What the product does
Included websites and cadence are recorded in the package schedule.
Guardian Website Vulnerability Monitoring provides baseline vulnerability and exposure visibility for the approved websites included in the customer package.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
Guardian records the website, issue, severity, observation dates, status, approved evidence, owner, actions and later review state. Credentials, raw scanner payloads and internal execution details remain restricted.
The package schedule identifies the included website count, monitoring profile, cadence and customer contacts. Additional websites or expanded cadence can be added using the approved product quantity.
Only approved customer-controlled websites and the agreed monitoring profile are included. Third-party or unsupported targets require separate approval or are excluded.
Included websites and cadence are recorded in the package schedule.
Raw scanner detail remains restricted while enough evidence is retained to support the finding and response.
Development, hosting and remediation remain with the agreed owner unless separately managed.
New releases, plugins, certificate changes, hosting changes, configuration drift and exposed services can introduce website risk between penetration tests. A simple scan report is not enough if nobody owns the finding or later reviews the fix.
Guardian Core includes a baseline monitoring allowance for approved websites. Findings are normalised into customer-readable records and can become risks or actions. Katana remains the add-on for deeper active website and API testing.
Run the approved baseline checks at the agreed cadence rather than waiting for the next project.
Show the affected website, issue, severity, status and practical remediation context.
Assign ownership, due dates and evidence, then review later monitoring state before closure.
Included websites and cadence are recorded in the package schedule.
Maintain explicit customer ownership, URL, environment and monitoring scope for each included website.
Run supported public vulnerability and exposure checks against the approved website scope.
Present issue, severity, site, status, first and last observation and remediation context.
Connect material website findings to Guardian risks, All Actions, owners and due dates.
Retain approved finding and remediation evidence plus later observation state.
Include website posture, material findings and remediation progress in Guardian reporting.
Raw scanner detail remains restricted while enough evidence is retained to support the finding and response.
Included sites, monitoring state, latest successful check and current material findings.
Customer-readable issue, severity, affected site, status and practical remediation guidance.
Developer, hosting provider, internal team or MSP ownership with due date and expected outcome.
First observed, last observed, reopened, resolved-pending-review and closed states where supported.
Approved technical context and later validation without publishing unsafe raw payloads.
Authorised customer website scope and remediation through provider-scoped Guardian relationships.
Development, hosting and remediation remain with the agreed owner unless separately managed.
Confirm ownership, URL, environment, contacts, exclusions and the included monitoring cadence.
Run supported baseline checks and track successful, failed or unavailable monitoring state.
Normalise supported findings and remove unsafe raw detail or obvious scope mismatch.
Identify material findings that require immediate action, planned remediation or deeper testing.
Track customer or provider actions and the evidence required to review closure.
Include the monitored website estate, material findings, overdue actions and current service state.
The baseline profile remains non-destructive and separate from deeper active testing.
Confirm website ownership, environment, URL, monitoring profile, contacts and exclusions.
Run the initial supported checks and validate site mapping and service behaviour.
Run the agreed baseline checks at the included cadence.
Normalise material findings and prepare customer-readable evidence and guidance.
Assign the required code, configuration, certificate, hosting or control change.
Review later monitoring state or approved evidence before recording closure.
The product is designed for ongoing awareness and accountable remediation, not to replace deeper testing.
Keep one or more public websites under baseline review without operating a specialist security platform.
Monitor approved provider websites as part of the Guardian Core package and assign remediation to the responsible party.
Manage authorised customer website inventories, findings and actions through a provider-scoped workflow.
Identify material exposure introduced by releases, plugins, certificates, hosting or configuration change.
Maintain baseline awareness after a formal penetration test while deeper retesting remains separately scoped.
Use the baseline findings and application context to decide whether deeper active Katana testing is required.
These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.
Onboarding confirms ownership, environment and the safe baseline monitoring profile. The customer provides the website URL, ownership, environment, hosting or developer contacts, expected authentication state, maintenance windows, exclusions and any third-party restrictions. Damocles confirms that the target is suitable for the included baseline profile. The initial check validates reachability, site identity, certificates, redirects and the quality of supported findings. Customer or provider ownership is confirmed before findings are published. Go-live records the included website allowance, cadence, notification path, action owner and the boundary between baseline monitoring, Katana active testing, penetration testing and remediation engineering.
The product can use approved website-assessment components without exposing the implementation as the customer product. The monitoring connector or assessment component must preserve target authority, job status, timestamps, finding identity, severity, evidence and safe failure state. Guardian provides the customer record and remediation lifecycle. A customer or provider does not receive unrestricted scanner access or raw execution payloads simply because the monitoring result is shown in Guardian. The public product remains Guardian Website Vulnerability Monitoring. Changes to the assessment component or connector are reviewed for target safety, finding continuity, evidence quality, supportability and the customer entitlement before use.
Findings retain enough evidence for action while avoiding unsafe public scanner detail. Guardian records the website, issue, severity, observation dates, status, approved evidence, owner, actions and later review state. Credentials, raw scanner payloads and internal execution details remain restricted. A finding that disappears from one check is not automatically treated as fully remediated. Closure can require later observation, customer evidence or deeper validation depending on the issue. Reports identify failed or unavailable monitoring state so missing checks are not represented as a clean result.
Guardian Core includes the approved baseline website allowance and cadence. The package schedule identifies the included website count, monitoring profile, cadence and customer contacts. Additional websites or expanded cadence can be added using the approved product quantity. Katana, authenticated testing, custom profiles, additional active assessment, included rescans, manual penetration testing, code review and remediation engineering remain separately entitled. The customer provides target authority and timely remediation decisions. Damocles operates the baseline checks, customer-safe findings and follow-up listed in the Core service definition.
The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.
Yes for the approved website allowance and cadence stated in the package schedule.
No. Core monitoring provides a baseline watch. Katana adds deeper active website and API assessment profiles, evidence and rescans.
No. Formal penetration testing provides human-led validation and attack-path analysis outside the baseline monitoring scope.
Only through a separately approved active-testing profile or engagement suitable for credentials and application workflows.
The agreed customer, developer, host, MSP or Damocles engineering service owns the remediation according to the action and contract.
Guardian shows the failed or unavailable monitoring state and the issue is investigated rather than converted to a zero-finding result.
We will define the included website allowance, cadence, target authority, finding workflow and whether deeper Katana testing is required.