Skip to content
ABOUT NIVARONIX

Building reliable infrastructure through secure engineering.

Nivaronix exists to simplify the complexity of building, securing, and operating modern software systems. We believe technology should remove complexity, not create it.

Our Mission

Technology should remove complexity, not create it.

  • Secure defaults built into every workflow

  • Engineering discipline over marketing hype

  • Transparent systems with clear visibility

  • Practical solutions for real infrastructure challenges

Engineering Principles

These principles guide every decision we make about product design, infrastructure, and team culture.

Security by Design

Security is not an afterthought. It's integrated into every development workflow, from code review to deployment.

Developer First

Tools should improve engineering velocity, not slow it down. We optimize for developer experience.

Transparent Systems

Clear visibility into infrastructure health and security status. No black boxes. No surprises.

Continuous Improvement

Software reliability requires iteration. We embrace feedback and evolve based on real-world usage.

What Nivaronix is

Nivaronix is an external, agentless security monitoring platform. It assesses a domain's public-facing SSL/TLS certificates, DNS configuration, and HTTP security headers with a read-only scan, then re-runs the same checks on a schedule to detect when a result changes for the worse. When it does, Nivaronix opens an incident, notifies the account, escalates once if unacknowledged, and requires a person to record a written root cause before the incident is marked resolved — it does not resolve incidents itself. An optional, request-only AI layer can explain an already-recorded finding or incident in plain language after the fact; it never performs the detection, and its output is kept separate from the deterministic result it describes.

The lifecycle, connected end to end

Each stage below feeds the next. Nothing here is an independent feature — a scan that never repeats cannot detect change, a change that is never classified cannot become an incident, and an incident nobody explains or resolves is just an unread alert.

  1. Scan. A one-time or recurring check reads certificates, DNS records, HTTP security headers, cookie flags and redirects for a domain you own, operate, or are authorized to assess.
  2. Findings. Each result is scored by severity and rolled into an overall security score, using the same fixed rule described on the methodology page.
  3. Continuous monitoring. Verifying a domain moves it from a one-off assessment to a recurring schedule (a 15-minute floor on Free and Starter, 5 minutes on Pro and Studio), and every run is recorded rather than overwriting the last. See what continuous monitoring means in practice.
  4. Detect change. Consecutive recorded observations are compared. Where they differ, a change event is written with the before and after values — an expiring certificate, a removed security header, a moved server IP.
  5. Respond (incident). A failing check opens an incident. It is alerted once confirmed still open, escalated once if nobody acknowledges it within your threshold, then owned and worked by a person.
  6. AI explanation (advisory, after the fact). On request, an optional layer explains a change event or incident already on record — what changed, why it matters, a suggested action — using only the data already attached to that event. It runs after detection, never in place of it, and its output is stored and labelled separately from the deterministic finding.
  7. Remedy.A governed, approval-gated remediation capability exists for select providers (a Cloudflare connector, Nivaronix's own Protection Agent, and a generic webhook connector). It has not yet executed end to end against a live customer target, so it is described as available-but-unproven rather than a delivered self-driving capability — see Limitations below.
  8. Verification. There is no separate automatic verification step. The way you confirm a fix is the same mechanism as the first stage: apply the fix, then rescan, and let the next recorded observation show whether the finding cleared. See how to verify a fix actually worked for common false-fix traps.
  9. Reports & audit. Findings, incidents and their recorded resolutions export as PDF, CSV or JSON, and every mutating action a customer takes is written to an audit log.

Who uses it

General visitor

Run one free, read-only scan of a domain you own or are authorized to assess — SSL/TLS, DNS and HTTP security headers — with results in seconds and no account required. Anonymous results are deleted after seven days unless you choose to share them.

Developer

Get a scan plus the fix steps for each finding, then rescan to confirm the fix landed. Fixing the issue is still yours to do — Nivaronix hands you the steps, it does not apply them.

Startup

Move from a one-off scan to continuous monitoring on verified assets — the Free tier includes 3 assets running the same checks as every paid plan — with a security score, certificate-expiry alerts, and exportable PDF, CSV or JSON reports.

Agency

Organize client domains under separate clients, monitor them continuously, and export white-label reports on the Studio plan. Archived clients keep their history without being deleted.

Student

Earn skill credentials from real findings on assets you verified and monitor yourself, awarded by a rescan confirming the fix — not self-reported. This is a learning-progress feature, separate from incident response.

Enterprise teams (Scale plan)

Get policy-as-code governance, approval workflows for actions a policy flags as sensitive, and an audit trail written before a verdict returns. Single sign-on and SCIM provisioning both come with Scale, set up against your identity provider as part of a negotiated deal rather than self-serve. “Enterprise” describes this audience, not a purchasable plan name — Scale is.

Agencies managing many client domains: see how agencies can monitor security across client websites.

Agentless and read-only

Nivaronix installs nothing on your infrastructure and holds no credentials to it. Checks run as outbound requests from Nivaronix's own infrastructure against what is already publicly reachable — the same requests a browser or search engine would make. That means there is a small, real request footprint (a scheduled homepage GET plus robots.txt and sitemap.xml) rather than a zero-impact or invisible one; see the security page for what is and is not stored from that traffic, and agentless vs. authenticated scanning for what this model can and cannot see compared to an authenticated assessment.

Limitations

  • A scan reads publicly observable configuration — certificates, DNS, HTTP headers, cookies, redirects and detectable technologies. It does not test application logic, authenticate into a target, attempt exploitation, or perform penetration testing.
  • Nivaronix runs no attack-blocking, WAF or intrusion-prevention capability. It detects configuration drift and known-bad states; it does not prevent an attack from happening.
  • The scan is read-only but not zero-impact: each check issues real outbound HTTP/DNS requests (a homepage GET plus robots.txt and sitemap.xml) on a schedule. Those requests are small and read-only, not invisible or footprint-free.
  • The optional AI layer explains a finding or incident that a deterministic check already recorded. It never performs the detection itself, and its output is stored separately from the deterministic result it explains.
  • A governed, approval-gated remediation capability (Remedy) exists in the product for select providers, including a Cloudflare connector, Nivaronix's own Protection Agent, and a generic webhook connector — but it has not yet executed end to end against a live customer target. Until it has, remediation is described as available-but-unproven, not as a delivered, self-driving capability.
  • Nivaronix holds no SOC 2 report or ISO 27001 certificate and is not undergoing an audit for either. It can help a customer build evidence toward their own compliance audit; it cannot claim to prove or certify anyone's compliance, including its own.
  • Audit logs are append-only at the database level with one explicit, deliberate exception for GDPR Article 17 erasure requests — “immutable” overstates a system that has a designed carve-out.

Related pages

  • Methodology — how the scan and score actually work.
  • Security — what Nivaronix stores, and what it does with scan data.
  • Pricing — what each plan includes.
  • Docs — API and integration reference.

Technical Foundation

Built with modern, proven technologies designed for security and scale.

Frontend

  • Next.js 16
  • React 19
  • TypeScript
  • Tailwind CSS

Backend

  • FastAPI
  • Python
  • PostgreSQL
  • Redis

Infrastructure

  • Docker
  • Single-region deployment
  • Automated deployments
  • Nightly backups

Product Roadmap

Our direction is public. We iterate based on real usage and customer feedback.

  1. Foundation

    Core platform — security scanning, monitoring, reporting

    Shipped
    • Domain & certificate scanning

    • DNS, TLS and header checks

    • Continuous monitoring & alerting

    • Team accounts & seats

    • REST API v1 with scoped keys

    • Webhook & Slack incoming-webhook alerts

    • Customer audit log

  2. Platform Expansion

    Developer tooling and integrations

    Planned
    • GitHub / GitLab integration

    • Slack app with channel picker (incoming webhooks already work)

    • PagerDuty integration

    • Custom dashboards

  3. Security Automation

    Unattended remediation and customer compliance reporting

    Planned
    • Unattended remediation, once it is proven against a live provider

    • Compliance reporting for your own audits — evidence you can map to SOC 2 or ISO 27001 controls. Nivaronix itself holds neither certification and is not undergoing an audit for either.

    • More providers for guarded remediation

  4. Developer Tooling

    CLI and local development tools

    Exploring
    • CLI for local scanning

    • Pre-commit hooks

    • IDE plugins

    • CI/CD pipeline integration

Ready to simplify your infrastructure?

Join engineering teams building reliable, secure software systems.