Hardn your site.
Built for indie devs and vibe coders shipping AI-built apps. Hardn finds the security holes in your site, explains each one in plain English, and hands you the exact fix for your stack — no CVE-reading required.
Free one-time scan · passive checks only · domain ownership verified before any scan
Hardn produces an automated hardening scan, not a certified security audit.
Who Hardn is for
If you don't have a security hire, Hardn is the watchdog you don't have to be.
Solo founders & indie hackers
You run a real app with real users and no time to become a security expert on the side.
AI-app & no-code builders
You shipped fast with AI-generated code. Studies find nearly half of it carries a common vulnerability — and you can't audit it line by line. Hardn reads it so you don't have to.
Small agencies & freelancers
You manage a fleet of client sites and need one place to watch them all — with reports you can hand straight to a client.
What Hardn checks
Passive checks that map your real, externally-visible attack surface — no payloads, no exploitation. Four run today; dependency and cloud-bucket checks are rolling out.
TLS & cert expiry
Weak protocols, broken ciphers, and certificates about to expire — caught before your visitors hit a browser warning.
Security headers
Missing or weak CSP, HSTS, X-Frame-Options and more — the headers that quietly defend every page.
SPF · DKIM · DMARC
Email authentication gaps that let anyone spoof your domain and land in your customers' inboxes.
Exposed files
Publicly reachable .env, .git, config, and backup files — the fastest way secrets leak.
Dependency CVEs soon
Known vulnerabilities in your dependencies, scanned from the lockfile you provide.
Bucket misconfig soon
Public cloud storage buckets that list or serve their contents to anyone — checked passively.
How it works
The scan is the easy part. The report is the product.
Scan
Verify you own the domain with a DNS challenge, then Hardn runs its passive checks and collects the raw findings.
Explain
An AI report scores each finding against your business context and rewrites it in plain English — what it is, and why it matters for your site.
Fix
Every issue comes with a copy-paste fix for your exact stack — nginx, Caddy, Vercel, Cloudflare — plus a command to verify it worked.
Why not just free tools + ChatGPT?
You can almost piece this together yourself. Here's what that actually looks like — and why a generic AI explanation isn't the same thing.
Free tools + ChatGPT
- Run SSL Labs, SecurityHeaders, a DMARC checker, an .env probe — each separately
- Paste each output into ChatGPT for a generic explanation
- Get a one-time letter grade with no business context
- Hope the suggested fix matches your actual stack
- Redo the whole thing by hand next month
Hardn
- Every check consolidated into one report
- Each risk scored against your business, in plain English
- Copy-paste fixes written for your exact stack — nginx, Caddy, Vercel, Cloudflare
- Every fix ships with a command to verify it worked
- Re-scans and change alerts so you catch drift (rolling out)
The scan is day one. Hardn keeps watching.
Your attack surface changes every time you ship. A free scan is a photo; Hardn is the security camera. It re-scans on a schedule and pings you the moment something slips.
/.env became publicly reachable since your last scan. Rotate any secrets in it now.Content-Security-Policy header disappeared from your checkout page after a deploy.Continuous monitoring is rolling out — these are example alerts. Today Hardn runs a full on-demand scan; scheduled re-scans and alerts are next. Hardn produces an automated hardening scan, not a certified security audit.
Pricing
Start free. Upgrade when you want Hardn watching continuously. Annual plans get two months free.
Free scan
- All live checks, one full run
- Plain-English report with copy-paste fixes
- Business-context risk scoring
- No card required
or $390/year — two months free
Monitoring · 1–3 domains coming soon
- Automatic re-scans on a schedule
- Drift alerts when something changes
- Cert-expiry warnings before they bite
- Change history across scans
- Add more domains anytime
or $1,290/year — two months free
Agency · up to 25 domains coming soon
- Everything in Monitoring
- Multi-domain dashboard
- Per-client grouping
- Client-ready reports
Want it done for you?
With done-for-you hardening we implement the fixes from your report — headers, TLS config, SPF/DKIM/DMARC, locking down exposed files — then re-scan to confirm each one. A hands-on service, separate from the automated scan. Not a certified audit.
Frequently asked questions
What is Hardn?
Hardn is a security scanner for indie developers, vibe coders, and small SaaS. It runs passive checks — today for TLS, security headers, email authentication (SPF/DKIM/DMARC), and exposed files, with dependency-CVE and cloud-bucket checks rolling out — then generates a plain-English AI report that scores each risk against your business and gives copy-paste fixes for your stack.
How much does Hardn cost?
The first scan and AI report are free. Monitoring is $39 per month (or $390 per year) for 1–3 domains and adds continuous re-scans, drift alerts, and cert-expiry warnings. The Agency plan is $129 per month for up to 25 domains. There's also an optional one-time done-for-you hardening service from $249 per site.
Who is Hardn for?
Solo founders and indie hackers, vibe coders and AI-app builders shipping generated code they can't audit line by line, and small agencies hardening client sites — anyone without a dedicated security hire. The plain-English report is most valuable to builders who can't read a CVE.
Do you have a plan for agencies managing many sites?
Yes. The Agency plan is $129 per month (or $1,290 per year) and covers up to 25 domains with a multi-domain dashboard, per-client grouping, and client-ready reports. The $39 Monitoring plan covers 1–3 domains, with the option to add more.
Can Hardn fix the issues for me, not just report them?
Yes, as a separate one-time service. With done-for-you hardening (from $249 per site) we implement the recommended fixes from your report — security headers, TLS configuration, SPF/DKIM/DMARC, and locking down exposed files — then re-scan to confirm each one is in place. It's a hands-on service, distinct from the automated scan, and is not a certified audit.
Does Hardn exploit or attack my site?
No. Hardn only performs passive and light-auth checks. It observes what your site already exposes to any visitor and never sends attack payloads, attempts authentication bypass, or causes load. It is an automated hardening scan, not a penetration test.
What does Hardn check?
Live today: TLS configuration and certificate expiry, HTTP security headers (CSP, HSTS, X-Frame-Options and others), SPF/DKIM/DMARC email authentication, and publicly exposed files such as .env and .git. Rolling out next: dependency CVEs from your lockfile, and passive cloud bucket misconfigurations.
How is Hardn different from free tools plus ChatGPT?
Free checkers give you a one-time grade per tool, and a generic AI explanation doesn't know your stack or your business. Hardn consolidates your checks into one report, scores each risk in context, and writes fixes for your exact stack with a command to verify them — with scheduled re-scans and drift alerts rolling out so it keeps catching what changes after you ship.