Is there a multi-tenant view, or one account per client?
+
One account holds every domain, grouped as personal, business or client, and the client grouping is what separates one tenant from another in the portfolio view. There is no per-tenant login handoff today. If a client wants their own account they create one and add their own domains, and the two accounts are independent.
How does the CVE alerting avoid drowning us in noise?
+
By re-asking the question against evidence. A KEV or NVD entry that name-matches something on the watchlist is only a catalogue match. DomainGuard then checks it against what scans actually observed on that account — scanner findings citing the CVE, components seen running with a version, service banners from open ports, and the published affected-version ranges — and labels the alert confirmed, possible, not affected, or unconfirmed. Unconfirmed means we have never observed the product, not that you are safe, and the interface says so in those words.
Can we pull this into our own reporting?
+
Yes, two ways. Pro includes read-only API keys and the MCP server, so an assistant or a script can read the account. Enterprise adds the write scope. PDF reports start at Starter if you would rather hand over a document than build one.
What happens to a tenant we stop managing?
+
Remove the domain. Nothing is deleted implicitly, and going over an automation cap never makes a domain read-only or drops it from the list — the oldest domains keep the automation and the rest scan on demand.
How much of this is free?
+
Every health module, on every domain, run whenever you ask: DNS and registrar records, SSL, SPF, DKIM and the DMARC record, uptime, blacklists, security headers, the website scan, the vulnerability scanner, tech detection and the compliance tracker. Free also keeps the five-minute uptime probe on three domains, one monitored address for dark-web exposure, and KEV/CVE alerts. Automation beyond that starts at $6.99 a month.