Penetration testing that proves every finding.
Notra runs a real pentest against your live site and returns a short list of verified vulnerabilities, each one backed by the exact request and response that proves it. No security hire required.
Evidenced
Every finding carries the request and response that proves it. No proof, we drop it.
False-positive filtered
We re-run each candidate with a harmless test. Under 0.8 confidence, it never ships.
Explained
Written so your developer knows what to change, with the CVE to back it.
A scanner hands you 800 findings. A handful are real.
This is one real scan. We cut everything we couldn’t prove and kept only what survives the gate.
Zero unverified findings. Structurally.
The gate re-runs every candidate with a harmless proof-of-exploit before it can ship. Under 0.8 confidence it never leaves the building — not because a policy says so, but because the gate can’t emit it.
This is the desk you work from.
The verified findings table, sorted by real risk — the same view your team gets after every scan.
- Your siteAny public site
- AuthorizeDNS or file token
- Live scansafe, non-destructive
- Verification gateproof or it's cut
- Verified reportranked, explained, PDF
Nothing runs until you approve it. Four steps, start to finish.
Prove it's yours
Add a DNS record or drop a file. We don't touch your site until you do.
Live scan
We map the site, then run safe checks. Nothing destructive, and you watch it happen.
Verification gate
We try to reproduce each finding. Whatever we can't prove, we cut.
Verified report
A ranked PDF. Each finding has its proof, its score, and the fix.
Click a finding, read the request that triggered it.
One finding from the sample audit, with the exact request and response we captured.
$ curl -s https://harborlanterngoods.com/wp-content/plugins/wp-file-manager/readme.txt | sed -n '1,6p' === WP File Manager === Contributors: mndpsingh287 Tags: file manager, wp file manager, filemanager Stable tag: 6.0 Requires at least: 3.0 # 6.0 is < 6.9 -> CVE-2020-25213 (CISA KEV). The elFinder connector is exposed with no auth check. # Notra's benign write probe (create a directory, no shell, no upload): POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1 Host: harborlanterngoods.com Content-Type: multipart/form-data; boundary=----vera7f3a ------vera7f3a Content-Disposition: form-data; name="cmd" mkdir ------vera7f3a Content-Disposition: form-data; name="target" l1_Lw ------vera7f3a Content-Disposition: form-data; name="name" vera_probe_7f3a ------vera7f3a-- HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 {"added":[{"name":"notra_probe_7f3a","hash":"l1_dmVyYV9wcm9iZV83ZjNh","phash":"l1_Lw","mime":"directory","ts":1756142870,"read":1,"write":1,"locked":0}]} # Unauthenticated directory creation succeeded -> the connector accepts commands with no nonce and no login. # Verification gate stopped here. Notra did NOT upload a payload. The empty folder notra_probe_7f3a was left in place # so your team can independently confirm and then delete it.
Every raw signal comes in. Only the proven ones ship. The rest go here:
deduped
Same flaw across many paths/params, merged to one.
info-only
Real, but harmless on their own.
unverified
We couldn't reproduce them.
false-positive
False alarms: framework CSRF, ORM "SQLi", bot-blocked 403s.
White-label every audit under your brand. Rechecks are billable, and clients read a plain-English report, no security hire on their side.
One honest answer before you launch: what on your site is actually exploitable today, and exactly what to change to fix it.
Catch a regression before your customers do. Every monitored rescan emails you the current findings, so nothing sits unnoticed between deploys.
Dozens of client sites in one console, white-label PDFs, and a verification gate that means far fewer false-alarm tickets.
Pay per site, not per finding.
Priced per site, per month. Pay yearly and two months are free. Early customers keep launch pricing for a year.
A letter grade in under a minute. Free with a Notra account.
- Passive scorecard: TLS, security headers, cookie flags, exposed files, email auth
- Letter grade and one-line plain-English summary
- Sign in free — no card, no domain ownership required
- Results in under a minute
- No verified findings or evidence pack (that starts at Deep Audit)
A full pentest, every finding proven. Once.
- Full active scan across every module (CVE xref, XSS, CORS, TLS, headers, exposed files, redirects)
- Every finding passes the verification gate before you see it
- Raw request/response evidence attached to each finding
- Branded PDF + shareable web report, findings explained like a human wrote them
- Unauthenticated deep budget: 360 requests · 60 min · 20-finding target
- Domain ownership required (DNS TXT or file upload)
The deep budget, plus your logged-in sessions.
- Everything in the Deep Audit, at the same verification standard
- Authenticated testing with your session cookie (member areas, dashboards, account flows)
- Extended ceiling ~480 requests · 90 min
- Raw request/response evidence attached to each finding
- Domain ownership required (DNS TXT or file upload)
One domain, watched. New criticals alert you.
- 1 monitored domain, deep-depth scans included
- Daily automated rescans
- Diff alerts: new, resolved and regressed findings between scans
- Findings cross-referenced against real NVD + CISA KEV data
- Email report on every rescan
Up to 5 domains, monitored and re-scanned.
- Up to 5 monitored domains
- 3 team seats
- Daily automated rescans
- REST API + CI/CD gate
- Everything in Monitor
White-label audits for your whole client roster.
- White-label PDF reports
- Client workspaces + 10 seats
- Up to 25 monitored domains
- REST API + CI/CD gate
- Everything in Pro, per domain
Pooled domains, SSO, and a named contact.
- Unlimited or pooled domain volume
- SSO/SAML, full audit log and role-based access control
- Custom modules and your own severity policy
- SLA plus named-engineer review of shipped reports
- On-prem / VPC scan runners for sensitive environments
| Classic scanners | Notra | |
|---|---|---|
| Output | Hundreds of raw plugin & version matches | Only the findings we can prove, ranked by real risk |
| Evidence | A version string and a guess | The raw request/response that proves it |
| False positives | You triage them | Filtered below a 0.8 confidence floor |
| Deliverable | A CSV of noise | A branded, plain-language PDF |
| Continuous | One-time snapshot | Scheduled rescans with email on every result |
| Who can read it | A security engineer, if you have one | Anyone on the team |
Is scanning my site safe?
Yes. Active probes use safe, non-destructive defaults with a per-target rate ceiling, and money-movement endpoints (cart, checkout, pay) stay untouched unless you agree to a sandboxed test. Every proof is a benign detection probe, never a weaponized exploit.
Do you need my passwords or source code?
No. Notra is black-box by default. It only sees what any visitor sees. Optional authenticated scans (Deep Audit) use a session cookie you paste in, encrypted immediately, used once for that run, deleted the moment it finishes, and called out plainly in the report.
How do you avoid false positives?
The verification gate. We throw out anything that can't attach evidence, re-run each candidate with a benign proof, de-duplicate, and hold everything to a 0.8 confidence floor before it reaches you.
Where do the CVEs come from?
We fingerprint your stack, then cross-reference NVD, CISA KEV, GHSA and OSV with version-range logic, and re-check continuously so a newly-published KEV on your stack raises an alert.
What stops someone scanning a domain they don't own?
A hard authorization gate. No active module runs until you prove control with a DNS TXT record or an uploaded file token, and every authorization is logged.
What if a scan fails?
It auto-retries once. If it still fails, it's automatically marked failed and refunded — no ticket to file. You never pay for a scan that didn't deliver.
See what’s actually exploitable.
Run the free scorecard in under a minute — sign in required, passive checks only. Upgrade to a verified deep audit whenever you’re ready.