Endpoint Monitoring

Every Open Port, Judged Against What Your Customer Approved

Once a day the platform scans all 65,535 TCP ports on each endpoint (a server or IP address), from the outside. Nothing is installed on the server.

$1.50 per endpoint per month Firewall map included

What the Scan Finds

Every port and service that answers, checked against that customer's own Allowed Ports list. Green means open on purpose, red means open and nobody approved it. Nothing is allowed by default, not even 80 and 443.

How a Port's Severity Is Decided

Severity starts from what the port is. Database, remote desktop and legacy file-sharing ports (MySQL, PostgreSQL, Redis, RDP, VNC, SMB) start Critical. SSH, FTP, the mail ports, 8080 and 8443 start High, common development ports Medium, and 80 and 443 Low. A known vulnerability scoring 9 or more on CVSS then makes the finding Critical, 7 or more makes it High, and a banner advertising an end-of-life version raises it to High.

Allowed PortsExample
https:443Allowed
ssh:22Allowed
smtp:587Allowed
mysql:3306Not allowed

How Endpoint Monitoring Works

Every check runs automatically, to a schedule, on the platform's own infrastructure. The platform finds the exposure, grades it and delivers the alert. Your customer closes the port, and you support your customer.

Scanned From the Outside

Scanning runs on the platform's own infrastructure against the customer's public address, so there is no agent on their server. The scan is read-only: it sees what answers on a port and never logs in or changes anything.

A Full Sweep Every Day

Every active endpoint gets a full scan of all 65,535 TCP ports once a day. In between, a lighter pass runs every few minutes over a rotating tenth of the range plus every port known to be open, verifying any change with a deep scan. Scan Now runs on demand, once per endpoint per hour.

Allowed Ports

A rule covers one port or a range, for one protocol, on a single endpoint or across the whole account, with a written reason and an optional expiry date. It closes any matching open issue straight away.

Alerts With the Fix Attached

Each alert carries the severity, the port, a plain-language explanation of what an open port of that kind means, and copy-and-paste fix commands for UFW, iptables, AWS, GCP or Azure.

Issues That Close Themselves

Once the port is closed, the next scan sees it closed and the issue resolves itself after a 36-hour grace period in which the port has not reappeared. If it comes back within 30 days the original issue reopens instead of a duplicate. A customer can also acknowledge and resolve an issue by hand, which schedules a follow-up scan.

Scan History and Issue Timelines

Every endpoint has a Scan History tab: the 25 most recent scans, what changed since the one before, and the full history as a CSV. Every issue keeps a timeline of detections, acknowledgments, closures and reopens.

How an Alert Reaches Your Customer

By email and in the portal, in your WHMCS client area if you run the module, and in Slack once the customer connects it. Each customer picks immediate alerts or an hourly, daily or weekly digest.

What Lands in Their Inbox

Signed one-click links let your customer view the issue, acknowledge it, or add the port to Allowed Ports without logging in first, valid for up to 24 hours. A 60-minute throttle per endpoint and port keeps repeat mail down, bypassed for critical ports such as 22, 3306 and 3389. Every email carries your logo, your name as the sender and your support address for replies.

Security AlertExample
Admin panel on 8080 open to the internetHigh

Port 8080 answering on the public address · Not allowed

Close the port or restrict it to a trusted address →

The Firewall Map

A map of what the internet can reach and which of a customer's servers can reach which, drawn from their own firewall rules and cross-checked against the scan and their Allowed Ports. It comes with endpoint monitoring at no separate price.

Where the Rules Come From

A small script on each server reads the active firewall (UFW, firewalld, nftables or iptables) and posts the output over HTTPS with an API key, every six hours by default. It opens nothing, listens on nothing and changes nothing, and rules can be pasted in by hand instead. Docker is the common case: it publishes ports through its own rules and bypasses UFW, so a server can look locked down and still answer.

Firewall MapExample
https:443Rule found
ssh:22Rule found
postgres:5432No rule

What Your Tech Team Will Ask

Gentle on the Server

The deep scan is a standard SYN scan with a hard ceiling of 500 packets per second and a 15-minute cap per host, so a server sees a trickle of traffic and a scan cannot run away.

What Counts as an Endpoint

One IP address, or one hostname that resolves, re-resolved every hour. A range in CIDR notation is not accepted: each address is its own endpoint, and it is not a place where software is installed.

When a Customer Cancels or Downgrades

Nothing is deleted. When a WHMCS service is suspended, canceled or changed, paid capacity is recalculated, and if the customer is over it the newest resources are paused first. The oldest resume when capacity returns.

One Rate Per Endpoint

You pay $1.50 per endpoint per month, wholesale, in USD. 20 endpoints at $1.50 each is $30 a month. You set the retail price and keep the difference.

Frequently Asked Questions

How often are servers scanned?

Once a day for the full sweep of all 65,535 ports, with the lighter pass described above running between sweeps, every few minutes. A customer can also trigger a scan themselves, once per endpoint per hour.

What about ports that are supposed to be open?

They go on the customer's Allowed Ports list, and while the rule stands they raise no issue at all. The port still appears in scan history, marked as allowed rather than exposed. Partner admins can add rules that apply to every endpoint on the account.

What happens after a customer closes an exposed port?

Nothing by hand, and nothing instant either. Full scans run nightly and the issue only clears once the port has stayed shut through the 36-hour grace period, so expect a day or two. Scan Now does not shorten that wait.

How is the severity of an exposed port decided?

By what the port is, and then by what the scan finds answering on it. The full ladder is under What the Scan Finds, above: four fixed labels, with an unrecognized port defaulting to Medium and a known vulnerability or an end-of-life banner raising a finding to High or Critical.

Will the scan slow down my customer's server?

No. The scan is capped at 500 packets per second and 15 minutes per host, and it cannot exceed either limit. It never opens a session: it notes what answers on a port and stops there.

What can a customer add as an endpoint?

An IP address, or a hostname; a hostname that does not resolve is refused at the point it is added. Because the lookup repeats hourly, a server that changes address carries on being monitored and the change is written to the endpoint.

Can a customer acknowledge or clear an issue from the email?

Yes, from the email or the Slack message, without logging in: the buttons are signed links that stop working after 24 hours. An issue is acknowledged when someone has seen it and resolved when it has been dealt with, and each step lands on its timeline. There is no snooze or mute.

Illustration: a small rocket with a shield nose cone lifting off between soft clouds

Sell Endpoint Monitoring Under Your Own Brand

Wholesale is $1.50 per endpoint per month, and nothing is owed before your first customer is active.

Create a Partner AccountOr explore the live demo