Frequently Asked Questions
Everything you need to know about Biz Secure Online. Can't find what you're looking for? Contact us and we'll help.
Commercial & Account
No. Buy one website or fifty, at the same price each. There used to be a four-website minimum on our top plan and we removed it, because it meant the price we advertised was not a price anyone could actually pay.
A free account is scanned monthly. Any website you pay for can be set to daily, weekly or monthly, and you choose that per website, so a critical site can run daily while a brochure site runs monthly. You can also run an on-demand scan whenever you want one.
No. Essential Eight is sold on its own, per company per month. Your free account still covers one website scanned monthly, and what that scan finds attaches itself to the controls it evidences. Worth knowing: Maturity Level 1 asks for internet-facing patches within two weeks, and a monthly scan cannot evidence that window: it finds the issues but not the response time. Weekly or daily scanning can.
Yes. Go to the subscription page and adjust the number of websites up or down at any time; billing is prorated automatically. Essential Eight company licences and team members work the same way.
Right now we don't support enterprise-sized accounts who support hundreds of sites. We are focused on providing a best-in-class product and customer service for SMEs who support up to 50 domains. We want to make sure that our backend scanning layer is rock-solid reliable before we take on the biggest customers in the marketplace. All things are changing fast so stay in touch for when this changes.
Technical
No. Biz Secure Online's scanners test the public perimeter of your digital service. We do not install software of any kind on your infrastructure.
- Availability: Confirms the site is reachable
- Security Headers: Evaluates HSTS, CSP, X-Frame-Options
- Technology Detection: HTML/header pattern matching to identify CMS (WordPress, Shopify, Wix, etc.)
- SSL/TLS: Certificate validation, expiry, and protocol probing
- Performance: Google PageSpeed Insights
- SEO: A blend of third-party solutions and our own HTML pattern analysis
- Nmap: TCP connect scan for port checking
- Nuclei: Template-based vulnerability scanner, updated every scan to test for latest vulnerabilities
- WPScan (conditional): WordPress-specific plugin/theme/core vulnerability scanning
Results are aggregated and an AI executive summary is generated.
As we are a security scanning solution we are always evaluating new tools that add value for an SME business, so this list will grow over time.
We test your public perimeter, which is what the outside world can see about your website or online service. It's the first line of defence, and often the most vulnerable. We scan what the internet sees such as exposed services, misconfigurations, outdated software, open ports, insecure headers, SSL problems, your site's loading speed and how your SEO is configured. This is what anyone from script-kiddies to the North Koreans can see. If you have a business website on the internet, then this is the bare minimum of stuff you should be aware of.
Our scan engine has been configured to give the best essential site information in the shortest possible time. Generally that's about 15 minutes as a rule of thumb. For sites that function as digital business cards - static text without any interactive features such as calendar booking, document upload or handling newsletter interest submissions - this can be somewhat shorter. Similarly, for large sites, it will take around 20% more time.
Great stuff. You're the sort of business we would really like to talk to. Drop us an email at support@bizsecure.online and get a conversation started. A good starting point is, if it's an opensource project on GitHub or the like, and it adds good information that would be of value to small business, we're very interested to learn about it and consider it for our service.
No, we cannot fix issues on your hosting servers. This requires someone with LOGIN and ADMINISTRATOR access to go into your server environment and make changes. Because we do not have ADMINISTRATOR access to your hosting environment we cannot make changes that will fix issues we find.
However, we understand the pressing need that SMEs have for remediation services to fix issues our service finds. We are looking at options to offer remediation services. Check in with us regularly on this.
All About Our Scan Report
Every scan starts at a perfect score of 100. Our engine then deducts points based on what it finds: vulnerability severity, missing security headers, high-risk open ports, and WordPress-specific issues.
The final score is clamped between 1 and 100. A score of 85–100 is strong, 60–84 is moderate, and below 60 needs urgent attention.
SEO and performance scores are reported separately and do not affect the security score.
For a detailed explanation, see our guide: How We Calculate Your Security Score.
We have a growing library of plain-language guides that explain every component of your scan report, from SSL/TLS and security headers to performance metrics and open ports. Visit our Guides section to browse them all.
The AI prompts are the last step in the scanning stages. After all the test data is obtained and run through a santisation process to remove duplicates and false positives, it is pushed to Anthropic's Haiku model where the prompts are created. The prompts are then put into the final report and stylised with our presentation theme. Each prompt is custom generated from the data from the scan engine, providing highly specific advice on the impact of the discovered issues and how to fix them.
