Skip to content

Five plans. Chosen after you have seen your own sites.

There is no trial and no public price list. Experience Servertorch on your own sites first, then choose the plan that fits — the price follows what you turn out to need, not the other way round.

  1. Request a demo

    Tell us which sites and what prompted it. No card, no account to abandon.

  2. We set it up with you

    On a call, on your real sites: checks, the agent where it helps, alerts to the right people.

  3. You see your own data

    Your uptime, traffic, attacks, file changes and DPDP findings — not a sample account.

  4. You choose a plan

    The price is agreed then, for the plan you picked. Nothing is charged before.

Starter

A business with a few sites · nothing to install

After your demo priced once you have seen it

Know the moment a site goes down, a certificate is about to expire or a header goes missing — checked from outside, with alerts to email, Slack or Teams.

Sites
3
People
3
History
30 days
Checks every
5 min

Includes

  • TLS certificates
  • DNS monitoring
  • Security headers
  • Blocklist monitoring
  • Privacy readiness (DPDP)
Request a demo

Growth

Small teams · up to 10 sites

After your demo priced once you have seen it

Adds the agent inside your sites: real traffic and visitors, attacks blocked inline, file changes and malware, and Claude's read on every new attack.

Sites
10
People
5
History
60 days
Checks every
1 min

Everything in Starter, plus

  • Traffic analytics
  • IP blocking
  • Attack detection
  • File integrity & malware
  • AI analysis & Nekoba
  • 300 AI analyses a month
Request a demo
Most teams start here

Pro

Teams shipping their own code · up to 25 sites

After your demo priced once you have seen it

Everything in Growth, plus code audit of the GitHub or Bitbucket repositories behind your sites, 30-second checks and six months of history.

Sites
25
People
15
History
180 days
Checks every
30 s

Everything in Growth, plus

  • Code audit
  • 1,500 AI analyses a month
  • 5 code repositories
Request a demo

Business

Agencies and larger estates · up to 100 sites

After your demo priced once you have seen it

For the people responsible for many sites: your brand on the console and client reports, deep code analysis with AI fixes, a year of history and assisted support.

Sites
100
People
50
History
365 days
Checks every
30 s

Everything in Pro, plus

  • Deep code analysis
  • Explain & fix for code
  • White label
  • Assisted support
  • 5,000 AI analyses a month
  • 25 code repositories
Request a demo

Enterprise

Large estates · sized with you

Sized with you

No ceilings on sites or people, two years of history, the largest AI allowance, and an agreement written around how you work.

Sites
Unlimited
People
Unlimited
History
730 days
Checks every
30 s

Everything in Business, plus

  • 20,000 AI analyses a month
Talk to us

Which plan fits?

Four questions. You can change your mind on the call.

Your plan

Starter

Every plan, side by side.

Every teammate gets a login on every plan, and alerts are never a premium feature. The plans differ in how deep Servertorch goes and how much of it you get.

Show plan
Plans compared: included modules and limits
Plan Starter A business with a few sites · nothing to install Growth Small teams · up to 10 sites Most teams start here Pro Teams shipping their own code · up to 25 sites Business Agencies and larger estates · up to 100 sites Enterprise Large estates · sized with you Sized with you
Price after you've seen it on your own sites. Request a demo Request a demo Request a demo Request a demo Talk to us
LimitsHow much of it you get
Monitored sites 3 10 25 100 Unlimited
Team members 3 5 15 50 Unlimited
Data retention 30 days 60 days 180 days 365 days 730 days
Fastest check interval 5 min 1 min 30 s 30 s 30 s
AI analyses per month – 300 / mo 1,500 / mo 5,000 / mo 20,000 / mo
Live attack analyses per site per hour – 2 new / h 2 new / h 4 new / h 6 new / h
Code repositories – – 5 25 Unlimited
MonitoringWhat we check from the outside, with no agent.
Uptime & response timeAvailability checks, response time, incidents and email alerts.
TLS certificatesCertificate validity, chain, expiry warnings and grade.
DNS monitoringRecord inventory and alerts when records that route traffic or mail change.
Security headersHeader audit with a score and exact fixes.
Blocklist monitoringChecks the site against spam and malware blocklists, including Safe Browsing.
Origin exposureDetects the CDN or proxy in front of the site and whether the origin server is exposed. –
Agent insightWhat the agent inside the site reports.
Traffic analyticsEvery request: visitors, pages, referrers, live view and server errors. –
Stack & vulnerabilitiesInventory of the server, CMS, plugins and packages, matched against known vulnerabilities. –
Server posturePHP configuration, file permissions and (for WordPress) database hardening checks. –
SecurityDetection and blocking.
Attack detectionThe request firewall inside the site records SQL injection, XSS, scanners and brute force. –
IP blockingBlock addresses from the evidence, and let the firewall refuse attacks rather than only record them. –
File integrity & malwareHashes the site's code, flags changed and added files and scans them for malware. –
Privacy readiness (DPDP)Data-protection readiness checks with fix steps for each finding.
Code auditScanning the code a monitored site is deployed from.
Code auditConnect GitHub or Bitbucket and scan the repository each monitored site is deployed from, with built-in rules. – –
Scheduled code scansScan tracked branches daily or weekly without anyone pressing a button. – –
Scan on pushA GitHub or Bitbucket webhook queues a scan whenever a tracked branch is pushed. – –
Deep code analysisAdds Semgrep, Gitleaks and npm audit to the built-in rules and Composer advisories. – – –
Explain & fix for codeAn AI explanation and suggested fix for one code finding. Also needs AI analysis. – – –
Intelligence & reportingExplanations and scheduled summaries.
AI analysis & NekobaAI triage of suspicious files, "Explain & fix" and the Nekoba assistant. –
ReportsPer-site reports for any period, as a page or download, and scheduled report emails.
Account & integrationsPeople, integrations and branding.
API accessAPI tokens and bearer-token access to the JSON API. –
Slack, Teams, Telegram & webhooksSend alerts somewhere other than email.
Team membersInvite people beyond the account owner, with roles.
White labelYour own brand colour and logo on the console and reports. – – –
Assisted supportGrant our staff time-boxed access to look at your data with you. – – –

“Unlimited” means no limit is set on the plan. Limits can be raised for an account without changing plan — ask on the call. More than a hundred sites, or an estate that fits none of these? Tell us about it and we will size it.

Before you buy: what works on your hosting.

Most small businesses are on shared hosting or a website builder, and they do not let us see everything. Here is exactly what works where — and the free check tells you which one your site is.

Your own server or VPS

DigitalOcean, AWS, Hostinger VPS, any Linux or Windows server

  • Uptime, SSL, DNS, headers, blocklists Yes
  • Every visit and visitor Yes
  • Attacks seen and blocked Yes Blocked inside the app before your code runs — by the guard for your stack, the WordPress plugin, or the PHP agent's request file.
  • File changes and malware Yes
  • Server CPU, memory and disk Yes Your machine's own CPU, memory, disk and load.

Everything Servertorch does works here.

Shared hosting, with an access log

Most cPanel, hPanel, Plesk and DirectAdmin plans

  • Uptime, SSL, DNS, headers, blocklists Yes
  • Every visit and visitor Yes
  • Attacks seen and blocked Yes Seen in the log within a minute, and blocked inside PHP once the agent's small request file is switched on (one click on the Agent tab). Requests for plain files such as images are answered before PHP runs — seen, not blocked.
  • File changes and malware Yes
  • Server CPU, memory and disk Shared machine Your account's disk use is yours. CPU, memory and load are the whole shared server's, used by other customers too — a useful trend, not your site's own usage.

Nearly everything works here. Server CPU and memory are the shared machine's, not yours alone.

Shared hosting, no access log

Hosts that keep no per-site log, or do not let you read it

  • Uptime, SSL, DNS, headers, blocklists Yes
  • Every visit and visitor Pages only Our request recorder logs every request that reaches PHP. Pages your host serves from its cache, and images, CSS and JS, never reach PHP — so visit counts read lower than reality, often by half or more on a cached WordPress site. Optional: paste our visitor script (two minutes, nothing else changes) to count cached pages too — or, if the site is on Cloudflare, add our worker for everything.
  • Attacks seen and blocked At PHP Attacks on pages, logins and forms reach PHP and are seen and blocked. Anything your host's own firewall stops first is not seen — it was stopped anyway.
  • File changes and malware Yes
  • Server CPU, memory and disk Shared machine Your account's disk use is yours. CPU, memory and load are the whole shared server's, used by other customers too — a useful trend, not your site's own usage.

Most things work here. Visit counts only include requests that reach PHP, so they read lower than reality.

Static or edge hosting

Vercel, Netlify, Cloudflare Pages, GitHub Pages

  • Uptime, SSL, DNS, headers, blocklists Yes
  • Every visit and visitor Via log drain With a log drain from Vercel, Netlify or Cloudflare: counted a few seconds after the fact.
  • Attacks seen and blocked At the edge Blocked at the edge by the edge guard (Cloudflare Worker, Vercel or Next.js middleware, Netlify Edge Function). A plain GitHub Pages site has no edge to put it on.
  • File changes and malware No server There are no server files to watch. Code audit covers your repository instead.
  • Server CPU, memory and disk No server There is no server of yours to measure.

Outside checks, edge blocking and code audit work here. There is no server for file or resource monitoring.

Website builders

Wix, Shopify, Squarespace, Webflow, GoDaddy Website Builder

  • Uptime, SSL, DNS, headers, blocklists Yes
  • Every visit and visitor No Website builders do not let anything be installed. Use the builder's own analytics.
  • Attacks seen and blocked No The builder runs its own firewall in front of every site; nothing of ours can sit there.
  • File changes and malware No The builder owns the files.
  • Server CPU, memory and disk No The builder owns the servers.

Only the outside checks work here — nothing can be installed on a website builder. The Starter plan covers everything that works; a bigger plan would pay for features this site cannot use.

How the AI allowance works.

Claude explains attacks and findings; it never stands between an attacker and your site. Blocking and alerting run on our own rules, on every plan, with no allowance to run out.

0

Blocking an attack

The firewall decides in the request, and you are alerted in about a tenth of a second. No AI involved, never counted.

1

Claude reads a new attack

What it was after, whether it worked and what to do on your stack — about twenty seconds later. The same pattern coming back within a week is linked to that read for free.

1

A question or a file

Asking Nekoba something, or having a suspicious changed file assessed. A file seen before is answered from memory, free.

5

A deep analysis

A larger model, on request, for the finding that matters. Five because it is the one you should think about asking for.

If an allowance runs out, everything keeps working — attacks are still blocked and alerted instantly; only the written explanations pause until the 1st. The allowance can be raised without changing plan.

In every plan, including the smallest.

Not upsells. A monitoring product that puts alerting behind a higher tier is selling a dashboard.

  • Alerts that reach a person. Severity routing, quiet hours and repeat collapsing, so thirteen notifications about one outage arrive as one that says thirteen.
  • DPDP readiness, rechecked weekly. An email only when something actually changed. Findings and fixes, never a compliance verdict.
  • Reports you can send on. Uptime, incidents and security for any period, as a page or a download.
  • Proper GST invoices. CGST and SGST within the state, IGST across it, zero-rated for exports, with a printable copy for your accountant.

Questions people ask about this.

Why don't you publish prices?

Because what an estate costs to watch properly depends on things neither of us knows yet: how many sites, how often they need checking, whether the agent goes on them, how long history has to be kept. We would rather you experience Servertorch on your own sites first and then choose — it is all about the price being right for what you actually need.

Is there a free trial?

No. A trial on a sample site tells you very little, and an account nobody set up is worse than none because it looks like cover. Instead we set it up on your real sites with you, and you see your own data before deciding anything.

What happens on the demo call?

We look at your sites before it, so it starts with findings: expiring certificates, missing headers, trackers firing before consent. Then we add your sites, put the agent where it earns its place and route alerts to the right people. You leave with a working account.

My site is on shared hosting. Will it work?

Mostly, and we will tell you exactly how much before you pay. Uptime, certificates, headers, file changes and attack blocking all work. Where your host keeps an access log, every visit is counted. Where it does not, our small request recorder counts every visit that reaches PHP — but pages your host serves from its cache, and images, never reach PHP, so visit numbers read lower than reality. Server CPU and memory on shared hosting are the whole machine's, not yours alone. On a website builder such as Wix or Shopify, only the outside checks work, and we will tell you Starter is enough.

What counts as an AI analysis?

One Claude read of a new attack, one Nekoba question, or one suspicious file assessed — each is one. A deep analysis is five. Blocking and alerting never count, and an attack pattern Claude already read for that site in the last week is linked to that read for free.

When am I charged?

Only after you have seen your own sites in it and agreed a plan. Invoices carry GST worked out correctly for your place of supply.

Can I change plan later?

Yes. Limits can move without a new contract, and a plan change takes effect on the account straight away — the console enforces whatever the current plan says.

Does every teammate need a paid seat?

No. Plans set how many people can have a login, and nobody pays per seat — charging per seat is how the person who would have seen the alert gets removed to save money.

What no plan includes.

Worth knowing before a call rather than after a month.

  • No SMS or phone calls yet. Alerts go to email, Slack, Teams, Telegram and webhooks. If someone must be woken by a ringing phone, we are not the whole answer yet.
  • No application tracing. We measure what a request cost and what the server was doing; we do not profile your code.
  • No log aggregation. We read your access log for traffic and attacks. It is not a place to ship application logs.
  • Compliance findings are not legal advice. Every readiness line is something observed from outside your site; the verdict stays with your lawyer.

Start with your own sites.

Run the free readiness check on a domain you own, or skip straight to the demo.

No tracking cookies here

We only use the cookies needed to sign you in and keep forms safe — no analytics, no ads, nothing to accept.

Cookie notice