Security monitoring for developers

Protect your reputationBefore hackers destroy IT

Bolwerk is Dutch for stronghold. Your vibe coded apps need one. We monitor certificate logs, DNS records, and open endpoints around the clock, so you know what's exposed before someone exploits it.

Built for vibe coded apps
Continuous monitoring
No security expertise needed
Bolwerk domain overview showing discovered subdomains, scan detections and AI security analysis

How it works

From one domain to a full picture of what you expose, in three steps

Discover every host

Enter one domain and we map the rest. Certificate Transparency logs reveal every subdomain that has ever had a certificate, including the ones nobody remembers setting up.

One domain is all it takes

Visit every site

Each host is opened in a real browser, the way a visitor sees it. We check its certificate, security headers and DNS, and record every request the page makes.

A real browser, not a ping

Catch leaked secrets

We read the JavaScript, JSON and source maps your sites serve and flag API keys and tokens that should never be public. Values are shown masked, and AI analysis tells you which ones matter.

Found before someone else finds them

What others miss, we find

Your domains reveal more than you think. From certificates to subdomains, we surface what an outsider can discover about you.

zsh — ~/bolwerk/threats
scanning
unauthorized.logcritical

Certificates issued without your approval

expiring.logwarning

Certificates nearing expiration dates

revoked.logcritical

Certificates that have been revoked

ct-missing.logwarning

Missing certificate transparency entries

phishing.logcritical

Look-alike domains targeting your brand

shadow-it.loginfo

Unknown subdomains and services

weak-keys.logwarning

Outdated or vulnerable cryptography

ssl-misconfig.logwarning

Insecure TLS settings and protocols

In active development

Your full attack surface

Certificate monitoring is where we started. We're now expanding to cover everything that's externally visible about your infrastructure.

Vulnerability Scanning

We scan your applications for known CVEs, misconfigurations, and weak spots across your stack.

Port & Service Discovery

We map which services and ports are reachable from outside. Continuously, not as a one-off.

Data Exposure Detection

We hunt for databases, API keys, and configuration files that accidentally ended up public.

Security Header Analysis

We check your HTTP headers for missing protections like CSP, HSTS, and X-Frame-Options.

DNS Security Monitoring

We track DNS changes, detect hijacking attempts, and flag dangling records.

Compliance Checking

We automatically test your configuration against industry security standards and best practices.

MCP Servers

Connect your AI tools directly to Bolwerk via the Model Context Protocol and query your attack surface in natural language.

Why Bolwerk

In Dutch, a bolwerk is a bastion: a fortified wall, a line of defense. Something that protects and holds its ground.

Built before the attack, not after.

Get started for free