Skip to content
Sign In Create account
Website protection

Most sites are cleaned after somebody else notices.

Five kinds of scan — files, FTP, the application, SQL injection and cross-site scripting — running weekly, daily or continuously depending on the plan. Malware that is found is removed rather than reported, and the seal on your footer says somebody is checking.

Your site stays on your hosting. Setting it up is FTP details and one ownership check.

What it does

Five kinds of scan, and what happens when one finds something.

Three of these look. Three deal with what is found. Three are about the part nobody plans for. How OFTEN they look, and how often what they find is removed, is the difference between the three plans — set out below rather than averaged into one claim.

Malware scanning

Your files are scanned on a schedule — weekly, daily or continuously — rather than only when something has already gone visibly wrong. Most infections are quiet on purpose: they are there to send mail or hide links, and breaking your site would end that.

FTP scanning

The other way in, and the one people forget they left open. Files arriving over FTP are scanned on the same schedule as the rest of the site.

Application, SQL and XSS scans

Three more passes, over what your site does rather than what it stores: the application itself, injection points into your database, and cross-site scripting. All five scans are part of the same arrangement — none of them is an upgrade.

Automatic malware removal

What is found is removed rather than listed in a report for you to act on. How often it may do that differs by plan — once at the first scan, twice a month, or without limit — and the table below says which, because that difference is the product.

Vulnerabilities on a dashboard

What could not simply be removed — an out-of-date component, a bad configuration — is reported where you can see it, with alerts you set yourself so the urgent ones reach you rather than waiting to be noticed.

Web application firewall

Requests are filtered before they reach your server. It is on some plans and not all of them, so we will tell you plainly whether the one that suits you includes it rather than letting you find out afterwards.

Content delivery network

The same edge that filters can also cache and serve. Also plan dependent, and the honest order is security first: a faster site is the side effect nobody minds, not the reason to buy this.

Blacklist monitoring

Being flagged by a browser or a search engine costs more traffic than the infection did. Reputation is watched, along with spam protection, so a listing is caught rather than discovered in your analytics a fortnight later.

A trust seal you can show

Once the site is scanned and clean you can display the seal — a snippet in your footer — which tells a visitor about to type a card number that somebody is checking. On a shop, that is the feature that pays for the rest.

Not sure which of those you actually need? Describe the site and we will tell you.

Describe your site

Three plans

What changes between them is how often.

All five scans are in all three. What you are choosing is how often they run and how often what they find can be removed — plus, at the top, a firewall and a network in front of the site.

Basic

€187.20 a year

Renews at €199.68

Scans run
Weekly
Malware removal
Once During Initial Scan
Pages covered
Upto 500
  • Web application firewall — not on this plan
  • OWASP top ten blocking — not on this plan
  • Content delivery network — not on this plan
  • Dynamic caching — not on this plan
  • Trust seal — not on this plan
  • Works alongside your certificate — not on this plan

Premium

€1,435.08 a year

Renews at €1,447.56

Scans run
Ongoing
Malware removal
Unlimited
Pages covered
Upto 500
  • Web application firewall — included
  • OWASP top ten blocking — included
  • Content delivery network — included
  • Dynamic caching — included
  • Trust seal — included
  • Works alongside your certificate — included

Sold on one-year terms — that is how the product is sold, so it is what we quote. There is no money-back guarantee on it.

How it works

In front, behind, and afterwards.

Three drawings rather than a dashboard screenshot. What is on this page is a diagram of the arrangement — the numbers on your own site come from looking at your own site.

On a schedule

Five passes, whether or not anything is wrong

Files, FTP, the application itself, injection points into the database, and cross-site scripting. All five are in every plan; what the plan changes is how often they run, not which of them you get.

  • Weekly, daily or continuous — the plan decides
  • FTP included — the way in people forget
  • No scan on this list is an upgrade

When it finds something

Removed, or put where you will see it

Malware is removed immediately. What cannot simply be deleted — an old component, a bad configuration — is reported on the dashboard with alerts you set yourself, so the urgent ones reach you instead of waiting to be noticed.

  • Removal, not a report you have to action
  • Vulnerabilities listed with what to do about them
  • Alerts you choose, so the noise stays low

What visitors see

A seal, and a name that stays clean

Once the site is scanned and clean you can show the trust seal — a snippet in your footer. Behind it, reputation and blacklist monitoring watch for the listing that would quietly cost you more traffic than the infection did.

  • The seal goes up only once the site is clean
  • Blacklist and spam reputation watched
  • On a shop, this is the part that pays for the rest

The honest part

A firewall does not fix a broken site.

Protection is worth having and it is not a substitute for the boring work. Here is where it genuinely helps, and where somebody would be selling you the wrong thing.

When this is not what you need

  • You want one cleanup and nothing ongoing — say so, and you will be quoted for a job rather than a subscription
  • Nothing has been updated in two years — a daily scan will keep finding the same thing until somebody patches it
  • You have no backups — scanning reduces the odds; a backup is what saves you on the day it goes wrong anyway
  • You only want HTTPS — that is a certificate, and it is cheaper and simpler
  • The site is slow and that is the real complaint — the CDN helps, but the cause is usually somewhere else entirely

When it earns its place

  • You run a CMS somebody else writes

    WordPress, Joomla, Magento and their plugin ecosystems are probed by automation constantly. A daily application, SQL and cross-site scripting scan is how you find out that something got through before your customers do.

  • Nobody is watching at three in the morning

    Most infections are found by a customer, a search engine, or the host suspending the account. All three are worse than being told by something that was already looking — and there are security engineers behind it around the clock, every day of the year.

  • You are asking people to type a card number

    On a shop the trust seal is a real conversion feature, and a browser warning is the expensive part of an incident — not the malware, which is often trivial to remove.

Tell us what the site runs and what you are actually worried about. If the answer is "update your plugins and take a backup", that is what you will get.

Two different things

Protection is not maintenance.

People ask for one and mean the other often enough that it is worth drawing the line here rather than after an invoice.

This page

cWatch protection

A platform in front of your site and a scanner behind it. Always on, nobody has to be awake, and it does the same thing on a bank holiday as on a Tuesday.

  • Blocks what has not happened yet
  • Finds and removes what already got in
  • Runs whether or not anybody is looking

The other one

Security & maintenance

People doing work on a schedule: updates applied and checked, backups taken and restored to prove they work, things fixed by somebody who knows your site.

  • Closes the holes rather than covering them
  • Backups that have actually been restored
  • A person who knows what your site is for

See security & maintenance

Most sites that need one benefit from both, and we will say so plainly rather than selling you the one you happened to land on.

Part of the arrangement

What comes with it, and one thing that does not.

None of this is an upgrade. The last item is on this list because you should read it before you buy rather than after.

Set up for you

FTP details into the panel, one check that you own the site, and the first scan starts. We do that with you rather than sending instructions.

Security engineers, around the clock

Consultants and engineers behind the product 24 hours a day, seven days a week, every day of the year. An alert nobody looks at is a log file with ambitions.

The seal is yours to place

A snippet in your footer once the site is clean. We will give you the snippet and put it in the right place if you would rather not touch the template.

Findings in plain words

What was found, where, and what it was doing. Not a severity number with no sentence attached — and no overall score, because a grade that flatters is a grade nobody can stand behind.

Billed in one-year terms

That is how the product is sold, so that is what we will quote. There is no monthly version of it and we are not going to imply there is.

No money-back guarantee

There is none on this product. You are reading that here rather than finding it in a clause, because a page that hides it is a page that has decided to argue with you later.

How it starts

Four steps, and one of them is yours.

No DNS change, no migration, nothing moves. The only thing we need from you is access, and we set it up with you rather than sending a guide.

  1. 01 Connect FTP details go into the panel. Your site stays where it is and your host does not need to be involved.
  2. 02 Validate One check that the site is actually yours. This is the step that stops anybody pointing a scanner at somebody else.
  3. 03 Scan The first pass runs immediately and tells you what is there. If it is already clean, we say that too.
  4. 04 Clean and watch What is found is removed, the rest is on the dashboard with your alerts, and the five scans continue every day.

Straight answers

The questions worth asking first.

No, and they are often confused. A certificate encrypts the connection between a browser and your server, so nobody can read what passes between them. It does nothing about what is stored at the end of that connection. This scans the files and the application themselves. You want both, and they are not substitutes.

Five things: a malware scan of your files, an FTP scan, a scan of the web application itself, a SQL injection scan and a cross-site scripting scan. All five are in every plan — none of them is an upgrade. What the plan changes is the frequency: weekly, daily, or continuously. The table on this page says which is which.

No. Nothing moves. Setting it up is FTP details in the panel and one check that you own the site — that triggers the first scan. Your host, your control panel and your files stay exactly where they are.

It is removed rather than added to a report for you to act on — but how often it may do that is a real difference between the plans. The entry plan removes malware once, during the initial scan. The middle one does it up to twice a month. Only the top plan is unlimited. If you are buying this because something keeps coming back, that is the line to read.

A snippet you put in your footer once the site has been scanned and is clean. It tells somebody about to type a card number that the site is being checked. We will give you the snippet, and place it for you if you would rather not touch the template.

On one-year terms. That is how the product is sold, so it is what we quote — there is no monthly version and we are not going to imply there is.

No. There is none on this product, and you are reading that here rather than finding it in a clause afterwards. If you are not sure it is right for you, say so in the form and we will tell you honestly whether it is.

On the top plan only, along with OWASP top-ten blocking and dynamic caching. The table on this page marks exactly which plan carries them, rather than leaving you to find out after buying.

Not directly. It opens from the management page in your account rather than from its own URL, which is worth knowing before you go looking for a login page that does not exist.

No, and anybody who says otherwise is selling. A daily scan tells you what got through; updating is what stops it getting through. If updates are the actual problem, our security and maintenance page is the honest answer.

No. Scanning changes the odds; a backup is what saves you on the day something goes wrong anyway — including the days that have nothing to do with security, which is most of them.

Free assessment

Tell us about the site. We will look before we quote.

What you are worried about matters more than which product you think you want. You get a real answer from somebody who has looked — including "you do not need this", when that is the answer.

Please do not put passwords, keys or FTP details in this message. We will ask for access properly once we have agreed what needs doing, and never by reply to a form.

Most enquiries are answered within one business day. Say so if a site is down or defaced and it goes to the top.