Know the instant your website is tampered with, cloned, or probed.
PharosHub continuously monitors your live site and verifies every page against what you actually published — so a swapped payment detail, an injected script, a cloned copy, or someone quietly mapping your paths never slips by unseen. Confirm your site once, and it is monitored around the clock from that moment on.
Continuous page-integrity monitoring · honeypot traps · clone & lookalike-domain detection
Trap sprungsomeone requested /.env
Honeytoken useda key that was never valid
Copy foundyour site on a domain you do not own
The attack nothing else is looking for
It is never defacement. It is one line.
Somebody gets into a hosting account, a build server, a CDN token. They change nothing you would notice — a reservations number becomes their number, a payment block appears on a room page, two digits move in an account number. The page loads perfectly and the request is entirely legitimate, so a firewall, a bot filter and a honeypot all see a completely ordinary day.
We sign what you publish, with a key you never hold.
At build time your site sends us a list of fingerprints — never the files themselves. We sign that list. The signature ships inside your own deploy and is served from your own CDN, so nothing about this sits between you and your visitors.
An attacker who owns everything still cannot sign.
The signing key is not on your servers, not in your build, not at your CDN and not in our database. Take over all of it and you can change whatever you like — it simply stops matching. That is the whole guarantee, and it is why this keeps working at the exact moment every other control has already failed.
Checked in the visitor’s own browser.
The page a guest actually received is hashed and compared against what you published. No agent to install, nothing to run, and no request to us on a page view — the check works offline because anyone can verify a signature without asking us anything.
Nobody legitimate ever touches a trap
Your firewall has to guess. A trap does not.
Every filtering product decides whether a request looks bad enough to act on, and it is sometimes wrong in both directions. A trap needs no judgement: the path exists for nobody, so a request for it is not evidence to weigh. It is an answer. The one caveat is your own tooling — a scanner you run or a pen test you commission will spring traps too, and the console lets you close those as your own in one click.
Reconnaissance is not an attack yet, so nothing blocks it
Somebody works through your paths for six minutes, learns where things are, and leaves. Nothing was exploited, so nothing fired — and the only record is forty lines in an access log nobody reads. That is the window this closes.
A used credential is proof, not a signal
Because you know which credentials were never real. A token planted where only an intruder would find it turns a maybe into a fact, and no amount of traffic filtering can produce that.
Doors that should never open
Paths on your own site that only an intruder asks for — /.env, /wp-admin, /backup.zip. A guest looking for a room never requests one, so a hit needs no interpretation: nobody legitimate had any reason to be there.
Keys that were never real
A credential that looks valid, works nowhere, and sits where somebody finds it only by looking where they should not. Nobody legitimate holds one, so a single use is not a signal to weigh. It is proof.
Not forty log lines
Dozens of small events from one source over a few minutes become a single alert with a score, a plain sentence, and every observation behind it kept so you can check the claim rather than believe it.
What it does
- Tells you someone is probing your site while they are still doing it
- Turns a used honeytoken into proof rather than a suspicion
- Compresses dozens of small events into one incident and one plain sentence
- Keeps the evidence, so every alert can be checked rather than believed
What it will never do
- Block, redirect, challenge or slow a visitor — that is your edge provider's job
- Read cookies, sessions, form fields or request bodies
- Delay a response: reporting is detached from the request
- Break your site — if anything throws, the request continues untouched
And the limit, stated here rather than buried: a trap only catches somebody who touches it. An intruder who knows exactly what they want and goes straight to it will not trip one. This makes the common case loud and cheap — it is not a guarantee, and any vendor offering you one is selling something.
And on Guard, the ground around them
The traps stay the product. Guard runs more of them, and adds continuous checks on the surface they sit in — the things that change without anyone deciding they should.
- Copies of your site
- A copied page carries our beacon with it, so the copy asks us for a script and tells us where it is running. We fetch that host ourselves and look for your own content before saying a word.
- Third-party scripts
- Fingerprinted each pass. Card skimming rarely breaks a site — it edits a script the site already trusted, and the booking form keeps working while it copies every keystroke.
- Lookalike names
- Public certificate logs make an impersonating domain visible within hours of registration. A watch list, not an accusation.
- Your own headers
- Checked from outside, continuously, so a protection you switched on last year is still on today.
- Sign-in patterns
- Spraying, stuffing and takeover — shapes no single request can show. You hash the account identifier, so we never learn whose it was.
Live in five minutes, on any site
Add your site, drop in one line, and confirm ownership in about a minute — no box to provision, no DNS to repoint, no agent on a server. From then on it is monitored around the clock. Node apps can add the package too, for honeypot traps and the cryptographic seal.
Read the install guide<script src="https://www.pharoshub.cloud/b/YOUR_SITE_KEY.js"
async></script>import { createGuard } from "@pharoshub/guard";
app.use(createGuard({
siteKey: process.env.PHAROS_SITE_KEY,
secret: process.env.PHAROS_SECRET,
}).middleware());Twelve traps on one site
$55 a month, $60 once to set up. Cancel from the billing screen, any time.