Skip to content
Free invite-only beta

Find what's broken.
Fix what matters.

Caldriax continuously audits and monitors your websites and applications, uncovering performance, security, availability and application-health issues — then helping you understand what changed and what to fix first.

Already invited? Sign in to Caldriax.

app.caldriax.com/audits — demo-store.example.com
82/ 100
Caldriax score · illustrative demo data
Reachable 3 new since last audit Monitoring on
  • Availability98
  • Security74
  • Performance68
  • SEO88
  • Accessibility81
  • Application health79
  • Website audits
  • Application health
  • Uptime monitoring
  • Performance analysis
  • Security checks
  • AI-assisted remediation
  • Regression tracking
  • GitHub workflow support

The problem

One score is not enough.

A site can respond with a healthy 200 and still be quietly failing the people using it.

  • runtime errors
  • broken user journeys
  • performance regressions
  • accessibility failures
  • security misconfiguration
  • SSL issues
  • SEO fundamentals
  • deployment regressions
  • third-party failures

Most tools hand you a single number and leave you to guess what it means. Caldriax combines deterministic auditing, browser-rendered evidence, continuous monitoring and historical comparison to build a clearer picture of real website and application health.

Every finding is traceable to the evidence behind it, so you can judge it yourself rather than trusting a black box. Caldriax will not tell you a site is secure or bug-free — it tells you what it observed, how serious it looks, and what changed since last time.

Platform

Six ways Caldriax keeps your estate honest.

Audit deeply

Run structured checks across availability, security, performance, SEO, accessibility, browser behaviour and application health.

  • Deterministic checks, not guesswork
  • Evidence-backed findings
  • Clear severity and status
  • Repeatable, versioned scoring

Monitor continuously

Track availability, health changes, incidents and SSL status between audits so problems do not have to wait for the next manual scan.

  • Uptime and response checks
  • Incident confirmation
  • SSL expiry and validity
  • Notifications with quiet hours

See what changed

Compare audits over time and distinguish new regressions, persistent issues and genuine improvements.

  • Every issue gets a stable identity across runs
  • New, persistent, resolved and reopened states
  • Score trends by category
  • Deployment-to-deployment comparison

Test the application your users actually experience

Caldriax renders your pages in a real browser and captures what happens, not just what the server returns.

  • Runtime failures surfaced in the page
  • Failed and blocked requests
  • Responsive and mobile layout issues
  • Application-health signals and screenshots

Understand what to fix first

Caldriax AI explains confirmed findings, groups likely root causes and prepares practical remediation guidance grounded in the audit evidence.

  • Executive summaries
  • Fix-first prioritisation
  • Finding explanations and remediation guidance
  • Developer fix prompts and GitHub issue drafts

Turn findings into action

Move from evidence to a ticket your team can actually work, without leaving your existing workflow.

  • GitHub integration with least-privilege permissions
  • Issue drafting from a real finding
  • Deployment-triggered auditing where configured
  • Developer-friendly evidence attached

Caldriax AI · fix-first summary

  1. 1. Restore transport security headers. Two findings share one likely root cause: the CDN redirect layer no longer forwards HSTS.
  2. 2. Cut render-blocking CSS on the homepage. Largest contentful paint regressed after the last deployment.

Grounded in this audit's evidence. AI never changes your score and never opens an issue without approval.

HighRegressionSEC-HSTS-01

Strict-Transport-Security header missing

Observed on https://demo-store.example.com/ — response returned no HSTS header on the final redirect hop.

First seen
14 audits ago
Status
Reopened
Evidence
Headers + screenshot

Boundaries, stated plainly. Caldriax AI never changes the deterministic audit score and never creates GitHub issues without your approval. Browser testing covers the pages and viewports Caldriax renders — it does not claim complete coverage of every user journey, and Caldriax never modifies your code.

Caldriax Score

A health score you can investigate

The headline number is a summary, never the whole story. Behind it sit the category scores, the individual findings, the evidence each one is based on, and how all of it has moved since your last audit.

  • Category scores across every audited area
  • Evidence attached to each finding
  • Severity you can sort and filter
  • Historical comparison across audits
  • Improvements and regressions made visible
  • Versioned rules so scores stay comparable

A Caldriax score is our assessment of observed health. It is not an industry certification or an assurance that a site is secure.

82/ 100
Caldriax score · illustrative demo data

How it works

Four steps from unknown to under control.

  1. 1

    Add your site

    Enter the website or application you want Caldriax to watch.

  2. 2

    Run an audit

    Caldriax collects deterministic, performance and browser evidence.

  3. 3

    Review what matters

    See prioritised findings, trends and application-health signals.

  4. 4

    Fix and monitor

    Use remediation guidance, GitHub workflows and continuous monitoring to stay ahead of regressions.

Uptime — last 20 checks

99.4% · 30 days

One incident confirmed and resolved · SSL certificate valid for 54 days · illustrative demo data

What a run gives you

  • Lab and field performance measurements for mobile and desktop
  • Transport, header and certificate checks
  • Browser runtime failures and blocked requests
  • Detected frameworks and platform signals

Agencies & teams

See your whole web estate in one place

Managing twenty client sites should not mean twenty separate checklists, twenty tabs and twenty different definitions of 'fine'.

Join the agency beta

Uses the same invite request process.

  • Multiple sites under one account
  • Portfolio view across the estate
  • Consistent auditing and scoring
  • Continuous monitoring per site
  • Shareable, redacted reports
  • Issue tracking across audits
  • Client-friendly insight, not raw logs
  • Evidence your developers can act on

Security & privacy

Built with security boundaries in mind

Caldriax handles evidence about your systems, so the platform is designed around least privilege and owner-scoped access.

  • Owner-scoped access controls

    Your sites, audits and evidence are readable only by your account.

  • Private evidence handling

    Screenshots and captured evidence are stored privately and served through short-lived links.

  • Server-side secret handling

    Third-party credentials stay on the server and are never shipped to the browser.

  • Restricted integration permissions

    Code-hosting integrations request the narrow permissions needed for the features you enable.

  • Verified webhooks

    Inbound integration events are signature-verified and protected against replay.

  • Rate limits and abuse controls

    Usage allowances and abuse suppression protect both the platform and your targets.

  • AI input redaction

    Evidence is redacted before it is sent to a model provider.

  • Protected audit targets

    Audit fetches run through hardened controls that prevent the platform being pointed at internal networks.

Caldriax is an auditing and monitoring platform, not a substitute for specialist penetration testing. No automated tool can prove a system is secure.

Free invite-only beta

Help shape Caldriax before general release

We're inviting a limited group of website owners, developers and agencies to use Caldriax free during beta and help us refine the product around real-world websites and applications.

  • Free access during beta
  • No card required
  • Direct product feedback channel
  • Early access to new features
Places are limited, usage allowances apply, and beta functionality may evolve as we learn from real sites.

No card required. Access is limited and usage allowances apply during beta.

FAQ

Questions, answered honestly.

Already invited? Sign in to Caldriax.