Know when your site breaks, and why.
Servertorch watches the websites you are responsible for — uptime, certificates, traffic, attacks and file changes — and explains every alert in plain words. From the outside with nothing installed, and much deeper with a guard built for your stack: PHP, Node.js, Python, .NET, Java, Go, Ruby, or at the edge for static React and Angular sites.
No trial and no card. We set Servertorch up on your own sites with you, you see your own data, then you choose a plan.
The console, replaying an example incident. Example data.
A minute inside the console.
Recorded in the real product with demo data, not mocked up. The fleet, one shop's uptime and traffic, the attacks it blocked, a web shell the integrity scan caught, the incident that explains a 14-minute outage, and what the plan includes.
How much it sees is up to you.
Add an address and Servertorch starts checking it from the outside within a minute, the way a visitor or a regulator would see it. Nothing to install.
Add the guard for your stack (a PHP file, or a package for Node.js, Python, .NET, Java, Go or Ruby) and it also sees what only the server knows: load, every request with the real visitor IP behind Cloudflare, attacks blocked at the site, and every file that changed. A WordPress plugin adds plugin and theme inventory.
The agent never runs as root and never needs SSH. You can read it before it goes anywhere.
- Availability Up, 212 ms, checked 12 s ago
- Certificate Valid, 58 days left, chain complete
- DNS No record changes in 30 days
- Security headers Grade A, one header missing, with the line that adds it
- Blocklists Clean on every list we check
- Server CPU 23%, memory 42%, disk 61%, inodes fine Not visible from outside
- Traffic 1,284 requests today from 312 people, 97 bots Not visible from outside
- Attacks 42 blocked today, mostly brute force on the login page Not visible from outside
- Files One web shell in uploads/, two changed files since Tuesday Not visible from outside
- Stack PHP 8.2, WordPress 6.6, three plugins with known vulnerabilities Not visible from outside
Example values for one shop.
No trial and no price list. Your own sites first.
A trial on a sample site tells you very little. So we set Servertorch up on the sites you actually run, with you, and you choose a plan once you have seen your own data.
-
Request a demo
Tell us which sites, where they are hosted and what prompted it. Two minutes, no card.
-
We set it up with you
On a call, on your real sites: checks, the agent where it helps, and alerts to the right people.
-
You see your own data
Uptime, traffic, attacks, file changes and DPDP findings from your sites, not a demo account.
-
Then you choose a plan
Sized to what you now know you need. Nothing is charged before you have seen it working.
“We want you to experience it first, then choose a plan. Pricing should follow what you need, not come before you know it.”
Compare what each plan includes On shared hosting or a site builder? See what works there first.
Everything it does, in one console.
Each module has a page of its own with the evidence behind the summary. No score without the reason for it.
Monitoring
What we check from the outside, with no agent.
- Uptime & response time
- TLS certificates
- DNS monitoring
- Security headers
- Blocklist monitoring
- Origin exposure
Agent insight
What the agent inside the site reports.
- Traffic analytics
- Stack & vulnerabilities
- Server posture
Security
Detection and blocking.
- Attack detection
- IP blocking
- File integrity & malware
- Privacy readiness (DPDP)
Code audit
Scanning the code a monitored site is deployed from.
- Code audit
- Scheduled code scans
- Scan on push
- Deep code analysis
- Explain & fix for code
Intelligence & reporting
Explanations and scheduled summaries.
- AI analysis & Nekoba
- Reports
Account & integrations
People, integrations and branding.
- API access
- Slack, Teams, Telegram & webhooks
- Team members
- White label
- Assisted support
Is your website ready for India's DPDP Act?
Which trackers fire before anyone consents, whether a grievance officer is named, whether your forms record what people agreed to. Free, no sign-up, about fifteen seconds — findings and fixes, never a compliance verdict.
We request your home page and privacy notice the way any visitor would. We do not scan for vulnerabilities, log in, or change anything.
A website check sees the front door. The personal data lives in your code.
Aadhaar numbers saved in plain text, phone numbers in log files, an account nobody can delete, a payment key committed by mistake — none of it is visible from outside. Code audit reads your repository and lists every gap, mapped to the DPDP Rules, with the fix.
What it found
database/seeders/demo_users.sql · Rule 6(1)(a)Customer.php:42 · aadhaar_number · Rule 6(1)(a)KycController.php:88 · phone, email · Rule 6(1)(c)routes/web.php · Section 8(7) · Rule 8config/logging.php · 14 days · Rule 6(1)(e)PaymentGateway.php:12 · rzp_live_•••• · Section 8(5)What a scan looks like. The repository is illustrative; the checks and their wording are the real ones.
- Every personal-data field, found Aadhaar, PAN, phone, email, bank, health and biometric fields — where they are stored, logged and sent.
- Mapped to the DPDP Rules and GDPR Each finding names the obligation it breaks — safeguards, retention, erasure, rights — and the penalty band.
- The fix, not just the problem A plain-language explanation and a code-level fix for each gap, so a developer can start the same day.
- Security leaks too SQL injection, secrets committed to the repo, vulnerable packages — the breaches that turn into ₹250 crore questions.
- A report you can hand over Download the full list as CSV, JSON or a printable report for your auditor, board or client.
- Checked again on every push New gaps reach you by email; fixed ones close by themselves. Your evidence of “we were watching”.
Website check — free
- Privacy notice and grievance contact
- Consent banner and trackers before consent
- Forms that collect data without a consent record
- HTTPS and security headers
Code audit — the part only your code can show
- How Aadhaar, PAN, health and bank data is stored — encrypted or not
- Personal data leaking into logs, URLs and third-party SDKs
- Whether people can see, export and delete their data (Rules 8 and 14)
- Log retention, breach detection and vulnerable packages
-
1
Connect
Give read-only access to the repository on GitHub or Bitbucket. Two minutes.
-
2
Scan
We read the code on our server. The copy is deleted when the scan ends.
-
3
Fix
Get the list with fixes and rule references — and walk through it with us on a call.
Why not wait
221 days to 13 May 2027
Penalties reach ₹250 crore for failing to protect personal data. Website fixes take an afternoon; code fixes take sprints — the earlier you have the list, the calmer May is.
A 30-minute call; we run the first scan with you. No card, nothing to install.
Read-only access · the code copy is deleted after each scan · findings show masked values, never full numbers · a list of gaps and fixes, not a legal opinion or a compliance certificate.
What it does not do.
Worth knowing before a demo rather than after a month.
- It does not fix things for you. It tells you a file changed, what changed in it and when. Restoring it is your call.
- It is not a CDN or an edge WAF. The firewall runs inside your site, on your server, and refuses the request after it arrives.
- It checks from one probe location. It tells “down” from “slow”, not “slow in Sydney”.
- It does not keep visitor data forever. Traffic and security records follow your retention setting, 30 days by default.
See it on your own sites.
Send us the list. We will come to the call having already looked at them, so it starts with findings rather than a pitch.