Security scanning that MSPs can actually afford.
ComplianceLayer exists because the cyber insurance industry changed the rules, and the existing tools were built for the wrong audience.
Why ComplianceLayer exists
In 2025, cyber insurance carriers increasingly asked for external evidence alongside the self-reported security questionnaire — scan reports, configuration screenshots, proof that DMARC was enforced, ports were closed, and SSL certificates were valid.
Enterprise security-ratings platforms are typically sold through annual enterprise contracts with pricing quoted per customer rather than published. They're designed for Fortune 500 procurement teams, not for an MSP managing 50 SMB clients who each need a scan before their insurance renewal. ComplianceLayer is $99/month, listed publicly.
ComplianceLayer fills that gap. A single API call scans any domain across 15 scan modules and returns an A–F graded report, typically in under a minute. No agents to install, no sales calls, no annual contracts. Plans start at $0.
Built by an infrastructure engineer
30 years of infrastructure engineering experience. Built ComplianceLayer because the MSPs and small security teams he worked with couldn't justify enterprise pricing for something that should be a simple API call.
What we scan
Every scan covers 15 scan modules, weighted to reflect what cyber insurers and compliance frameworks actually check:
Contact
Support: support@compliancelayer.net · We aim to respond within one business day
API Status: compliancelayer.net/status
Documentation: compliancelayer.net/docs
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. The free tier is here to stay.
All scans are external and non-exploitative — we never access your servers, install agents, or require credentials. View our security practices, or live system status.