Security and compliance checks that run every day, not just on audit day.
qzila is a family of small, single-purpose tools built by security auditors. Each one checks or watches one thing — your email authentication, TLS, security headers, DNS, uptime, web pages or lookalikes of your domain — and tells you when it changes.
To use the tools you need an account with a card on file — nothing is charged when you add it. The first €5 each month is free, and a €50 monthly cap, which you can lower, keeps the rest in check. SafeCheck, Security Headers, TLS Scanner and Email Security each run a single manual check without an account.
Every tool does one thing properly
Independent tools that share one account and one invoice. The check tools run a single check without an account; with one, the first €5 of usage each month is free.
SafeCheck
Someone sent you a link or an attachment and you are not sure — check it before anyone clicks.
Security Headers
Know your website's security-header grade and exactly which headers to change — and re-check after each release.
TLS Scanner
Confirm that a server no longer accepts old TLS versions and that its certificate is valid and not about to expire.
Email Security
See at a glance whether your domain publishes SPF, DKIM, DMARC and MTA-STS the way it should.
Uptime Monitor
An alarm rings when your site or API goes down, and again when it is back.
ServiceWatch
One screen that shows the state of your monitors and grades across the qzila tools.
DNS Monitor
See when someone changes your DNS — your MX, your nameservers, your website's address — and what it was before.
Typosquat Monitor
Hear when a lookalike of your domain appears or gets mail records, before it is used to phish your customers.
Snapshots
Catch a defaced or accidentally changed page the day it happens, with a before/after picture.
Breach Monitor
Find out which of your staff's addresses turned up in a data breach, the day it is published.
Auditor
Run your ISO 27001 or NIS2 audit with findings, evidence requests and deadlines in one place.
Asign
Run your whole NIS2 or ISO 27001 programme — risks, controls, vendors, incidents and evidence — in one place.
A letter grade and the exact fix
Every check ends in a grade you can put in front of the board — and, underneath, the exact record, header or setting to change. No endless scanner export.
- SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI
- CSP, HSTS and the other response headers
- TLS protocols, ciphers and certificate expiry
- SPF v=spf1 include:_spf.google.com -all
- DKIM google · 2048-bit
- DMARC p=quarantine · adkim=s · aspf=s
- MTA-STS mode: testing → enforce
- BIMI /bimi/logo.svg
Hear about it the moment it changes
The monitoring tools run on a schedule; Uptime Monitor, Typosquat Monitor and Snapshots alert you in Slack, Jira or your own webhook.
- One hub for every tool
- Verdict flips, new findings, incidents open and close
- Per-asset history for the auditor
Grade dropped A → B — TLS 1.0 enabled after a load-balancer change.
One invoice, itemised per tool
Each tool has its own price per unit, metered monthly. A default €50 monthly cap, which you can lower, limits what you can be charged.
- No minimum and no annual licence
- Usage per tool in your account
- Prices shown in your account before anything is billed
| Email Security | 4 domains | € 8.00 |
| Uptime Monitor | 12 monitors | € 12.00 |
| TLS Scanner | 6 endpoints | € 6.00 |
| Snapshots | 40 pages | € 10.00 |
| Free monthly credit | − € 5.00 | |
| Total excl. VAT | € 31.00 | |
Illustrative example — not a price list.
- 9tools available today, one account
- 15+reputation and threat-intelligence sources behind each SafeCheck link check
- 3locations to choose from for Uptime Monitor checks
- EUhosting: AWS Frankfurt and Ireland
How it works
Sign in once
One qzila identity opens every tool. No separate accounts, no separate invoices.
Add what to watch
A domain, a URL, a host, a page — the unit of work is always something you own.
Get told when it changes
Uptime Monitor, Typosquat Monitor and Snapshots tell you in Slack, Jira or a webhook.
Show the evidence
History and verdicts stay in the tool, ready for the auditor, the board or the customer.
Built by the people who run the audits
Forged in real audits
We run ISO 27001, NIS2 and DORA audits for a living. The tools started as the checks our engagements kept needing, and each engagement since has refined them.
Free to start. Clear as you grow.
The check tools run a single check with no account, and the first €5 of usage each month is free. Beyond that each tool bills its own unit, metered monthly, under a default €50 cap you can lower — no bundles, no tiers, no annual licence.
Evidence, not screenshots
Results and their history are kept per asset, with timestamps, so you can show an auditor what was true and when. With the Asign GRC platform, findings can also become risks and evidence there — compliance as a running process, not a report you rebuild every year.
European by design
Built and operated by adcore s.r.o. in Slovakia and hosted in the EU. Card payments, the sign-up bot check and optional analytics use Stripe, Cloudflare and Google, as the Privacy Policy explains. Your questions are answered by the people who build the tools.
Need the whole picture? Asign.
Asign is the GRC platform for NIS2, DORA and ISO 27001 — risk analysis, BIA, vendor management, incident management, training and automated evidence collection. An integration with the qzila tools is planned.
Start with one tool. Add the rest when you need them.
Sign in once and every tool is a click away. You pay only for what you use, per month, with no minimum and a spending cap you control — the price list is in your account before you add anything.
- One account across every qzila tool
- The first €5 of usage free every month, then pay-as-you-go
- Uptime, Typosquat and Snapshots alert you in Slack, Jira or a webhook