CyberScan checks your site for malware, hidden redirects, and unsafe configuration, then hands you a plain-English report your team can act on — with the PIPEDA and provincial breach-notification obligations laid out alongside it.
Point CyberScan at a URL and it does the rest remotely — nothing to install on your server.
Paste in your website or web app address from your dashboard.
CyberScan fetches your pages and checks them against dozens of malware, header and certificate signals.
Every finding comes with a plain-English explanation and the exact fix — sorted by severity.
Remote, non-destructive checks — CyberScan reads your site the way a browser or a search engine would, and never modifies anything.
Hidden iframes, obfuscated or packed JavaScript, cloaked redirects, defacement messages, and hidden spam-link injections commonly left behind after a compromise.
Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options and other headers that limit what an attacker can do even after a partial breach.
Certificate validity, expiry, and outdated protocol versions that put visitor data or your search ranking at risk.
Whether your domain is currently flagged by Google Safe Browsing, which would show visitors a full-page warning before they can reach you.
Identifies your CMS (e.g. WordPress) so you know exactly what to keep patched.
Flags unexpected cross-domain redirects, a common sign a site is being used to funnel visitors to phishing or malware.
If customer or employee personal information may have been exposed, Canadian privacy law can require you to act — not just clean up the code. CyberScan flags this context alongside your technical findings so nothing falls through the cracks.
If a breach creates a real risk of significant harm to an individual, organizations must report it to the Office of the Privacy Commissioner of Canada, notify affected individuals as soon as feasible, and keep a record of every breach for 24 months.
Organizations must promptly notify Quebec's data protection authority (CAI) and affected individuals when an incident presents a risk of serious injury.
Alberta's private-sector privacy law sets its own real-risk-of-significant-harm notification duty, on a similar but separately enforced timeline.
This is general information, not legal advice, and CyberScan is not a substitute for a privacy lawyer or a certified breach-response process. Provincial obligations vary (British Columbia and Quebec have their own private-sector privacy statutes), and CASL may also be relevant if a compromise is used to send unsolicited commercial messages. Speak with legal counsel to confirm what applies to your organization.
Start free. Upgrade when you need more sites or more frequent scans.