The alert, before opening
Alert screenshot: failed step, time, store. You get it before the site opens.
Ping
Pathly watches the path. Ping if it’s up. Flow if a user can walk it. Chain if the services behind it hold. TLS and headers stay a secondary signal.

The site responds, and how fast, from Europe. The TLS certificate is valid, on the right name, and not expiring soon. HTTPS is actually enforced, not merely available. Six usual headers are checked: HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy. Cookies carry Secure and HttpOnly. The server doesn't advertise its software and version.

Every monitored site gets a score out of 100 and a grade from A to F, recomputed every six hours. The grade alone is of limited interest. What matters is the day it drops from B to D because a deploy removed the CSP: that day you get an alert, not a report nobody opens.

Auditing a public page adds what would be absurd to measure hourly: SPF and DMARC, domain expiry, dead internal links, a www variant that fails, redirects leaving the domain. No account, about thirty seconds.

An availability probe costs one request, a browser journey costs a full Chrome. Mixing them would mean billing the first at the price of the second. So you put the watch on every site, and journeys on those whose funnel earns money.

| What is seen | HTTP ping | Pathly Veille |
|---|---|---|
| The site responds | yes | yes |
| TLS certificate near expiry | sometimes | yes, with notice |
| Security headers | no | six headers graded |
| Cookies without Secure or HttpOnly | no | yes |
| Alert when the grade drops | no | yes |



Product proof
Alert screenshot: failed step, time, store. You get it before the site opens.
First page of the monthly PDF report — attach it to the maintenance invoice (Business).
No admin access, no plugin, no FTP. You record the checkout as a visitor. Data in the European Union. One measurement origin.
Five sites watched on the Solo plan, no credit card.
Create my workspace — free