per finding.
Priced per site, per month. Pay yearly and two months are free. Early customers keep launch pricing for a year.
A letter grade in under a minute. No account needed.
- Passive scorecard: TLS, security headers, cookie flags, exposed files, email auth
- Letter grade and one-line plain-English summary
- No account, no card, no domain ownership required
- Results in under a minute
- Save the result and unlock one verified audit trial with a free account
- No verified findings or evidence pack (that starts at Deep Audit)
A full pentest with inspectable evidence. Once.
- Full active scan across every module (CVE xref, XSS, CORS, TLS, headers, exposed files, redirects)
- Every finding passes the verification gate before you see it
- Raw request/response evidence attached to each finding
- Branded PDF + shareable web report, findings explained like a human wrote them
- Unauthenticated deep budget: 360 requests · 60 min · 20-finding target
- Domain ownership required (DNS TXT or file upload) — payment is for the active verified audit only
One domain, watched. New criticals alert you.
- 1 monitored domain — monthly deep audit + daily rescans included
- Diff alerts: new, resolved and regressed findings between scans
- Findings cross-referenced against real NVD + CISA KEV data
- Email report on every rescan
| Capability | Classic scanners | Notra |
|---|---|---|
| Output | Hundreds of raw plugin & version matches | Only the findings we can prove, ranked by real risk |
| Evidence | A version string and a guess | Saved request/response evidence |
| False positives | You triage them | Filtered below a 0.8 confidence floor |
| Deliverable | A CSV of noise | A branded, plain-language PDF |
| Continuous | One-time snapshot | Scheduled rescans with email on every result |
| Who can read it | A security engineer, if you have one | Anyone on the team |
Is scanning my site safe?
Yes. Active probes use safe, non-destructive defaults with a per-target rate ceiling, and money-movement endpoints (cart, checkout, pay) stay untouched unless you agree to a sandboxed test. Every proof is a benign detection probe, never a weaponized exploit.
Do you need my passwords or source code?
No. Notra is black-box by default. It only sees what any visitor sees. Optional authenticated scans (Deep Audit) use a session cookie you paste in, encrypted immediately, used once for that run, deleted the moment it finishes, and called out plainly in the report.
How do you avoid false positives?
The verification gate checks whether a candidate has saved request/response evidence, applies a confidence floor, and de-duplicates signals before reporting. This reduces unsupported findings; it is not a claim of perfect accuracy.
Where do the CVEs come from?
When a component finding is in scope, we fingerprint the stack and cross-reference NVD, CISA KEV, GHSA and OSV with version-range logic. Findings without a relevant CVE are reported with the evidence and references that apply.
What stops someone scanning a domain they don't own?
A hard authorization gate. No active module runs until you prove control with a DNS TXT record or an uploaded file token, and every authorization is logged.
What if a scan fails?
It auto-retries once. If it still fails, it's automatically marked failed and refunded — no ticket to file. You never pay for a scan that didn't deliver.
See what’s actually exploitable.
Run the free scorecard in under a minute — sign in required, passive checks only. Upgrade to a verified deep audit whenever you’re ready.