DocsYour apps

The guardian

Daily or every five minutes, incidents, what changed, and the emails.

Needs an accountUpdated
On this page

In short

  • The guardian checks every app you add, from the day you add it: whether it answers, its certificate, its security headers and the report's checks. On Watch and Care, the targeted checks run from the first day too, and where a finding sits and how to fix it open once the domain is confirmed. On Free, the targeted checks wait for a confirmed domain.
  • Every app is checked once a day on any plan. An app on Watch or Care with a confirmed domain gets the close watch: reachability every five minutes. An app on Free keeps the daily check, even in a company that pays for other apps.
  • A card on the app's page, What runs on its own, lists which checks run every day and which wait until you press Run a check.
  • It records incidents and daily changes on the app's page, and emails your alert address about new or fixed findings, and about incidents with a paid plan.
  • On Watch and Care, page health also opens your pages once a day and reports what does not work, as Hints on a card beside the guardian. Hints are not findings and do not change the score.

Where in the app

The guardian's schedule, its measurements, its checks and its log are on each app's page.

An app's page: the band with the guardian's schedule (2), the Guardian card with its checks and its log (4) and the Needs you list (6).

Step by step

  1. Open the app

    Click the app under Apps in the sidebar or on Home. Its page opens.

  2. Read how it is doing

    In the band under the app's name, Uptime, 7 days sums up the reachability checks of the last seven days, with the typical response under it. Until one has run, it reads Nothing measured yet. Guardian reads Daily or Every 5 min, and the line under it says when the next check runs.

  3. Read an exact value

    With the close watch on, a line in the Guardian card draws the response time of the last 24 hours. The dashed line is the typical time, and a check that failed gets a mark below the line.

    Without the close watch, one check a day draws no line, and the card reads Once a day. Every five minutes on a plan. in its place. On a paid plan the card reads Every five minutes once the domain is confirmed. until the domain is confirmed. Once the close watch runs, the chart reads Not enough measurements yet to draw a line. until two checks are in.

    Point at the line, or tap it and drag a finger along it. With the keyboard, move to it with the Tab key and use the arrow keys; Home and End jump to the first and the newest check.

    A small bubble shows that check's time in milliseconds and when it ran. A check that got no answer reads No answer, and one that answered with an error adds failed. Esc, or a tap elsewhere, closes the bubble.

  4. Read the checks

    On the app's page, the Guardian card lists Uptime, Certificate, Header drift and Full check. Each row says whether the check passed or failed and how long ago it ran, such as passed 3 min ago, with a green or red dot. The Full check row reads passed only when its latest report left nothing open. Otherwise it reads ran with the worst severity still open and how many, such as ran just now · 2 critical, and the dot takes that severity's colour. A check that has not run yet reads due now. A Header drift row whose latest run got a refusal instead of your page reads checked with no dot. Watched since beside the heading gives the day the app was added.

  5. See what runs on its own

    Under Reports, the What runs on its own card sorts the checks into groups. Automatic reads Every day, without you doing anything. Show these checks lists them by name.

    Until the domain is confirmed, an app on Free has a second group that reads Manual: Only when you press Run a check. Confirm the domain and they join the daily check. Confirm the domain opens the domain step. Once the domain is confirmed, the group is gone and those checks are listed under Automatic.

    The last group is the code checks. Automatic reads Your code is read every day, along with the rest. Not yet reads Connect your code and these join the daily check., with Connect code beside it where connecting code is switched on. On a plan reads Reading your code is part of a plan. Without one, only your website is checked., with See plans beside it. Show the code checks lists them.

  6. See what changed

    Under the list, the daily full check writes a line for each new or fixed finding, up to five of each. Further new findings share one line. A line starting "New on" names a finding that was not there before; "Fixed since the last check on" names one that went away. When you had asked us to fix it, the line ends with "Your fix request is closed."

  7. Follow an incident

    An open incident is the first row of Needs you, under the band. It names the checks that saw it, since when and for how long, and what the check last measured. One failure seen by several checks is one row. Open the site opens the app for an outage; See the fix opens a report taken after the incident began.

    While an incident is open, the score keeps its number but loses its colour, and the sentence under it points to the incident. When the check passes again, the incident closes by itself and moves to Earlier incidents with how long it lasted.

  8. Turn on the close watch

    Confirm your domain and choose a paid plan under Plans and billing. Guardian then reads Every 5 min, with Round the clock, with alerts under it.

  9. Choose whether to join the sample

    The Settings card holds Include this app in the sample. To leave the app out, untick it and click Save.

What happens behind the scenes

The four checks

CheckWhat it looks atHow often
UptimeWhether the app answers. No answer, or an answer of 500 or above, fails. A bot-protection page does not.Once a day. Every five minutes with a paid plan and a confirmed domain.
CertificateWhether browsers trust the certificate and it has at least seven days left.Once a day.
Header driftWhether a security header that was there last time is missing now. The first run only notes what is there. An answer that refuses the request is skipped.Once a day.
Full checkEvery check a report runs, compared with the app's latest report.Once a day.
  • When an app has no report yet, the guardian's first full check is its baseline. The log gets one line, with the score when there is one, and no email goes out.
  • Otherwise each full check is compared with the app's latest report, whether you or the guardian started it.
  • The full check is skipped when a report of the app finished in the last 20 hours and every check ran, for example after Run a check. That skip counts as done, so the next full check is a day away.
  • A fix pull request from Vallit that you merge makes the full check due at once. It runs at the next pass, even when a report finished earlier that day, and its report decides whether the fix request closes (Fixes).
  • A report with a check that did not run, such as a registry that did not answer, does not hold the next full check back. The guardian runs again at the next pass, at most once an hour and at most three times in those 20 hours. Checks held for the domain or by bot protection do not count, since asking again changes nothing.
  • When a paid app with a confirmed domain still has checks that did not run, Vallit's team is told which app and why.
  • It is also held back when another check of the same address ran in the last hour. That check is due again at the next pass, a few minutes later, not a day later, and the wait writes no result. It runs once the hour is over.
  • On Watch and Care, the full check runs the targeted checks from the first day, on the tick you gave when you added the app. Their findings show their title and severity at once; where they sit and how to fix them open once the domain is confirmed (Reading a report).
  • On Free, until the domain is confirmed, the full check leaves out the targeted checks, such as the search for left-over backup files and open folders. Its report marks them Waiting, and a score that would read Good reads Partial. Run a check includes them. The What runs on its own card lists them as Manual. The guardian and the card read the same list.
  • A full check starts only when the run still has time to finish it. When there is none, the check is not lost: it is due again at the next pass instead of a day later.
  • A finding marked Accepted risk, Not an issue or In progress keeps that status in the next full check. A finding marked Fixed that comes back is open again.
  • When the full check no longer finds a finding you asked us to fix, your fix request closes as done. Fixing what we found shows how else a request closes.
  • Full checks run by the guardian do not count toward the checks your plan covers each month.
  • When the app has a published trust page, each full check without a critical or high finding renews it for another seven days.
  • Header drift skips an answer that refuses the request: an error code of 400 or above, or a bot-protection page. Such a page lacks your app's headers, so comparing it would report headers as missing that your app still sends. The skipped run is not compared, and the next run compares with the last time your page answered.
  • Header drift runs at least 15 minutes after the same app's full check starts, or before it in the same pass. Some hosts refuse requests for a while after a full check.
  • The response chart, Uptime, 7 days and Typical response read only the Uptime check's results. The chart covers the last 24 hours, the two figures the last seven days.
  • Typical response is the median: half the answered checks were faster. A check that got no answer does not count toward it.

Incidents

  • Uptime opens an incident after two failed checks in a row, so one dropped request does not.
  • Certificate and Header drift open one on the first failed check. The full check never opens an incident; its findings go into the report and the log.
  • An incident closes by itself when its check passes again. A Header drift run that got a refusal neither opens nor closes one.
  • Incidents are recorded on every plan. Only the incident email needs a paid plan.
  • The schedule follows each app's own plan, not the company's. In a company with one app on Care and one on Free, the Care app is checked every five minutes and the Free app once a day.

Emails

EmailWhen it is sentWhat it needs
An incidentWhen an incident opens. One email per incident, with no repeats while it lasts.Paid plan and an alert address
New findingsWhen the daily full check finds something new, and at least one new finding is critical or high.An alert address
FixedWhen a finding from the previous check is gone that was critical or high, or that you asked us to fix, and nothing critical or high is new.An alert address

A day with nothing new sends nothing. Alerts shows what each email says and where it goes. Vallit's own team also gets a short message about incidents, daily changes and each run of the sample, which you never receive. What Vallit's team is told lists what it carries.

The sample

Now and then an AI reviewer reads what the daily check saw of an app and asks for a few extra read-only requests from a fixed list. What it finds is filed as a pattern without your app's name, and comes back to you as a finding once a fix exists. Only apps with a confirmed domain can be picked. The box starts ticked for every app.

Before that review, values in recognized credential formats are masked, including values in earlier finding titles and observations. The remaining text can still contain other secrets or personal data. Privacy and safety explains this boundary.

If something goes wrong

What you seeWhat it meansWhat to do
Your app did not respond.Two uptime checks in a row got no answer.Open the app in a browser. If it does not load, check your hosting provider's status and logs.
Your app returned error …Two uptime checks in a row got a server error, 500 or above.Check your hosting logs for the error. The incident closes once the app answers again.
Your security certificate expires in … days.The certificate has fewer than seven days left.Renew it with your host or certificate provider.
Your security certificate has expired.The certificate is past its end date, so browsers warn your visitors.Renew it now.
Browsers no longer trust your security certificate.Browsers do not accept the certificate, for example because it names another address or comes from an unknown issuer.Issue a new certificate for the app's address through your host.
We could not read your security certificate.The secure connection to your app failed.Open the app with https:// in a browser and check it loads.
A security setting stopped being applied after a change: …A security header that was there the last time your page answered is missing from your page now, often after a deploy. A refused request never raises it.Add the named header back. The report's fix kit for it shows how.
… could not be checkedThe last run of that check ended in an error, which the line below names.Wait for the next run. If the error stays, write to us with Get help.
Waiting for its domainThe domain is not confirmed, so the app stays on the daily schedule.Follow Confirm your domain.
ManualThe check is in the What runs on its own card and waits until you press Run a check, because the domain is not confirmed.Follow Confirm your domain, or click Run a check to run it now.
Nothing measured yetNo reachability check of the app has run in the last seven days.Wait a few minutes. A new app's first check is due at once.
Not enough measurements yet to draw a line.Fewer than two reachability checks ran in the last 24 hours.With the close watch, wait a few minutes. On the daily schedule, one check a day draws no line.