Know if your website has been compromised — and what Canadian law says to do next.

CyberScan checks your site for malware, hidden redirects, and unsafe configuration, then hands you a plain-English report your team can act on — with the PIPEDA and provincial breach-notification obligations laid out alongside it.

Built for Canadian small & mid-size businesses No file access or plugin required Reports in minutes, not days

Three steps, no site access needed

Point CyberScan at a URL and it does the rest remotely — nothing to install on your server.

01

Submit a URL

Paste in your website or web app address from your dashboard.

02

We scan it

CyberScan fetches your pages and checks them against dozens of malware, header and certificate signals.

03

You get a report

Every finding comes with a plain-English explanation and the exact fix — sorted by severity.

What each scan checks

Remote, non-destructive checks — CyberScan reads your site the way a browser or a search engine would, and never modifies anything.

Injected & hidden malicious code

Hidden iframes, obfuscated or packed JavaScript, cloaked redirects, defacement messages, and hidden spam-link injections commonly left behind after a compromise.

Security headers

Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options and other headers that limit what an attacker can do even after a partial breach.

TLS & certificate health

Certificate validity, expiry, and outdated protocol versions that put visitor data or your search ranking at risk.

Public blacklist status

Whether your domain is currently flagged by Google Safe Browsing, which would show visitors a full-page warning before they can reach you.

Platform fingerprinting

Identifies your CMS (e.g. WordPress) so you know exactly what to keep patched.

Redirect chains

Flags unexpected cross-domain redirects, a common sign a site is being used to funnel visitors to phishing or malware.

What Canadian law expects if your site is compromised

If customer or employee personal information may have been exposed, Canadian privacy law can require you to act — not just clean up the code. CyberScan flags this context alongside your technical findings so nothing falls through the cracks.

Federal — PIPEDA

Breach reporting duty

If a breach creates a real risk of significant harm to an individual, organizations must report it to the Office of the Privacy Commissioner of Canada, notify affected individuals as soon as feasible, and keep a record of every breach for 24 months.

Quebec — Law 25

Prompt notification

Organizations must promptly notify Quebec's data protection authority (CAI) and affected individuals when an incident presents a risk of serious injury.

Alberta — PIPA

Without unreasonable delay

Alberta's private-sector privacy law sets its own real-risk-of-significant-harm notification duty, on a similar but separately enforced timeline.

Straightforward pricing

Start free. Upgrade when you need more sites or more frequent scans.

Trial
$0
  • 1 website
  • 5 scans / month
  • Full report & remediation guidance
Start free
Agency
$99/mo CAD
  • 25 websites
  • Unlimited scans
  • Team seats
  • Priority support
Start free trial