Pricing
Hitt Hosting Security is free.
No tiers, no subscription, no card. Every feature unlocks the moment you sign in with your Hitt Hosting account.
Security just works on login. Nothing is metered, nothing is locked behind a plan, and there's no upsell waiting on the other side.
Everything you get, at no cost
- Cross-product monitoring across every product on your account
- Dark-web & breach monitoring for your domain and team (rolling out — reports as a not-connected source until the intel feed is wired, never a false all-clear)
- Identity & credential hygiene — live today: MFA-gap detection on every scan plus breached-password checks against the HIBP corpus (k-anonymity, never stored); impossible-travel detection rolling out
- Severity-ranked findings, per-product worst-of
- True finding age from a first-seen ledger — every weakness is dated from the moment we first saw it, so age buckets, SLA clocks, escalation, and POA&M "Identified" dates reflect real elapsed time, not the last scan
- Remediation tracking (resolve / reopen / evidence) with due dates and owners
- Compliance framework coverage — your latest scan mapped to cross-framework control areas (CIS Controls v8 · OWASP · NIST CSF): Access Control, Change Management & Audit Logging, Data Protection, Vendor & Supply-Chain, Account & Billing Integrity, Identity & Credential Hygiene, each with covered/open/source-not-connected status, rolled up into the JSON evidence pack. Self-assessment, not certification
- NIST 800-171 requirement families — the coverage view and POA&M export name the 800-171 Rev 2 families (3.1, 3.3, 3.5 … 3.14) your CMMC assessor works from: all 14 rolled up to covered/open/not-in-scope, and every POA&M finding tagged with its family (e.g. "3.3 Audit & Accountability") beside the CIS/OWASP/CSF ref. Deterministic and offline — no official SPRS score computed or submitted, no certification claimed
- NIST 800-171 requirement register — track all 110 Rev 2 requirements as living controls with your own status (met / not met / N/A), owner, and dated notes; a working self-assessment total updates as you answer, and every unmet requirement lands in your POA&M, your SSP as a documented gap, and your JSON evidence pack. It also closes what the scan can't see — 3.2 Awareness & Training, 3.6 Incident Response, 3.7 Maintenance, 3.9 Personnel Security, 3.10 Physical Protection — once you record what you actually do. Your answers, your judgment: a draft total you review, not an official SPRS score, never calculated for you or submitted anywhere, and not a certification
- Assessment of record — capture your 800-171 self-assessment as a dated, immutable snapshot of all 110 answers with its working total, so next quarter you can still say exactly what you claimed and when. Editing a requirement afterwards leaves the record untouched: captured assessments are insert-only in the database, with no update or delete path. Compare any two assessments (or one against today) to see what improved, regressed, or changed applicability, and re-run your POA&M or SSP against any past assessment. Every answer change is recorded in an append-only trail with who changed it and why. Your own determinations, kept honestly — the platform never assesses for you, computes no official SPRS score, and submits nothing anywhere
- POA&M target completion dates & projected total — put a planned completion date on each not-met 800-171 requirement so the Scheduled Completion Date column an assessor reads is filled in, the row reads In-progress rather than a flat Open, and a date you have blown through is flagged. The register also shows what your draft total becomes once every gap you have dated is closed by its date, with an overdue count. Undated gaps still count against you in full; leave every date blank and your POA&M is unchanged. A draft projection you review, not a prediction and not an official SPRS score
- Attestation review cadence — give every control-area sign-off a re-review date (30 / 90 / 180 / 365 / 730 days, per account or per area) so a year-old mark stops reading like a fresh one, the way NIST 800-171 3.12 expects a self-assessment to be revisited. Due and overdue states show in the compliance view, the SSP, the branded posture report, the POA&M's attestation cell, and the JSON evidence pack's integrity checksum, with one-click re-review. A stale attestation is a prompt to look again — never deleted, downgraded, or reported as a failed control. Self-assessment, not a certification
- Incident register — document a security incident through detection, analysis, containment and recovery, with a note per phase so 800-171 3.6.1 has a record rather than a status that jumped; log who you notified and when (3.6.2); and mark a tabletop as an exercise so 3.6.3 has a date behind it. An incident affecting covered defense information shows your own DFARS 252.204-7012 72-hour countdown from discovery, and flags overdue. It feeds a §3.6 section in your SSP export. We track your clock; we never submit anything on your behalf, to DIBNet or anyone else. Self-assessment, not a certification
- Periodic privileged-access reviews — recertify every API token, integration key and invite across your stack on a quarterly cadence, with a dated keep/revoke record and a "review due" flag when the last review lapses. The completed review drops straight into your JSON evidence pack, covered by the same integrity checksum. Advisory + self-assessment: a revoke decision is your note to yourself; we never edit the underlying product's tokens, and nothing here is a certification
- Compliance control-area sign-off — mark each control area Reviewed or Accept-risk with a dated note; the attestation persists and travels into your JSON evidence pack, POA&M, and branded posture report, so you hand an assessor a dated record of what you reviewed, not just a live scan. Self-assessment, not a certification
- Shared-responsibility matrix — per control area, what the platform provides beneath your tenancy (RLS org-isolation, AES-256-GCM at rest for stored banking tokens, append-only finding-event trail) versus what you still own (who you invite, MFA, credential rotation, vendor due-diligence), plus the shared middle. Renders in the compliance card, folds into the SSP export as a per-area Shared Responsibility / Inherited Controls block, and sits inside the evidence pack's integrity checksum — the inheritance split an assessor asks an ESP customer for. Inheritance inputs you validate and document, not certified controls
- Evidence register — attach the proof an assessor asks for (policy docs, config exports, screenshots) to each control area and finding as a titled reference with an optional link and date; it flows into the SSP's per-area "Supporting evidence" block, an appended "Evidence" column on every POA&M row, and the JSON evidence pack. We store the reference and link, never the file — pointers to your own artifacts, which we don't hold, validate, or attest to. Self-assessment, not a certification
- Configurable severity SLA thresholds — set your own critical and warning escalation windows (1–90 days) to match your compliance commitments
- Time-to-breach countdown — a forward-looking "Approaching SLA breach" panel projecting each open finding's age against your configured window, so you see what's about to breach (and how many days are left to fix it) before it does, findings closest to the line first — your targets, not a guarantee
- Remediation velocity — mean time-to-remediate by severity and your SLA-breach rate, computed from your own finding history, so you can prove your remediation process is getting faster (observed metrics, not an SLA guarantee)
- Scan source coverage — every scan records which of your sources actually answered. If one times out, its open findings are held rather than marked resolved, no "cleared" event is written to their audit trail, and your posture score is not recorded that day, so an outage leaves an honest gap in the trend instead of a fake improvement. A source that reports "not provisioned" is a real answer and is treated as one — this distinguishes no findings from no answer, and says which happened
- Free-text working notes on any finding — keep the remediation conversation on the record, in one timeline with the finding's lifecycle history
- Saved finding views — filter by severity, product, owner, due date, or free-text search, then save the slices you work from (My overdue criticals, Unowned, etc.) as one-click views
- Bulk finding actions — select across the filtered slice and acknowledge, resolve, mute, assign, or set a due date on the whole set in one click, with a per-finding audit-trail entry preserved for each
- Accept-risk mute with a reason on the record
- Idempotent critical email digests
- Reliable webhook delivery — HMAC-signed HTTP fan-out to Slack, PagerDuty, ticketing, or any HTTP endpoint; severity floor per endpoint; failed deliveries auto-retried with a per-endpoint delivery log so a broken endpoint never silently swallows a critical
- Security posture score — one risk-weighted 0–100 number, tracked daily
- Weekly posture report — a plain-English email recap of your security score trend, what opened and closed this week, and your oldest unresolved critical (on by default, one-click opt-out)
- What changed since your last scan — an itemized appeared/cleared diff between your two most recent scans (cleared findings carry their last-seen severity), updated by scheduled scans too and exported with the evidence pack
- Scan history — see every scan that ran, when it ran, and how your finding counts moved scan-over-scan, so a stalled scheduled scan can never hide; a read-only activity log with a prominent last-scan timestamp and per-scan critical/warning/info deltas
- Recurring-finding watch — findings that clear and reappear on their own across scans are flagged with an appearance count, surfaced on the finding and in the JSON evidence pack (observed behavior, not a certification)
- Append-only audit log and posture history
- One-click findings export (CSV + JSON evidence pack)
- Built-in remediation guidance — every finding ships with a recommended fix (clear corrective-action steps on the card) that also auto-fills the corrective-action column of your assessor-ready POA&M export, so you never hand over a weakness list with a blank remediation column; deterministic and offline (no AI call, no rate limit), and your own note always wins when you've written one. Self-assessment, not a certification
- POA&M (Plan of Action & Milestones) export — one row per open finding in the canonical NIST/CMMC layout, with control reference, owner, scheduled completion date, and status; the artifact your CMMC/NIST 800-171 assessor actually asks for. Self-assessment aid, not a certification
- Remediation milestones — attach dated, staged remediation steps to any finding ("Rotate exposed key — 2026-07-20; Enforce MFA — 2026-08-05 [done]"); they populate the POA&M "Milestones with Completion Dates" column your assessor expects — not just one lump due date — and thread into the JSON evidence pack. Self-assessment planning, not a certification
- On-demand branded posture report — a single one-click, print-to-PDF document composing your posture score and trend, severity distribution, remediation velocity, compliance control-area coverage, and finding age; hand it to a prime, insurer, or assessor instead of a spreadsheet. Self-assessment, not a certification
- AI policy assistant (Anthropic Claude)
- Persisted AI security briefing — the Claude-powered cross-product analysis (correlations, predicted emerging risks, plain-language recommendations) is dated and saved on every generation instead of evaporating on refresh; the panel shows when it was generated with a one-click Previous analysis view (no new AI call), and the latest briefing threads into your JSON evidence pack and branded posture report so the analysis you read is the one you hand an auditor. Self-assessment aid, not a certification
- Shareable trust page + security badge — publish a live, always-current summary of your posture (overall score, severity counts, compliance-coverage %, last-scanned date) at a shareable public link, plus an embeddable badge for your own site; prove you're secure to prospects and partners without emailing spreadsheets. You choose which summary cards are visible and can rotate or revoke the link anytime — only aggregate summary data is ever exposed, never finding details. Self-attested posture from your own scan, clearly labeled — not a certification or audit
Questions, answered.
Is Hitt Hosting Security really free?
Yes. Security is completely free for everyone: there's no tier to pick, no card to enter, and nothing that gets locked behind a plan. You just need a Hitt Hosting account (the same login as the rest of the suite). Sign in and every feature is unlocked.
Do I need another Hosting product to use Security?
No. Security stands on its own and is free regardless of what else you use. If you do use other Hosting products (CRM, Books, HR, Desk, Sign, Field, SE, Hosting), Security watches the data they already store, but nothing about Security itself is gated on having them.
Will there be paid tiers later?
Not today. Security is free and ungated. If anything ever changes we'll say so plainly, but right now there is no upsell, no per-seat tax, and no metered limit.
Does the dark-web monitoring really scan the dark web?
Dark-web and breach-corpus monitoring is rolling out. Once a feed is connected we'll check leak databases and breach corpora for any email/domain tied to your account. We don't crawl the dark web directly; we partner with feeds that do that responsibly. Until then the dashboard reports this source as not-connected, never a false all-clear. What's live today: an interactive breached-password check against the Have I Been Pwned corpus (k-anonymity, nothing stored).
Can I limit who in my team sees findings?
Today Security is single-tenant per account: one Hitt Hosting login owns the findings, and per-account isolation is enforced server-side. Multi-user team access with role-based roles (owner, admin, accountant, viewer) is on the 2026 roadmap and will match the rest of the suite when it ships.
Start watching your account today.
Sign in with your Hitt Hosting account and Security turns on: free, fully unlocked, nothing to buy.