About Aion Security
I built Aion Security after watching a government website go dark for reasons nobody in the building could explain.
I worked for a municipal government. One morning, one of our sites just stopped loading. No error page, no warning — it was just gone. Residents called us. We called IT. IT called the developers who'd originally built the site. Eventually, after a lot of back-and-forth, someone figured out what had happened: the domain registration had expired. The person who'd originally registered it had since left, and getting the domain back meant tracking down account access, proving who we were, and a lot of phone calls to people who had no obligation to move quickly. The site was down for four days. For a business, that's bad. For a government office — the place residents go to pay bills, find services, and trust that things work — it's a genuinely bad look, and there was no one villain to blame. Just a date nobody had on their calendar.
That's the thing about domain and infrastructure security: it's rarely a dramatic hack. It's a certificate nobody renewed, a header nobody set, a domain nobody was watching. Small, boring, invisible failures that turn into a very visible outage or breach at the worst possible time. I built Aion Security so that "nobody was watching" stops being the reason it happens to you.
What Aion Security actually does
Run a free scan on any domain and get instant visibility into the things that quietly go wrong: SSL/TLS certificate health and the protocol/cipher your server actually negotiates, HTTP security headers, accidentally exposed files like .env and .git, cookie security flags (Secure, HttpOnly, SameSite), DNS and email authentication records (SPF, DMARC, and DKIM), IP blacklist status, disclosure/hardening signals like security.txt, CAA, and DNSSEC, domain expiration — yes, that one's personal — and, for WordPress, WooCommerce, and Shopify sites, exposed admin surfaces and outdated plugins. You get a plain-language grade and a downloadable PDF report in seconds. No signup required.
If you want more than a one-time snapshot, the dashboard lets you add your domains and have Aion Security keep watching them — daily, weekly, or monthly, your choice. It keeps a full history of every scan, lets you compare any two side by side, and emails you the moment something regresses: a grade drop, a certificate nearing expiration, a domain newly appearing on a blacklist. Starter and Pro accounts also get a monthly PDF report delivered automatically, so the record exists even if nobody thinks to go looking for it.
There's also a free dependency vulnerability scanner: upload a package-lock.json, yarn.lock, requirements.txt, or composer.lock and every dependency gets checked against OSV.dev's public vulnerability database. No signup, and the file itself is never stored or logged.
Who this is for
It's for me, because I own, operate, and manage more websites than I can keep track of, but it's also for you; the developers and small teams who are already stretched thin — the people who'd rather find out about an expiring certificate from an email than from an angry phone call. You don't need a security team to catch the boring failures before they become expensive ones. You just need something watching the calendar.
Get started
Run a free scan on the home page, check your dependencies for known vulnerabilities, or log in to your dashboard to start monitoring your domains continuously.