A backup of your site’s settings is public
Anyone can download it, and it holds the password to your database, where your orders live.
Our AI agents go at your site like a real attacker, check if it’s already been hacked and explain every fix in words you actually understand. Every week.
Anyone can download it, and it holds the password to your database, where your orders live.
Attackers scan for these two automatically. Both already have a safe update waiting.
Your domain lets strangers write to your customers as if the message came from you.
Every finding is proven before you ever see it. This is the whole record for the settings backup, kept exactly as it happened.
The server handed it over to anyone who asked: a copy of your site’s settings.
Same file. One odd response can be a glitch; the same one twice is a fact.
Got a plain “not found”. So the server isn’t handing out any name you ask for — this file is really there.
Read only enough to know what it is. The password itself was never stored, and nothing was downloaded.
Written for the person who has to do it — not for a security team.
Open your hosting’s file manager, find it in the main folder of your site, and delete it.
The file was public, so treat the old password as known. Most hosts change it in one click, and Teyna shows you where.
Teyna runs against the real thing, on purpose. The limits that make that safe are written into the software, not into a promise.
It only reads — never changes, deletes or submits anything — and stays quieter than a slow evening of real customers.
It keeps the smallest piece of evidence that proves the problem, and masks anything that looks like a password.
Every problem is proved twice before you are told. What it cannot prove, it says so instead of guessing.
The first run only reads what is already public. Anything deeper happens after you turn it on inside your dashboard, and stops the moment you turn it off.
None of these arrive with a warning. You hear about them from a customer, a bank or Google.
Browsers show a red “deceptive site” screen before anyone reaches your page.
Ad networks suspend accounts that send traffic to a compromised site.
One swapped script copies what customers type and sends it somewhere else.
Once anyone can send mail as you, providers stop trusting your domain.
You have probably tried one already. Here is the same site through both.
Delete one file, change one password.
Press Update next to both, about 5 minutes.
Add two records, we give you the exact text.
What it looks like for a small business on an ordinary morning.
One button. A minute later the report says two things need fixing, worst first.
“What do I do?” The AI explains it the way a person would, and gives three steps.
You follow the steps. Teyna checks again and confirms it is really closed.
The first check costs nothing and needs no card. Paid plans keep checking after you've fixed things, because websites change every week.
If your first paid month turns up nothing worth fixing, we refund it automatically — and you keep the report, a dated answer for whoever asked.
Swipe to compare plans
Cancel whenever you like — the next month simply doesn't start.
The same findings, written for whoever has to read them.
Three sentences per problem: what could happen, how bad it is, and what to do about it.
Request, response, the exact line, the proof it was repeated, and the change to make.
A dated summary you can forward under your own name, without exposing your stack.
Every finding, every re-check and every authorisation, dated and in one place.
You never need any of this to use Teyna. It is here for the curious, and for your developer.
Most of it you never see: hundreds of raw results become the handful that could actually be used against you.
The limits it works insideWhile you slept, it went over your site from every side, threw out the false alarms and kept the three problems that are real. You never had to read any of it.
A break-in is never one mistake. You see every link in the chain, in order.
How it stays safe doing thatNobody told you about it. It showed up in a public certificate log on 14 September.
No password, no restriction on who can reach it.
The screen that asks who the owner should be, waiting since September.
The owner of this tool can run commands on the server it sits on.
One forgotten page was enough for a stranger to take over your server. Teyna found it before anyone else did, and told you which door to close first.
Connect the repository and it reads that too: passwords in the code, keys still working, packages with known holes.
What's includedIt has been in the repository since a commit made 14 months ago, and it still works. Anyone who can read the code can send mail as you — replace it with a setting, then retire the old key.
A password left in your code 14 months ago still worked. Teyna found it, showed exactly where it is, and wrote the fix for you or your AI to apply.
You confirm your email and land in your dashboard while the first run finishes, which takes about a minute. You see what was found in plain words, worst first. Nothing to install, and no card.
It shows the signs you can see from outside: hidden scripts on your pages, spam pages Google sees but you don’t, strange redirects, and whether your site is on a blocklist. It can’t see inside your server, so a clean result is not a guarantee, and it does not clean the site for you. If it finds signs of a hack, it tells you exactly what to do first.
Usually not. Teyna is gentle, only reads, and signs every request with its own name, so it is easy to recognise. If your host does block it, we tell you and show how to let it through.
A plugin watches from inside WordPress. Teyna looks from outside, the way an attacker does: forgotten copies, open backups, your email, parts of your site the plugin never sees. The two work well together.
Yes. Put every client site in one list on Pro and send reports under your own name. Need more than five? You add them from your dashboard.
If your first paid month finds nothing worth fixing, that month is refunded automatically, and you keep the report — a dated record that your site was checked and nothing was found. That is the answer you want when a client, a bank or an insurer asks.
That's who it's written for. Each problem is one sentence about what could happen to you, then the steps to stop it. No codes, no jargon. If a fix needs a developer, we say so instead of pretending you can do it.
Most fixes are settings you change yourself in 5 to 20 minutes, and the steps say exactly where to click. For the rest you can copy a ready-made prompt and give it to an AI assistant like Cursor, Claude or ChatGPT, or forward the whole list to whoever built your site.
The free run takes about a minute and appears on screen. The full run happens overnight and is waiting for you the next morning — it's deliberately slow and gentle so your site never feels it.
The free run only reads what anyone on the internet can already see, the same way a search engine does. Anything deeper is switched on by you, on your own site, inside your dashboard.
It's yours. We keep the report so you can compare it with the next one, we don't sell it, and we don't publish anything about your site. Delete your account and the reports go with it.
Yes. Teyna checks the site the way the public sees it, so it doesn't matter what it was built with. On hosted builders some fixes are settings in your account, and the steps are written for that.
Yes. Type the server’s IP address into the same field instead of a web address. Teyna checks what that server shows to the internet: which doors are open, what software answers behind them, and whether that software has known holes. The padlock and email checks need a web address, so for a website you get the fullest report by typing its address.
Enter the address and the run starts. Results land in your dashboard.
For online shops, small businesses, web studios and anyone shipping with AI. No security team needed.