notra·
The Journal

Your fleet, watched between audits.

Scheduled re-seals across 3 domains. We email you only when a seal would break.

Inside the Journal
Alert lifecycle

Every alert follows the same loop.

Monitoring reuses the pipeline behind a one-time live scan and ships results in the same format as the sample report — so a monitored alert and a full audit always agree.

01

Baseline

Your first verified audit records exactly what shipped, at what severity, with evidence.

02

Detect

Scheduled rescans diff the live site against that baseline — new findings, regressions, and resolved issues.

03

Verify

Nothing reaches you raw: every change re-runs the verification gate before it counts as an alert.

04

Re-seal or alert

One email per result with severity, proof, and the fix. Quiet when nothing changed.

Fleet health
harborlanterngoods.comD
2 crit2 high5 med
last verified 2m ago
northwind-supply.coB
2 medall clear
last verified 1h ago
atlas-books.storeC
1 high3 med
scanning…
Diff feed & CVE-watch
critical Bricks theme downgraded to vulnerable 1.9.5
A staging restore reverted the theme from patched 1.9.6.1 back to 1.9.5. The unauthenticated RCE (CVE-2024-25600, CISA KEV) is reachable again right now, this is your top-priority alert.
2 hours ago · 2026-08-25 16:44 UTC
high CVE watch: new advisory matches your Bricks 1.9.5
A newly published Patchstack advisory covers Bricks <= 1.9.6. Your fingerprinted version 1.9.5 is in range. This is in addition to the existing CVE-2024-25600. Update to 1.9.6.1+.
6 hours ago · 2026-08-25 12:31 UTC
medium Regression: TLS 1.1 and 3DES re-enabled
Following a server-block change at 21:40, the endpoint is again offering TLS 1.1 and the 3DES (SWEET32) cipher. The downgrade window you closed on Aug 12 has reopened.
yesterday · 2026-08-24 22:08 UTC
info Resolved: reflected XSS in 'sort_by' no longer reproduces
The Product Filter parameter now HTML-escapes input and the payload no longer executes. Finding VER-2608-05 auto-closed after two confirming re-runs.
yesterday · 2026-08-24 16:52 UTC
high New HIGH since your Aug 20 deploy: exposed .env.bak
/wp-content/uploads/.env.bak returned HTTP 200 for the first time, it was 404 in the previous 6 weekly baselines. The file contains a live Stripe secret and DB credentials. Rotate secrets and delete it.
3 days ago · 2026-08-22 04:10 UTC
Fleet grade trend
2 improving · 1 regressing
CVE watch
4
new CVEs match your fleet this week
Recent changes across the fleet
Bricks downgraded → 1.9.5 (CRITICAL)TLS 1.1 re-enabled on harbor.env.bak appeared → 200XSS in sort_by resolvednew endpoint /wp-json/wc/store
Alerts: Email · threshold Medium+Cadence: Daily
Where monitoring fits

Monitoring is a plan, not a project: pick a cadence on pricing, keep the baseline current after every deploy, and read any alert against the full verified report for that site.

Catch the regression before your customers do.

Scheduled rescans, verified alerts, and an email on every result. Monitoring plans start on the pricing page.

See monitoring plans See a sample report