Diagnostics & monitoring · Continuous site monitoring

Security headers continuous monitoring

We continuously watch specifically your site's security headers — HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, CORP/COOP — and immediately warn you if an important header disappears, weakens or changes after a deploy. So the protective layer does not 'drift' silently. Honestly upfront: this is detection of changes and alerting, not configuring headers and not protection from hacking — the presence of headers is only one layer, and we do not guarantee security.

Price
$1,600
Duration
setup usually 1–2 business days, then continuous operation on a monthly basis

Security headers continuous monitoring — overview

Security headers continuous monitoring — price, timeline & scope

Security headers continuous monitoring is an ongoing (monthly) service focused on security: we regularly check the site's responses on agreed URLs and compare specifically the security headers against a fixed baseline — HSTS (and its parameters), CSP (and whether the policy weakened or allows too much), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Resource-Policy and Cross-Origin-Opener-Policy. If a header disappears, weakens, changes value or stops being served on some pages, an alert arrives with a diff. Honestly about the essence: this is detection of changes and alerting, NOT configuring headers and NOT fixing — we do not set or edit headers on your server; that is done by your team or by us separately. And crucially: the presence of headers ≠ correct configuration ≠ 'the site is secure' — it is only one layer of protection, and monitoring does not guarantee the absence of vulnerabilities or a breach; it catches drift and weakening in the headers. We watch drift from a baseline, so a base set must already be in place; if there is none, a one-time setup/security audit is needed first (separately). False positives are possible on your own planned policy edits — we update the baseline by agreement. And honestly about coverage: 100% of all traffic cannot be covered unless all URL/subdomain/language/device variants are specified — we check the agreed set. If a third-party monitoring platform is used, its fee is separate. Coverage is the configured URLs; someone must react to an alert. An important boundary: this is narrow monitoring of the security headers specifically. If you also need to watch caching and delivery headers (Cache-Control, Vary, ETag, Alt-Svc, etc.), that is the broader 'HTTP headers monitoring (22 checks)' — a separate service; here the focus is on security only. This is also not a one-time security audit and not server configuration. If the site is simple, with no forms, accounts or sensitive data, strict security headers and their monitoring may be overkill. Picture this: instead of 'we set up CSP six months ago and after a release it quietly weakened and opened a hole' you get an alert on the deploy day that the security policy changed. The base price starts from 8,000 ₽ per month; it depends on the number of URLs and the check frequency.

Problems we solve

  • You set up security headers but do not know whether they weakened after deploys.
  • After a release CSP or another protective header may have quietly changed.
  • The protective layer 'drifts' unnoticed, and you learn of it from an incident.
  • Headers are edited by several people/CMS, easy to weaken unnoticed.

What's included in the Security headers continuous monitoring service

  • Comparison of security headers against a baseline (HSTS/CSP/X-Frame/X-Content-Type/Referrer-Policy/Permissions-Policy/CORP/COOP)
  • Control of CSP weakening (allows too much) and header disappearance
  • A diff of changes: what changed and where
  • Checking on an agreed set of URLs
  • Baseline updates by agreement on planned edits
  • Alerts on disappearance/weakening/change
  • Monthly continuous operation
  • An alert channel of your choice (email, messenger, webhook)

What you get

  • You quickly learn if a security header disappeared or weakened
  • You see on which URL and which header changed
  • Less chance of silently losing the protective layer over time
  • You know what to restore or tighten (configuration — separately)

How the work goes: steps

  • We fix the security-headers baseline, agree on URLs and the alert channel; collect access
  • We set up the regular comparison and weakening control
  • We launch monitoring, update the baseline on legitimate edits

Why PDV Expert

  • Fixed price and timeline — no surprises on the invoice.
  • Report and recommendations in plain language — clear without a technical background.
  • In touch at every step and answering questions about the result.

FAQ

  • Will you configure the headers and protect the site?

    No. We compare security headers against a baseline and send an alert on a change, but we do not set or edit them and do not protect from hacking. Configuration is done by your team or by us separately. And the presence of headers ≠ 'the site is secure' — it is one layer, monitoring does not guarantee the absence of vulnerabilities.

  • How is this different from HTTP headers monitoring (22 checks)?

    This service focuses only on security headers and is cheaper. If you also need to watch caching and delivery headers (Cache-Control, Vary, ETag, Alt-Svc, etc.), that is the broader HTTP headers monitoring — a separate service. Choose one depending on the task.

  • What if security headers are not set at all?

    Then a one-time setup or security audit is needed first (separately), because monitoring watches drift from a baseline. Once a base set exists, we watch that it does not weaken over time.

About the provider

The «Security headers continuous monitoring» service is provided by PDV Expert — a team specialising in «Diagnostics & monitoring». We work under contract and deliver a written report with recommendations.

Prepared by PDV Expert · updated