Everything your site needs, in one place.
Torlyx covers the whole lifecycle — from the code you're about to ship to the site your customers use every day. Here's exactly what you get.
Before you deploy
Catch problems while they are still cheap to fix — before your code is live.
Pre-Deploy Readiness
Connect a GitHub repo and every commit gets a clear ready-or-blocked verdict — static analysis, leaked-secret detection, vulnerable dependencies and container checks, with the exact fix. Ship only what is safe.
Map your attack surface
See what an attacker sees first — every host and port exposed to the internet.
Subdomain Finder
Discover every subdomain and forgotten host attached to your domain from public certificate-transparency logs, each with a live DNS check — your real, current exposed surface.
Port & Service Scan
A real TCP scan of your host's common ports — see exactly what's reachable from the internet and get flagged when a database, admin panel or other sensitive service is exposed.
Find every risk
One scan looks at your whole site the way an attacker would — no security background needed.
Security Scans
Paste a URL and get 119 security checks — headers, TLS, CORS, exposed files, DNS and email hygiene, client-side issues and known CVEs. Scheduled re-scans keep you covered as things change.
Unified Findings
Every issue from every scan and audit in one ranked list — by severity and category, each with a plain-language fix. No 400-item PDF that nobody reads.
Active Testing (DAST)
Technology-aware dynamic testing that safely probes your running site for exploitable vulnerabilities — injection, XSS, SSRF, RCE, misconfig — the deep pass a passive scan can't do. Light and deep modes, consent-gated to sites you've verified.
SSL/TLS Deep Audit
A full TLS grade from a live handshake — negotiated protocol and cipher, the certificate chain and expiry, which TLS versions your server accepts, and HSTS. Catches weak or expiring certs before browsers do.
CMS / WordPress Scanner
Fingerprints your stack and scans the detected CMS — WordPress, Joomla, Drupal and more — for vulnerable core, plugins, themes and misconfigurations, the way a targeted attacker would.
Block and stay up
After you launch, Torlyx watches around the clock and stops live attacks.
Managed WAF
Connect your own Cloudflare account in a two-minute wizard — no enterprise plan needed. Torlyx turns your findings into edge rules that block SQL injection, XSS and bad bots before they reach you.
24/7 Monitoring
Uptime, SSL/TLS and per-page checks run non-stop on your plan's interval — from every 30 minutes on Free down to every minute on Scale — with instant alerts and downtime screenshots.
Host Agents
Install a read-only agent for deep inside-out monitoring — pending updates, open ports, firewall and SSH hardening, cert expiry and more. Read-only by design: it can never change your server.
Cloud Posture
Connect a scoped, read-only AWS key and Torlyx audits your account for real misconfigurations — public S3 buckets, security groups open to the world, IAM users without MFA, root access keys and public databases.
Get found and understood
Security is not the only thing that decides whether your site succeeds.
SEO Audit
68 on-page checks — titles, meta, headings, structured data, image alt text and internal links — scored with clear, prioritized fixes so search engines rank you higher.
AEO Audit
46 checks for the AI era: how clearly ChatGPT, Gemini and other assistants can read and cite your site — structured data, entity clarity, headings, robots and llms.txt.
Fix it and get help
Finding a problem is half the job. Torlyx helps you close it.
Fix Center + AI guidance
Every finding comes with step-by-step, AI-guided remediation you can apply yourself — or hand it to Torlyx's engineers to patch for you. Fix, don't just flag.
Torlyx Rescue
Need something fixed now and don't want a subscription? Torlyx engineers fix a specific issue for you as a one-off — you get a fixed quote up front and pay only to start.
Messages
Talk to the Torlyx team in-app on any plan — questions, fix requests and progress, all in one thread with file attachments.
Task Management
A board and backlog to track security work — including anything you've handed to Torlyx — so nothing slips.
Scale with your team
Bring people in and prove your posture when it counts.
Team Management
Invite members, build teams and assign roles and permissions — everyone sees exactly what they should. Free and Starter delegate work to Torlyx instead.
Compliance
Generate readiness reports against common frameworks so you can answer a security questionnaire or an auditor without a fire drill.
Pentest Reports
Turn an active test into a branded, point-in-time penetration-test report — executive summary, findings with evidence and remediation, and a retest diff — as a downloadable PDF you can hand to a client or auditor.