The tools that keep you compliant and secured — every day, not just on audit day.
qzila is a family of small, single-purpose tools built by security auditors: each one watches one thing — your email, TLS, DNS, headers, uptime, brand or people — and speaks up the moment it changes.
Free to start on every tool — no card, no time limit. You pay only for what grows beyond the free tier.
Every tool does one thing properly
Independent tools that share one account, one alert hub and one bill. Every one of them has a free tier — use one, or all of them.
SafeCheck
Someone sent you a link or an attachment and you are not sure — check it before anyone clicks.
Security Headers
Know your website's security-header grade and get told when a deploy quietly makes it worse.
TLS Scanner
Get warned before a certificate expires or a change turns on a weak TLS protocol.
Email Security
Make sure nobody can send email pretending to be your company — and prove it to the auditor.
Uptime Monitor
An alarm rings when your site or API goes down, and again when it is back.
ServiceWatch
One screen that shows what is red across all your tools right now, and who was told.
DNS Monitor
Know within minutes if someone changes your DNS — your MX, your nameservers, your website's address.
Typosquat Monitor
Hear when someone registers a lookalike of your domain, before they use it to phish your customers.
Snapshots
Catch a defaced or accidentally changed page the day it happens, with a before/after picture.
Breach Monitor
Find out which of your staff's addresses turned up in a data breach, the day it is published.
Auditor
Run your ISO 27001 or NIS2 audit with findings, evidence requests and deadlines in one place.
Asign
Run your whole NIS2 or ISO 27001 programme — risks, controls, vendors, incidents and evidence — in one place.
A letter grade and the exact fix
Every check ends in a grade you can put in front of the board — and, underneath, the exact record, header or setting to change. No 400-line scanner export.
- SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI
- CSP, HSTS and the other response headers
- TLS protocols, ciphers and certificate expiry
- SPF v=spf1 include:_spf.google.com -all
- DKIM google · 2048-bit
- DMARC p=quarantine · adkim=s · aspf=s
- MTA-STS mode: testing → enforce
- BIMI /bimi/logo.svg
Hear about it the moment it changes
Every tool runs on a schedule and pushes a signal into one alert hub. From there it goes wherever your team already looks: email, Slack, a webhook, SMS or a Jira ticket.
- One hub for every tool
- Verdict flips, new findings, incidents open and close
- Per-asset history for the auditor
Grade dropped A → B — TLS 1.0 enabled after a load-balancer change.
One invoice, itemised per tool
A public price per unit, metered monthly. Add a domain and it starts billing; remove it and it stops the same day. Set a budget and get warned before you reach it.
- No minimum, no annual licence, no contract
- Usage overview per tool, exportable
- Prices listed in your account
| Email Security | 4 domains | € 12.00 |
| Uptime Monitor | 12 monitors | € 18.00 |
| TLS Scanner | 6 endpoints | € 9.00 |
| Snapshots | 40 pages | € 20.00 |
| Total excl. VAT | € 59.00 | |
- 11tools, one account
- 15+threat-intelligence sources behind SafeCheck
- 3regions watching your uptime
- EUbuilt and hosted in the European Union
How it works
Sign in once
One qzila identity opens every tool. No separate accounts, no separate invoices.
Add what to watch
A domain, a URL, a host, a page — the unit of work is always something you own.
Get told when it changes
Every signal goes to the alert hub and on to email, Slack, webhook, SMS or Jira.
Show the evidence
History and verdicts stay in the tool, ready for the auditor, the board or the customer.
Built by the people who run the audits
Forged in real audits
We run ISO 27001, NIS2 and DORA audits for a living. Every tool here was built because an engagement demanded it — then hardened on the next hundred.
Free to start. Honest to scale.
A small estate costs nothing, ever. Beyond it you pay a public price per unit, metered monthly, visible per tool — no bundles, no tiers, no sales call to learn the number.
Evidence, not screenshots
Each signal lands in the Asign GRC platform as a risk or a piece of evidence with a timestamp. Compliance becomes a running process, not a report you rebuild every year.
European by design
Built, hosted and operated in the EU. Your data never leaves it, and the people who answer your questions are the ones who wrote the code.
Need the whole picture? Asign.
Asign is the GRC platform for NIS2, DORA and ISO 27001 — risk analysis, BIA, vendor management, incident management, training and automated evidence collection. qzila tools plug into it.
Start with one tool. Add the rest when you need them.
Sign in once and every tool is a click away. You pay only for what you watch, per month, with no minimum and no contract — the price list is in your account before you add anything.
- One account across every qzila tool
- Free tier on every tool, then pay-as-you-go
- Alerts to email, Slack, webhook, SMS or Jira