Cybersecurity & Digital Protection · Assessment

Vulnerability Monitoring Plan

Monthly scanning and patch advisories for systems your own team keeps up to date

Subscribe

$129USD per month

Recurring plan. Cancel before the next renewal to stop it.

The four questions this page answers

  1. 1

    What you buy

    A monthly subscription. We scan the systems in scope, track them against published advisory databases, and tell you in writing what needs patching and how urgently. We advise; your own developer, host or IT team applies the patches.

  2. 2

    What you get

    4 deliverables, listed in full below

    • A monthly written vulnerability report for the systems in scope
    • Same-day critical advisories naming the affected component and the available fix
    • A running record of findings opened and closed, so progress is visible over time
    + 1 more
  3. 3

    How it is delivered

    Managed Subscription

    An ongoing remote service that runs each period until you cancel it in writing.

    SUBSCRIPTION

  4. 4

    How long it takes

    First scan within 5 business days of onboarding, then monthly until cancelled

    Measured from the point everything under “what we need from you” is with us, not from the moment you pay.

Uptime and performance monitoring with alerting — illustrative concept, not a screenshot of a client system
Uptime and performance monitoring with alerting. Illustrative interface concept — not a screenshot of a client deployment.

What is this, in plain English?

A monthly subscription. We scan the systems in scope, track them against published advisory databases, and tell you in writing what needs patching and how urgently. We advise; your own developer, host or IT team applies the patches.

The advisory-only counterpart to Security Monitoring & Patching. That plan applies the patches for you and costs more because of it. This one suits businesses whose developer or hosting provider already does the patching but who have nobody reading the advisories and deciding what is urgent. It renews monthly until you cancel.

The problem it solves

Patches exist for the software you run, but nobody in the business reads security advisories, so you find out about a vulnerability from an attacker rather than from a bulletin.

If that does not describe you, this is probably the wrong product. Tell us and we will point you at a better fit rather than sell you the nearest one.

What you get

The concrete things that exist at the end and that you own.

4 deliverables

  • A monthly written vulnerability report for the systems in scope
  • Same-day critical advisories naming the affected component and the available fix
  • A running record of findings opened and closed, so progress is visible over time
  • A quarterly review call with whoever is responsible for applying the patches

What's included

The work covered by the figure in the buy box, at no extra cost.

  • Up to three systems or sites
  • Monthly external and authenticated scanning
  • Advisory tracking for platform and dependency versions
  • Certificate expiry and header drift checks
  • Monthly written report and same-day critical alerts
  • Quarterly review call

Not seeing something you expected? Check what you are not buying before you order.

What does it do?

Everything listed here is delivered as part of this product. Nothing on this list is aspirational.

  • A monthly scan of the agreed systems, external and authenticated where credentials are provided
  • Platform, dependency and library versions tracked against published advisory databases
  • Every finding rated, with the specific fix named and the urgency stated
  • Critical advisories sent within one business day rather than held for the monthly cycle
  • Certificate expiry and security header drift watched between scans
  • A monthly written report showing what changed since the previous one
  • A quarterly call to review what is still open and why

How it works

The delivery sequence from order to handover.

  1. 1

    Agree the scope

    We fix which systems are covered and confirm in writing that you authorise recurring scanning of them.

  2. 2

    Baseline

    The first scan establishes the starting position, so later reports show movement rather than repeating a list.

  3. 3

    Scan monthly

    Each month the systems are re-scanned and versions re-checked against the advisory databases.

  4. 4

    Report and escalate

    You receive the monthly report. Anything rated critical is sent immediately instead of waiting.

  5. 5

    Review quarterly

    A call every three months to go through what remains open and whether the risk is being accepted deliberately.

Delivery & fulfilment

Stream Edge Solutions ships nothing. Every package on this site is carried out and handed over remotely — this is exactly what happens after you order.

SUBSCRIPTIONHow this is delivered
  1. 1We confirm what is coveredWe agree exactly which systems the plan covers and the access we need to look after them.
  2. 2We set the plan up remotelyMonitoring, alerting, backups and the maintenance schedule are configured by our team. This part is a one-off remote setup.
  3. 3It runs, and we reportThe work is carried out through each billing period and reported to you. The plan continues, period after period, until you cancel it.

An ongoing remote service that runs each period until you cancel it in writing. Typical turnaround: First scan within 5 business days of onboarding, then monthly until cancelled.

Delivery method
Managed Subscription
Expected delivery time
First scan within 5 business days of onboarding, then monthly until cancelled
Measured from the point everything under “what we need from you” is with us — not from the moment you pay.

Full detail of how work is handed over, what happens if requirements are outstanding and how order records are kept is in the Delivery & Fulfilment Policy.

What we need from you

Nothing starts until these are in place, and the turnaround above is measured from that point — not from the moment you pay.

  • Written authorisation to scan the named systems on a recurring basis
  • Read access, and test credentials where authenticated scanning is wanted
  • An agreed list of the systems in scope
  • A named contact who is able to act on what the reports say
  • Acceptance that we report and advise rather than remediate

Who this is for

  • Businesses whose website is maintained by a developer or agency on request
  • Companies with an internal IT person who can patch but has no time to track advisories
  • Owners who want an independent second opinion on their supplier’s patching
  • Organisations asked to show they track vulnerabilities on an ongoing basis

Business needs this addresses: Improve IT infrastructure

What's not included

Just as plainly as the list above: the things this package is not.

  • Applying any patch or fix; that is the difference between this plan and Security Monitoring & Patching
  • Emergency response after a compromise, which is quoted separately
  • Paid scanning tool subscriptions if you require a specific commercial tool
  • Penetration testing or manual application testing
  • Out-of-hours response; reports and alerts are issued during working hours
  • Any suggestion that scanning finds every issue, or that a clean report means you are secure

Anything outside the scope above is quoted separately, in writing, before it is carried out. Nothing is added to your bill without your agreement.

FAQs

How is this different from Security Monitoring & Patching?

That plan scans and then applies the patches for you, including out-of-cycle critical ones, and needs the access to do that. This plan stops at telling you. It exists for businesses whose developer or host insists on doing their own patching, or who simply want an independent check on it. If you would rather we did the patching, that is the plan to buy.

Do you need our permission to scan us every month?

Yes, in writing, before the first scan. Scanning a system without the owner’s authorisation is illegal in most places, so we hold a signed authorisation naming the systems and covering the recurring schedule, and we will not run a scan without it. If a system moves to a host whose terms require notice, tell us and we will pause that target until it is cleared.

What happens if we cancel?

It is a rolling monthly plan, cancellable in writing before the next renewal. Every report we have issued is yours to keep, and the advisory history stays with you. Scanning stops at the end of the final period, so nothing is watched after that date. Our Refund & Cancellation Policy covers how a part-used month is treated.

If a report comes back clean, are we secure?

No. A clean report means the scans and the advisory databases did not flag anything on that day, for the systems in scope. Scanners miss issues in custom code, and a vulnerability published tomorrow is invisible today. It is a useful ongoing check, not a certificate of health, and we would not describe it as one.

Refund & cancellation

How this plan is cancelled, and what happens to money already paid.

Cooling-off before work starts
You have 7 days after ordering to cancel while work has not yet begun. Up to 25% may be retained to cover scoping and scheduling already carried out.
Cancelling this plan
It continues, period after period, until you cancel in writing. A monthly plan needs 30 days' notice. The service runs to the end of the period you have already paid for.
Work already done
Once delivery has started, refunds are assessed against the work completed and the deliverables already handed over — the list under “what you get” above is what that assessment is made against. Approved refunds are processed within 14 days.
If we cannot deliver what is described here
You are refunded. The scope on this page is the scope we are held to, which is exactly why the exclusions above are stated before you buy rather than after.

The full terms, item type by item type, are in the Refund & Cancellation Policy — see subscriptions. How the work reaches you is covered by the Delivery & Fulfilment Policy.

Not sure this is the right product?

We would rather point you at the right thing than sell you the nearest one. Ask us before you buy — no obligation.

Related products

Others that solve nearby problems, in case this is not quite the right fit.

Or see all 11 in Cybersecurity & Digital Protection.

Contact us