Mission control for
your stack.
OrionCmd watches uptime, certificates, DNS, email health, firewalls and security exposure — from the outside, around the clock, in plain English. Nothing to install. Routine monitoring is passive-first, with common-port reachability probes and optional authorized scans. One site or fifty client networks — same watch.
Seven stars. Seven layers under watch.
The hunter's brightest stars, mapped to what OrionCmd watches on every site you add.
Is the site up and answering? Checked around the clock.
Certificates graded and expiry tracked before anything lapses.
Nameservers, records and registration watched for silent changes.
The red giant. When something needs you, you hear about it fast.
SPF, DKIM and DMARC watched so your mail keeps landing.
Headers, stack and known issues — observed, never attacked.
The brightest star. One composite grade for overall exposure.
Full-sky coverage.
Twenty-one capabilities across three watch stations. Passive-first monitoring, lightweight reachability probes, and optional authorized scans.
HTTP Availability
Millisecond-precision status & keyword checks with intelligent anti-flap detection.
DNS Resolution
Continuous mapping of A, AAAA, CNAME, and MX records to ensure reachability.
Firewall Endpoint Watch
Up/down heartbeat for client firewall IPs with automatic common-port probing — a dead perimeter never goes unnoticed.
SSL / TLS Expiry
Precise expiration tracking so your certs never lapse unexpectedly.
TLS Grading
Deep analysis of protocols, ciphers, and chains yielding A+ to F security grades.
Domain Expiry & Integrity
Track RDAP/WHOIS limits and detect unauthorized nameserver or delegation changes.
Email Deliverability
MX record validation and real-time Spamhaus / Barracuda DNSBL checking.
Email Authentication
Basic (SPF/DMARC) and Pro (DKIM, DMARC reject, MTA-STS, TLS-RPT, BIMI) coverage.
Search Indexability
Monitor robots.txt and noindex headers to protect your SEO rankings.
Defacement Detection
Cryptographic homepage hash diffing to instantly alert you of unauthorized changes.
Threat Reputation
Continuous cross-referencing against Google Web Risk & Safe Browsing.
Passive Web Security
Validation of CSP, HSTS, XFO headers, secure cookie flags, and mixed content.
Stack Fingerprinting
Identification of 50+ underlying technologies, frameworks, and CMS versions.
Vulnerability & CVE Mapping
Automated OSV.dev integration to match your stack against known vulnerabilities.
Performance Audit
Deep Lighthouse profiling via PageSpeed Insights for speed and accessibility.
Non-Intrusive Scan
Optional, authorized Nuclei checks use curated templates to identify exposed panels, misconfigurations, and known-vulnerable surfaces without exploit payloads.
Passive Web Scan
Optional OWASP ZAP bounded crawling and passive response analysis of an authorized target — no active attack payloads.
Automated Client Reports
Beautiful PDF/HTML exports with AI-generated incident explanations.
Public Status Pages
Subscriber notifications and transparent downtime reporting for your users.
Operator Alerting
Instant Slack, Discord, and Webhook dispatches with configurable quiet hours.
Auth-Gated Scans
Strictly enforced signed scope authorizations and ownership affirmation.
Watching in three moves.
Add a site
Type a web address or a firewall IP. That's the whole setup — no software, no agents, nothing installed on your side.
We keep watch
Routine checks observe from outside your network. Firewall monitoring probes common ports for reachability, and optional security scans run only on targets you affirm you are authorized to test.
You get told
When something drifts — downtime, an expiring certificate, a DNS change — an alert goes out in plain English, with what to check first.
Frequently asked questions.
Do I need to install anything?
No. Every check runs from the outside, the same way your visitors reach your site. No agents, no plugins, no passwords to hand over — type an address and it's under watch.
Will the checks slow down or harm my site?
Routine monitoring is designed to be lightweight and runs from outside your network. Firewall reachability uses common-port connection probes. Optional security scans run only after you affirm authorization and use bounded checks; OrionCmd does not log in or send exploit payloads.
How do I find out when something breaks?
Checks run around the clock; when one spots trouble — downtime, a certificate about to lapse, a DNS change — an alert goes out, and another when it recovers. Email by default, with Slack, Discord, and webhook options. Set quiet hours if you'd rather not get notices overnight.
What's included for free?
Uptime checks, SSL certificate tracking, and domain-expiry watch on your sites — free, with no time limit. Paid plans add deeper security scanning, email-authentication checks, client management, and reports.
I look after websites for clients — is this for me?
Yes. Organize monitors per client, give each client their own read-only portal, and send clean status reports. It's built for MSPs and agencies as much as for single-site owners.
My site went down at 3am — what happens?
Checks run every few minutes, so you hear about it quickly — and again when it's back. If you've set quiet hours, notices wait for your window. Either way, the dashboard keeps a day-by-day history so you can show exactly what happened and for how long.
Do you fix the problems you find?
No — and that's deliberate. OrionCmd tells you what changed, why it matters, and what to check first. The fixing stays with you or your IT person, so our alerts never double as a sales pitch.
Who can see my monitoring data?
Only you — and a client only if you explicitly invite them to their own portal, where they see just their sites. Monitoring data is never sold or shared.
Illustrative OrionCmd dashboard preview

ILLUSTRATIVE PRODUCT PREVIEW — NOT LIVE CUSTOMER DATA