Continuous server scans
Trivy CVEs, ClamAV malware, rkhunter rootkits, SSH and OS hardening — every layer, every six hours, with one-click auto-fix from the dashboard.
One platform for every Linux server and every website you run. Continuous scanning, automatic fixes, off-host backups, and a forensic post-mortem for every outage — all from a single dashboard, live 60 seconds after one paste-and-run install command.
Are you an agency? See how we're built for you →
What it covers
Most security tools are good at one thing. Astrari is built so the layer that catches a problem is irrelevant — every finding lands in the same dashboard, scored, routed, and explained.
Trivy CVEs, ClamAV malware, rkhunter rootkits, SSH and OS hardening — every layer, every six hours, with one-click auto-fix from the dashboard.
Wordfence Intelligence catalogue for plugin/theme CVEs. Headers, cookies, exposed config, user enumeration, SSL and domain expiry — every site, every day.
What's actually listening, not just what's installed. MySQL on 0.0.0.0, Redis without a password, /.env files, default-path admin panels — plus your own custom probes.
Append-only B2 credentials on the agent. EU-hosted, encrypted on the host before upload. Even a fully compromised host cannot delete the backup history.
Site goes down and recovers — Astrari has already collected the why. Logs, OOM kills, failed services, frozen at the moment of recovery, in the same email.
Three kinds of probe — HTTP, port, file — composable into rules that fit your stack. A forgotten /admin path, a database port that should never face the internet, a config file with the wrong flag. Pushed to every agent on next checkin.
Statically linked Go binary. Drops onto any Linux distribution. No runtime dependencies.
Dashboard actions reach the agent in under a minute. Auto-fixes apply within seconds of approval.
The agent only ever makes outbound HTTPS to the API. No SSH from us. Same security posture as your monitoring agent.
Measured, not just counted
Two hosts with the same number of findings can be worlds apart — one already patched by a backport a naïve scanner can't see, one already broken into. Astrari weighs every finding for what it actually means, so the score and the badge point you at what matters first.
A box that could be attacked and one that already has been should never sit in the same list. Confirmed malware, an injected web shell, a tampered database, or a verified rootkit push the score into the red and raise a compromise badge — the host that needs you tonight stands out from the one with a routine outdated package.
⌖ Keyed off real detections, not advisory noise — a rootkit checker's config warnings won't brand a healthy host as owned.
AlmaLinux and RHEL fix vulnerabilities by backporting the patch while keeping the old version number, so a naïve scanner raises alarms for CVEs that are already closed. Astrari understands backports, TuxCare and KernelCare extended support, and kernels that aren't the running one — and weights each accordingly. An end-of-life box on a care plan reads as cared-for, not as a flat zero.
⌖ A 0–100 that actually spreads: unpatchable and non-running-kernel CVEs are discounted, confirmed compromise is floored.
In their words
We used to log into four different tools per client. Astrari is one. The first thing it surfaced on a host we'd been managing for years was a Redis sitting on 0.0.0.0 with no password — that alone justified the year.
The monthly reports go out branded with our logo, on our domain, and our clients think we built the dashboard. They didn't. We're upfront about that — but the sender line is ours, the design is ours, and that's what they remember.
I was wary of yet another security tool. The thing that won me over was the auto-fix — when SSH root login was open on a client's box, I clicked one button and it was done. From inside the host. No SSH session from me, no ticket, no follow-up.
Built for agencies
Group every server and site under a named client. Invite a scoped login that sees only their estate. Send monthly reports automatically — your logo, your colour, your sender name. None of this is roadmap — it's shipped and in production today.
A 60-second tour
Astrari Vault · backup add-on
The agent on each Vaulted server has B2 credentials that can write new snapshots and read old ones — but cannot delete or overwrite. A ransomware operator with full root inherits those credentials and finds they cannot wipe a single existing snapshot. Pruning runs from Astrari infrastructure with a separate key the host never sees.
EU-hosted Backblaze B2 by default. Encrypted on the host before upload. £0.05 per GB stored / month; 10 GB of restore egress free per month. No per-server vault fee.
Read the Vault essay →Agent B2 credentials
Pricing
What changes between plans is the count of servers and sites, not the depth of inspection. Vault is metered separately.
Free
Forever
£25
per month
£65
per month
Running client estates? The Agency plan covers 125 sites and 25 servers, with scoped client logins and automatic branded monthly reports — £149/mo. See full pricing →
A small UK security team
Astrari is a service of Incus Technologies Limited. We answer the support emails ourselves. The team is small enough that everyone knows what every check is doing and why.
Start free — no credit card