host security, for developers

The dev security
control panel

Vulnerability scanning, live host metrics, network discovery, threat intel and compliance checks — one dashboard, one API, one CLI. Real data only; nothing mocked.

Open the dashboard Quickstart
terminal
# install the CLI
npm i -g @rootwatch/cli

# point it at the control plane
rootwatch login --server https://app.rootwatch.dev --token rw_…

# scan this machine
rootwatch scan
✓ secrets  ✓ dependencies  ✓ repo hygiene — findings pushed to dashboard

Quickstart

Sixty seconds from zero to your first scan.

Create an account

Sign up at app.rootwatch.dev — your organization is created automatically.

Mint an API token

Dashboard → Access Control → New token. Pick scopes (read, scan, write, admin). Tokens are rw_…, shown once, hashed at rest.

Connect a client

CLI, MCP agent, desktop app, or curl — every client authenticates with the same token against the same org-scoped data.

Clients

One trust boundary — the server. Four ways in.

CLI rootwatch / rw

Secrets, dependency and hygiene scans on any repo or host. Results land in the dashboard.

npm i -g @rootwatch/cli
rootwatch login --server https://app.rootwatch.dev \
          --token rw_…
rootwatch scan # secrets · deps · hygiene
rootwatch scan --deps
npm · build from source: cli/

MCP For AI agents

Streamable HTTP MCP server with 11 tools — or the stdio bridge for desktop MCP clients.

// claude_desktop_config.json / mcp.json
{
  "mcpServers": {
    "rootwatch": {
      "url": "https://app.rootwatch.dev/mcp",
      "headers": { "Authorization": "Bearer rw_…" }
    }
  }
}
stdio bridge: rootwatch mcp

API REST /api/v1

Org-scoped Bearer-token API. Score, hosts, scans, vulnerabilities, events, reports.

curl -H "Authorization: Bearer rw_…" \
     https://app.rootwatch.dev/api/v1/score

curl -H "Authorization: Bearer rw_…" \
     https://app.rootwatch.dev/api/v1/vulnerabilities
scopes: read · scan · write · admin

APP Desktop

Electron thin client for Linux — AppImage, deb, snap. Same login, same data, native shell.

# installers are provided during
# managed onboarding — see below
linux · experimental flatpak

What it watches

A rule engine plus real collectors — no sample data, ever.

Host rule engine

SSH config, firewall state, pending security updates, Docker socket exposure, failed-login spikes, unexpected public listeners. Failures become findings; recoveries resolve them.

Network discovery

Neighbor table discovery plus TCP connect scans — open ports, risky exposed services, per-device history and risk scores.

Threat intel & Trivy

CISA KEV feed for exploited-vuln awareness, Trivy filesystem scans for real CVEs in installed packages.

Reports & compliance

Live-data HTML reports, compliance check rows, audit log — every surface org-scoped.

Pricing

Free to start — upgrade when you need more seats, tokens, or hosted AI.

Free

For solo developers getting a feel for their own machine.

$0 / month
2 seats · 3 API tokens
BYOK AI (your own provider key)
dashboard · API · MCP · CLI
Start free

Pro

For teams who want hosted AI analysis and room to grow.

$20 USD / month
10 seats · 10 API tokens
hosted AI insights + predictions
priority support
Upgrade in-app

Managed

Canadian Web Consulting runs it for you — onboarding, monitoring, monthly reports.

Monthly retainer
unlimited seats + tokens
we operate + report
per-client org isolation
Talk to us

Managed service

Prefer it run for you? Canadian Web Consulting operates the control plane and onboards your machines.

We run it

Hosted control plane, updates, monitoring and alerting — operated by Canadian Web Consulting.

We onboard your hosts

CLI/agent rollout across dev machines and servers, org-scoped tokens, per-client isolation.

You get reports

Monthly security posture reports and real incident alerts — findings, not noise.

Talk to Canadian Web Consulting