Ping

Ping. Is it up?

Pathly watches the path. Ping if it’s up. Flow if a user can walk it. Chain if the services behind it hold. TLS and headers stay a secondary signal.

Pathly HTTP probe with security grade

What the watch measures

The site responds, and how fast, from Europe. The TLS certificate is valid, on the right name, and not expiring soon. HTTPS is actually enforced, not merely available. Six usual headers are checked: HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy. Cookies carry Secure and HttpOnly. The server doesn't advertise its software and version.

Pathly product screenshot

An A–F grade, and above all its trend

Every monitored site gets a score out of 100 and a grade from A to F, recomputed every six hours. The grade alone is of limited interest. What matters is the day it drops from B to D because a deploy removed the CSP: that day you get an alert, not a report nobody opens.

Pathly product screenshot

The one-off audit goes further

Auditing a public page adds what would be absurd to measure hourly: SPF and DMARC, domain expiry, dead internal links, a www variant that fails, redirects leaving the domain. No account, about thirty seconds.

Pathly product screenshot

Why it's separate from journeys

An availability probe costs one request, a browser journey costs a full Chrome. Mixing them would mean billing the first at the price of the second. So you put the watch on every site, and journeys on those whose funnel earns money.

Pathly product screenshot

Plain ping and Pathly Veille

What is seenHTTP pingPathly Veille
The site respondsyesyes
TLS certificate near expirysometimesyes, with notice
Security headersnosix headers graded
Cookies without Secure or HttpOnlynoyes
Alert when the grade dropsnoyes

FAQ

Is this a penetration test?
No. Pathly Veille reads what your site already publishes: response headers, certificate, public DNS. No authentication attempt, no hunt for exploitable flaws, no malicious payload. It is an outside hygiene check, not a pentest.
How often is the grade recomputed?
Every six hours on each monitored site. Availability itself is checked at your plan's frequency, down to once a minute.
Does the grade replace a full security audit?
No. It measures whether protections are present, not how well they are configured: a permissive CSP counts as present. It catches omissions and regressions, not application flaws.
Can I audit a prospect's site before taking it on?
Yes, on a public page and without an account. Agencies do this before a meeting. The audit never touches a login page, a checkout funnel or a payment.

Product proof

What you show the client

01

The alert, before opening

Alert screenshot: failed step, time, store. You get it before the site opens.

02

The invoice attachment

First page of the monthly PDF report — attach it to the maintenance invoice (Business).

03

Nothing to install on the client site

No admin access, no plugin, no FTP. You record the checkout as a visitor. Data in the European Union. One measurement origin.

Put the watch on your sites

Five sites watched on the Solo plan, no credit card.

Create my workspace — free

Audit a site now