The client finds out when the site stops loading.
A certificate expires on a date somebody could have known about six weeks earlier. Glarion watches the sites you look after and writes to you only when something changes.
Why this exists
Running the scanner is the easy part.
The open-source tools are free and good. Point one at a client site and it returns thirty-odd findings, most of them informational, none of them in an order. That output is not something you can put in front of the person paying you.
Deciding what matters is the work.
Glarion re-ranks everything against what it means for a live business — a missing content policy is informational to a scanner and serious to us — then splits it into what to fix, what to look at, and what is merely on record. A real scan of thirty-two findings came out as three things to do.
Priced for a portfolio, not a project.
Tools in this category charge per application, from about ninety dollars each. That is a sensible price for a company with one product and an absurd one for an agency looking after twenty client sites. One subscription here covers all of them.
The report has your name on it.
Findings come out as a numbered worklist with a plain-English reason and a fix, under your agency's name and logo, printable to PDF. It is written for the client to read, not for the person who ran the scan.
What the client receives
- A worklist, not raw output.Every finding includes the business reason, the next action and enough context to assign it.
- Your identity stays in front.Paid reports carry your agency name and logo, ready to print or save as PDF.
- Nothing is staged for this preview.The layout mirrors the report model used by Glarion; the client and domain above are deliberately fictional.
Trust, in verifiable terms
- Ownership before active scanning
- DNS or hosted-file proof is required and checked again before every scheduled scan.
- Constrained scanning
- Tools and templates are allowlisted; attacking tags, callbacks and private-network targets are refused.
- Change-focused reporting
- Weekly monitoring surfaces what changed instead of making clients reread the same inventory.
- Tested release gates
- Backend, frontend, formatting and static-route checks run before production deployment.
The arithmetic
Twenty client sites.
| Per year | Glarion | Priced per application |
|---|---|---|
| Twenty sites, monitored weekly | €750 | €20,000 + |
| What you can bill for one audit | ~€300 | ~€300 |
| Audits before it has paid for itself | 3 | 67 |
The monitoring is the part you resell. A one-off audit is a job; a site that is watched every week, with a note when something changes, is a retainer.
Pricing
-
FreeOne site. Scan when you ask. No scheduling.€0
-
Studio RecommendedTen sites, weekly checks, white-label reports.For independent consultants and small agency portfolios.€39/month · €350 a year, saving €118
-
AgencyForty sites, weekly checks, white-label reports.For established teams managing multiple retained clients.€99/month · €750 a year, saving €438
What we will not do
A full scan probes: it requests paths a site never advertised and tries known vulnerability fingerprints against them. Doing that to a domain uninvited is the thing computer-misuse law was written to describe.
So Glarion will not run one until the domain's owner has proved control of it, by DNS record or by a file on the host. The proof expires and is re-checked before every scheduled scan, because domains change hands. A scanner that points itself anywhere on request is a different product, and we would rather refuse the work than be it.
The check at the top of this page is exempt for a reason that survives scrutiny: it reads only what the site broadcasts to every visitor and to every search engine. Nothing is probed, no path is guessed.