Included in Guardian Core

Keep a baseline watch on public websites and turn new findings into tracked remediation.

Guardian Website Vulnerability Monitoring provides baseline vulnerability and exposure visibility for the approved websites included in the customer package.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Included Core allowanceApproved website inventoryBaseline vulnerability monitoringRisk, actions and evidence
Buyer decision summary

Know what Guardian Website Vulnerability Monitoring does, what the customer sees and what Damocles is responsible for before activation.

Guardian records the website, issue, severity, observation dates, status, approved evidence, owner, actions and later review state. Credentials, raw scanner payloads and internal execution details remain restricted.

The package schedule identifies the included website count, monitoring profile, cadence and customer contacts. Additional websites or expanded cadence can be added using the approved product quantity.

Only approved customer-controlled websites and the agreed monitoring profile are included. Third-party or unsupported targets require separate approval or are excluded.

01

What the product does

Included websites and cadence are recorded in the package schedule.

02

What the customer sees

Raw scanner detail remains restricted while enough evidence is retained to support the finding and response.

03

What Damocles manages

Development, hosting and remediation remain with the agreed owner unless separately managed.

The operational problem

Public websites change between formal assessments, but the customer still needs to know when baseline exposure appears.

New releases, plugins, certificate changes, hosting changes, configuration drift and exposed services can introduce website risk between penetration tests. A simple scan report is not enough if nobody owns the finding or later reviews the fix.

Guardian Core includes a baseline monitoring allowance for approved websites. Findings are normalised into customer-readable records and can become risks or actions. Katana remains the add-on for deeper active website and API testing.

01

Maintain ongoing awareness

Run the approved baseline checks at the agreed cadence rather than waiting for the next project.

02

Make the finding usable

Show the affected website, issue, severity, status and practical remediation context.

03

Track the fix

Assign ownership, due dates and evidence, then review later monitoring state before closure.

Product capability

The baseline website assurance included in Guardian Core.

Included websites and cadence are recorded in the package schedule.

WI

Approved website inventory

Maintain explicit customer ownership, URL, environment and monitoring scope for each included website.

BM

Baseline monitoring

Run supported public vulnerability and exposure checks against the approved website scope.

CF

Customer-readable findings

Present issue, severity, site, status, first and last observation and remediation context.

RA

Risk and action linkage

Connect material website findings to Guardian risks, All Actions, owners and due dates.

EV

Evidence and history

Retain approved finding and remediation evidence plus later observation state.

RP

Core reporting

Include website posture, material findings and remediation progress in Guardian reporting.

What the customer sees

Customers see a simple website inventory, findings and remediation state.

Raw scanner detail remains restricted while enough evidence is retained to support the finding and response.

WS

Website status

Included sites, monitoring state, latest successful check and current material findings.

FD

Finding detail

Customer-readable issue, severity, affected site, status and practical remediation guidance.

OW

Ownership

Developer, hosting provider, internal team or MSP ownership with due date and expected outcome.

HS

History

First observed, last observed, reopened, resolved-pending-review and closed states where supported.

EX

Evidence

Approved technical context and later validation without publishing unsafe raw payloads.

PV

Provider view

Authorised customer website scope and remediation through provider-scoped Guardian relationships.

What Damocles manages

Damocles operates the baseline monitoring workflow and customer-safe finding process.

Development, hosting and remediation remain with the agreed owner unless separately managed.

ON

Website onboarding

Confirm ownership, URL, environment, contacts, exclusions and the included monitoring cadence.

MO

Monitoring operation

Run supported baseline checks and track successful, failed or unavailable monitoring state.

QR

Quality review

Normalise supported findings and remove unsafe raw detail or obvious scope mismatch.

PR

Prioritisation

Identify material findings that require immediate action, planned remediation or deeper testing.

RF

Remediation follow-up

Track customer or provider actions and the evidence required to review closure.

SR

Reporting

Include the monitored website estate, material findings, overdue actions and current service state.

Operating lifecycle

From approved website to monitored finding and reviewed outcome.

The baseline profile remains non-destructive and separate from deeper active testing.

01

Approve

Confirm website ownership, environment, URL, monitoring profile, contacts and exclusions.

02

Baseline

Run the initial supported checks and validate site mapping and service behaviour.

03

Monitor

Run the agreed baseline checks at the included cadence.

04

Review

Normalise material findings and prepare customer-readable evidence and guidance.

05

Remediate

Assign the required code, configuration, certificate, hosting or control change.

06

Verify and report

Review later monitoring state or approved evidence before recording closure.

Common use cases

Common baseline website-monitoring use cases.

The product is designed for ongoing awareness and accountable remediation, not to replace deeper testing.

SB

Small-business website

Keep one or more public websites under baseline review without operating a specialist security platform.

ND

NDIS provider websites

Monitor approved provider websites as part of the Guardian Core package and assign remediation to the responsible party.

MS

MSP website estate

Manage authorised customer website inventories, findings and actions through a provider-scoped workflow.

CH

Change awareness

Identify material exposure introduced by releases, plugins, certificates, hosting or configuration change.

PT

Pentest follow-up

Maintain baseline awareness after a formal penetration test while deeper retesting remains separately scoped.

KA

Katana qualification

Use the baseline findings and application context to decide whether deeper active Katana testing is required.

Operating model

How Guardian Website Vulnerability Monitoring is onboarded, integrated, evidenced and scoped commercially.

These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.

ON

Onboarding and implementation

Onboarding confirms ownership, environment and the safe baseline monitoring profile. The customer provides the website URL, ownership, environment, hosting or developer contacts, expected authentication state, maintenance windows, exclusions and any third-party restrictions. Damocles confirms that the target is suitable for the included baseline profile. The initial check validates reachability, site identity, certificates, redirects and the quality of supported findings. Customer or provider ownership is confirmed before findings are published. Go-live records the included website allowance, cadence, notification path, action owner and the boundary between baseline monitoring, Katana active testing, penetration testing and remediation engineering.

IN

Connector and integration model

The product can use approved website-assessment components without exposing the implementation as the customer product. The monitoring connector or assessment component must preserve target authority, job status, timestamps, finding identity, severity, evidence and safe failure state. Guardian provides the customer record and remediation lifecycle. A customer or provider does not receive unrestricted scanner access or raw execution payloads simply because the monitoring result is shown in Guardian. The public product remains Guardian Website Vulnerability Monitoring. Changes to the assessment component or connector are reviewed for target safety, finding continuity, evidence quality, supportability and the customer entitlement before use.

EV

Data, evidence and reporting

Findings retain enough evidence for action while avoiding unsafe public scanner detail. Guardian records the website, issue, severity, observation dates, status, approved evidence, owner, actions and later review state. Credentials, raw scanner payloads and internal execution details remain restricted. A finding that disappears from one check is not automatically treated as fully remediated. Closure can require later observation, customer evidence or deeper validation depending on the issue. Reports identify failed or unavailable monitoring state so missing checks are not represented as a clean result.

CM

Commercial unit and responsibilities

Guardian Core includes the approved baseline website allowance and cadence. The package schedule identifies the included website count, monitoring profile, cadence and customer contacts. Additional websites or expanded cadence can be added using the approved product quantity. Katana, authenticated testing, custom profiles, additional active assessment, included rescans, manual penetration testing, code review and remediation engineering remain separately entitled. The customer provides target authority and timely remediation decisions. Damocles operates the baseline checks, customer-safe findings and follow-up listed in the Core service definition.

Frequently asked questions

Questions buyers ask about Guardian Website Vulnerability Monitoring.

The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.

Q1

Is this included in Guardian Core?

Yes for the approved website allowance and cadence stated in the package schedule.

Q2

Is it the same as Katana?

No. Core monitoring provides a baseline watch. Katana adds deeper active website and API assessment profiles, evidence and rescans.

Q3

Does it replace a penetration test?

No. Formal penetration testing provides human-led validation and attack-path analysis outside the baseline monitoring scope.

Q4

Can authenticated areas be tested?

Only through a separately approved active-testing profile or engagement suitable for credentials and application workflows.

Q5

Who fixes the finding?

The agreed customer, developer, host, MSP or Damocles engineering service owns the remediation according to the action and contract.

Q6

What if the site cannot be checked?

Guardian shows the failed or unavailable monitoring state and the issue is investigated rather than converted to a zero-finding result.

Scope and boundaries

Baseline monitoring is not authority for unrestricted scanning, exploitation or destructive testing.

Only approved customer-controlled websites and the agreed monitoring profile are included. Third-party or unsupported targets require separate approval or are excluded.

The product does not claim discovery of every application defect, business-logic weakness, authenticated issue or future vulnerability.

Deeper active testing, penetration testing, code review and remediation implementation remain separate unless expressly included.

Take the next practical step

Confirm the public websites that should remain under baseline security review.

We will define the included website allowance, cadence, target authority, finding workflow and whether deeper Katana testing is required.