WEBSITE INTELLIGENCE
See the whole website risk surface — and what to improve next.
Quantivus Observatory brings passive security checks, technical SEO, accessibility, privacy, performance and regulatory evidence into one inspectable workflow. Teams receive findings with context, reproducible evidence and reports that can move directly into remediation and governance.
- 21
- bounded analysis modules
- 5,078
- inspectable catalog tests
- 7
- report formats
One assessment, six decision layers
A website can be fast and still expose risky headers, inaccessible interactions, broken links or weak privacy signals. Observatory evaluates these concerns together so engineering, security, marketing and governance teams work from the same evidence.
- Passive security posture and public attack-surface indicators
- Technical SEO, metadata, crawlability and content quality
- Accessibility and responsive experience checks
- Performance and browser-rendered measurements
- Privacy, cookie and third-party technology observations
- Evidence mapping for EU AI Act, BSI and other governance frameworks
Example: launch a new customer portal with fewer blind spots
Before launching a new portal, a digital team can scan the planned public domain, then share one prioritized view with development, marketing and privacy. The security owner sees exposed headers and transport signals; the SEO lead sees indexability and metadata; the accessibility reviewer sees interaction barriers; and the DPO sees cookie and third-party observations.
- Run a baseline before go-live and record the evidence
- Assign technical findings to the responsible delivery team
- Export a management summary and a developer-ready remediation list
- Schedule recurring checks after the portal is live
A transparent test catalog
The repository exposes 194 native checks and 4,884 eligible upstream HTTP definitions across the catalog. Discovery, applicability, execution errors, matches and exclusions remain separate; a no-match result is never presented as a certification.
- Per-test identity, module, version and evidence source
- Documented reasons for excluded upstream definitions
- Bounded time budgets and partial-result handling
- Module selection for the target and assessment objective
- Inspectability for technical and non-technical reviewers
- Versioned plans for controlled evolution
Safe scanning by design
Targets are validated before and during a scan. Public-address and allowed-port enforcement, DNS pinning and redirect re-validation reduce SSRF and target-switching risks. Optional active templates require verified control and explicit authorization.
- Public-target validation and redirect checks
- Tenant-scoped admission, quotas and API keys
- Isolated browser and template runners where enabled
- Bounded workers and cancellable job states
- Immutable report attachments and controlled retention
- Only scan assets you own or are authorized to assess
Reports that fit the next workflow
Results can be archived and delivered in the format needed by developers, auditors or decision-makers. Language is selected per export rather than being tied to the operator interface.
- HTML, JSON, CSV and SARIF for technical workflows
- Markdown and DOCX for collaborative remediation
- PDF for management and audit communication
- English, German and Brazilian Portuguese output
- Signed archive packages and legal-hold support
- Scheduled monitoring and verified-recipient delivery
Separate experiences for each operating role
Customer, agency and Quantivus administration run as distinct portal surfaces. This separation supports white-label agency operations, customer workspaces and central platform governance without mixing responsibilities.
- Customer projects, scans, reports and remediation
- Agency portfolio and branding controls
- Central customer access grants and expiration
- Jobs, statistics, usage and quality trends
- Stripe subscription and consumable-quota integration
- Calendar monitoring, alerts and priority queues
Deployment and fit
Observatory is built on ASP.NET Core 10 and Blazor with containerized API, workers and data services. PostgreSQL, Redis and MinIO adapters support durable operations. External providers and active testing remain subject to documented configuration and acceptance gates.
- Website owners with multiple public properties
- Agencies that need repeatable, customer-ready reporting
- Engineering and security teams prioritizing remediation
- Governance teams building auditable evidence
- Organizations requiring multilingual reporting
- Programs that need monitoring instead of one-off audits
Website audits and monitoring: choosing the right scope
An SEO audit focuses on crawlability, metadata and technical content issues. A website security assessment examines security exposure, while an accessibility review considers how people use the site. Quantivus Observatory brings these perspectives together so teams can prioritize findings in context.
- For agencies: repeatable website audits and client reports
- For website operators: recurring monitoring and remediation priorities
- For security and compliance teams: documented findings for human review
FAQ
Questions, answered clearly
Scope, deployment and commercial terms are confirmed for your use case.
Does a clean result prove compliance?
No. Observatory reports observed evidence and test outcomes. A no-match or passed technical check is not a legal certification.
Can agencies manage several customers?
Yes. The architecture separates agency and customer portals, supports portfolio operations and allows agency-level branding and email configuration.
Which report formats are available?
The documented pipeline supports HTML, JSON, CSV, SARIF, Markdown, DOCX and PDF, with localized exports.
Can Observatory run recurring checks?
Yes. Opt-in monitors, calendar scheduling, alerts and report archiving are part of the platform design; deployment-specific integrations must be configured.
How do I choose the right scope?
Start with one use case, the people involved and the evidence you need. In a demo, agree on integrations, access permissions and the operational scope before rollout.
NEXT STEP
Turn website findings into a prioritized improvement plan.
Tell us which domains, reporting languages and evidence frameworks matter to you. We will define a safe assessment scope and the right operating model.