# KeptShut > Security monitoring built for solo developers and small businesses. KeptShut > watches the operational and money-losing gaps that no single platform covers: > live exposure, repositories, provider spend, server control panels, and domain > posture. Findings come with paste-ready fix prompts. Tagline: Security for the small operator. ## What it does - **Live exposure scan** — finds a web-readable .env, .git, CLAUDE.md or backup; directory listing; debug mode; admin routes reachable without auth; anon keys in front-end bundles; missing CSP and HSTS; dangling CNAMEs; expired certificates. - **Repository scan** — on every push: packages that do not exist, committed secrets, .gitignore gaps, routes with no server-side authorisation, SQL built by concatenation, lockfile integrity and malicious-package alerts. - **Bill-shock guard** — spend velocity per key and endpoint across AI, SMS, cloud and payment providers, with pre-authorised revoke of an abusive key. - **Panel watch** — outside-in fingerprint of the control panel, web server, PHP and database versions, matched hourly against the known-exploited list. - **Domain posture** — transfer lock, registry lock, DNSSEC, CAA, expiry runway, dangling DNS, MFA checklist, and recovery-email breach checks. ## The rule that governs everything KeptShut runs PUBLIC checks — what any visitor could see — against any hostname. Anything active, authenticated or probing requires the customer to first prove ownership with a DNS TXT record, a meta tag, or a file. This is a legal boundary, enforced in one shared authorization helper, and every refusal is written to an audit log. ## Pricing - Free — 1 site, 1 scan, public checks only, badge included. No card. - Solo $19/month — continuous monitoring, 3 sites, repository scan, domain posture. - Pro $49/month — adds bill-shock guard, panel watch and behavioural testing, 10 sites. - Agency $99/month — 50 sites, white-label reports, client portal, team seats. ## The badge Every monitored site gets a public page and an embeddable SVG reading "Kept shut since ". It EXPIRES the moment a monitored check regresses. That is deliberate: a badge that cannot expire means nothing. ## Key pages - https://keptshut.com/ — overview - https://keptshut.com/how-it-works — the four steps - https://keptshut.com/modules — every module in detail - https://keptshut.com/pricing — plans and limits - https://keptshut.com/security — how KeptShut secures itself ## Contact - Support: support@keptshut.com - Security and responsible disclosure: security@keptshut.com