Frequently Asked Questions
Find answers to common questions about our cybersecurity tools, website scanning, security scoring, password safety, and CyberShield Pro platform features.
CyberShield Pro is a modular cybersecurity health platform that provides both free scanning tools and SaaS-based continuous monitoring for small businesses, developers, and agencies. It combines website vulnerability scanning, SSL/TLS certificate checking, security headers analysis, DNS and email security auditing, password strength testing, and an overall cybersecurity scorecard — all accessible from a single unified dashboard designed for non-security experts.
Yes, our website vulnerability scanner performs only non-destructive, publicly observable passive checks. It inspects HTTPS configuration, TLS certificates, HTTP security headers, DNS records, cookie attributes, and exposed services without attempting to exploit any vulnerabilities, modify data, or send authenticated requests. It is a defensive security assessment tool, not an offensive penetration testing platform, making it completely safe for any website owner to use.
No, our password strength checker runs 100% client-side in your browser using JavaScript. Your passwords never leave your device, are never transmitted over the network, and are never stored on our servers. The tool calculates entropy scores, checks against common password patterns, and estimates crack times locally — making it a privacy-first approach to password security testing that you can trust with your credentials.
The free plan includes one-off website security scans, a basic cybersecurity score with category breakdowns, limited PDF export of scan reports, educational remediation recommendations tailored to your specific findings, and unlimited access to all individual security checker tools including the SSL checker, headers analyzer, DNS security checker, and password strength tester. No credit card is required to start using the free plan.
Our security scoring engine performs a weighted analysis across multiple categories: HTTPS/TLS configuration (certificate validity, cipher strength, protocol support), security headers (CSP, HSTS, X-Frame-Options, and more), DNS and email authentication records (SPF, DKIM, DMARC, DNSSEC), cookie security flags, and OWASP-oriented misconfigurations. Each check is weighted by severity, and the final score reflects your overall security posture on a 0-100 scale with color-coded grades from A to F.
The free tier allows individual on-demand scans for any domain, one at a time, which is ideal for testing your primary business website. Paid plans support scanning multiple domains simultaneously with scheduled recurring scans: Business covers up to 5 domains, Professional supports 20 domains, Team handles up to 50 domains, and MSP/Agency plans include unlimited domains with multi-client dashboards for service providers managing security across multiple organizations.
We accept payments via Stripe and PayPal, including all major credit and debit cards (Visa, Mastercard, American Express, Discover). For Team and MSP/Agency plan subscribers, we also offer annual invoicing with net-30 payment terms upon request. All transactions are processed through PCI-compliant payment gateways, and we never store your full credit card details on our servers.
Scan frequency depends on your subscription tier: Business plans include daily automated scans of all configured domains, Personal plans provide weekly scheduled scans, and Professional, Team, and MSP plans support fully configurable scan intervals ranging from daily to near-real-time monitoring. All paid plans include email alerts when new security issues are detected, so you never miss a degradation in your security posture.
Yes, you can cancel your subscription at any time with no cancellation fees, hidden penalties, or long-term contract obligations. Your access to paid features continues until the end of your current billing period when you cancel. You can also downgrade to the free plan at any point, and your historical scan data remains available in read-only mode for 30 days after cancellation to facilitate a smooth transition.
Free scan data is stored temporarily in your browser session and discarded when you close the page. Paid plan subscribers retain complete scan history and security score trends according to their plan tier: Personal retains 30 days, Business retains 90 days, and Professional/Team/MSP plans retain up to one year of historical data. We never sell, share, or use your scan data for any purpose other than providing the security monitoring service to you.
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication protocol that prevents attackers from spoofing your domain in phishing and business email compromise attacks. It builds on SPF and DKIM to tell receiving mail servers how to handle unauthenticated email claiming to be from your domain. Without a properly configured DMARC policy, cybercriminals can impersonate your business email to scam customers, partners, and employees.
Start by addressing the top-priority security gaps identified in your scan results. Our platform provides prioritized, actionable remediation recommendations for each finding — starting with critical issues like missing HSTS headers, expired TLS certificates, and absent DMARC policies. Work through the recommendations systematically, re-scan after applying each fix, and watch your security score improve. Paid plans include score trend tracking so you can measure your cybersecurity improvement over time and demonstrate progress to stakeholders.