Skip to content
AI Website Security

Website security

You will know exactly what your site contains.

An antivirus compares your files against a list of catalogued threats — a list that will never contain the one targeting you. We work the other way round: we establish where each legitimate file comes from, and we show you what has no provenance.

Justification in progressdemonstration
0

justified

0

without provenance

812

executables

  • core/lib/Db/DbPDO.php
  • includes/version.php
  • modules/paiement/gateway.php
  • plugins/catalogue-export/index.php
  • themes/boutique/functions.php
  • var/cache/prod/min.a3f9c2.js
  • admin/includes/file.php
  • uploads/2026/01/index.php
  • vendor/composer/autoload_real.php
  • includes/class-query.php
  • uploads/2026/01/i.php
  • mu-plugins/.cache.php
  • includes/js/editor/tmce.php

Three files could not account for their presence. These are the only ones we will discuss — the other 809 bear the name of their origin.

My site has been hacked

Analysed. Repaired. Attested.

With nothing to install, in a single operation: the complete analysis, the automatic repair — proven or cancelled, your site is re-tested after every action — plus the signed attestation of its recovery.

My site is fine — keep it that way

Monitored. Every day.

Watch compares your files every day against the official fingerprints from their publishers, and only writes to you if something has changed — on your side, or on theirs. No news is good news.

Our seal — a guilloche, the engraving that protects banknotes from counterfeiting. It is born from an equation: copying it requires recovering its numbers. Every document we issue is protected by the same principle — signed by computation, tamper-proof, and verifiable by anyone.

Renewal
none — everything is paid once
Technical action on your part
none, if you entrust us with your credentials
Modification of your files
none without the Restore option
Data retained
Record: at most one 64-character fingerprint; Watch: the monitoring record, deleted when it stops
Justification analysisdemonstration
0
executable files
0
justified
0
without provenance

Every executable file must be able to name its origin. Those that cannot are the only ones we talk about.

publisher
0
official repository
0
seal applied
0
generated
0
without provenance
0
false positives
0,0 %
across 27 real, live sites
implants detected
19/19
in an official WordPress
files of genuine code
28 972
and not one accusation

Almost no vendor publishes its false positive rate. Here is ours, with the protocol and the commands to reproduce it.

Results of our measurements
What you receive

A short document, and signed

Here is a document we actually issued, transcribed field by field. This isn't a screenshot: the file is online, and its signature can be verified without you having to trust us.

You'll notice it contains no flattering counters. It contains a verdict, zero serious findings, and four things it doesn't look at, which it names itself.

Nothing observedfinding · format 1
site
aigeniestore.com
when
2026-08-11 14:50
serious findings
0
recognized families
none

Its four blind spots, declared

  • the server files (backdoors dropped outside public pages)
  • the database (injected content, added administrator accounts)
  • the configuration files (.htaccess, wp-config, scheduled tasks)
  • the pages not visited by the analysis

signature Ed25519 · timestamped by a third party
a453 d9ec 0e45 e928 512b 13cd b2eb 3fa1

Timestamping authority non-qualified in the eIDAS sense — we state this in the document. Only 32 bytes of fingerprint were transmitted to it: neither the site's name, nor its content.

The reversal

What can be signed, shown, and re-verified

The entire difference lies in the form of the final sentence. One makes a negative claim about an infinite set. The other, a positive claim about a finite set. Only the second can be signed, shown, and re-verified by someone else.

What a signature-based tool says

"We found nothing."

  • Unverifiable: no one can check an absence.
  • Out of date by the next day, with nothing to flag it.
  • Blind to anything not yet catalogued — that is, to whatever is targeting you.
  • Shown to no one: no host will restore a site on the strength of that sentence.

What we write

"As of this date, all 812 executable files on this site had a named provenance."

  • Verifiable: the set is finite, it can be recounted.
  • Anchored to the inventory fingerprint — the first file that changes breaks it.
  • Signed: your host verifies it in their browser, without taking your word for it.
  • Refused until it is true. An attestation you always get is worth nothing.
Where others promise to detect everything, we promise to justify everything — or to attest to nothing at all.
What we promise, exactly
3f8a…c19d20…7be47c…09b1e5…446ac9…2d0f73…8ea812…5fthe file that has changedthe root is no longer the same

The attestation is anchored to the fingerprint of the entire inventory. A single modified file, and that fingerprint changes all the way up: the document contradicts itself, without anyone having to admit anything.

World firsts

Six world firsts, in service today.

Every line on this page corresponds to a mechanism actually in place — never an intention. The label "world first" is reserved for what no market player offers as of the 25 August 2026 survey; the dated comparison below provides the proof. If a line ceases to be true, it goes.

World first

The attestation the whole world can verify without us

Every document is signed by computation (Ed25519). Your host, your insurer — anyone — checks the signature in their browser, with no account, without sending us anything, without taking our word for it.

World first

Proven or void — three verdicts, never two

After every repair, your public site is re-tested. Repaired, void — the original state comes back on its own — or not observable: an error page proves nothing, so we conclude nothing.

World first

The verdict "0 unexplained executable files"

Antivirus tools look for the known-bad in an infinite space. We demand the opposite: that every executable file justify its presence. A malware nobody has catalogued yet is still caught — it is unexplained.

World first

The proven silence of monitoring

Watch only writes to you if something new has moved — silence means "nothing new", not "nobody looked".

World first

Repair in a single act

No extension, no account, no mandatory subscription — only the access details your host sent you. The full analysis, the automatic repair and the attestation of reinstatement — one operation, paid once.

World first

The intrusion window, dated

Two time boundaries frame the compromise. A vulnerability published after the window is ruled out outright — it did not exist yet. Nobody dates it; we date it.

Eight more exclusives

Three viewpoints compared

The same page served to the visitor, to Googlebot and to mobile — cloaking shows up by difference, never through a single-identity analysis.

The checkout funnel found by name

In four languages, even in noindex, even absent from the sitemap — the page that matters, the one ordinary tools never open.

The real exfiltration destination, named

When a script reads the payment fields and sends them elsewhere, the finding names the real destination — never an innocent CDN pointed at in its place.

The baseline of served scripts

A script that changes content without changing address is seen by fingerprint — the control the payment standard requires every week.

Official WordPress and PrestaShop fingerprints

Every core file compared against what the vendor actually published — nobody else covers PrestaShop.

Blind spots, disclosed in every report

What the analysis didn't see is written in black and white, with the exact coverage — a "clean" result states what it covers.

The refusal to rewrite what is already sound

The actual state is read before every action; a "repair" that would duplicate what already exists is refused, with its reason.

0.0% false positives, measured

Across 27 real sites, against their own neighbours — a replayable real-world condition, not a brochure figure.

Check for yourself rather than taking our word for it: the rates and the real-world conditions are published on the results page, and every signed document can be checked on the verification page, in your browser.

What only we do

The only one to repair a hacked site in a single act — and to prove it.

The leaders in the field do good work, each in their own way — cleanup by analysts at Sucuri and Wordfence, automatic repair via plugin at MalCare. None of them brings together the five rows of this table, and two of them exist nowhere else.

Survey of 25 August 2026SucuriWordfenceMalCareAI Website Security

Automatic repair, no human intervention

Sucuri and Wordfence have their teams of analysts do the cleanup — by ticket, within a set turnaround.

Nothing to install — no extension, no account to create

MalCare and Wordfence live inside a WordPress plugin; Sucuri goes through its firewall.

Pay per job, no subscription

With all three, repair is included in an annual subscription.

Proven or reverted — the site is re-tested after each action, with automatic rollback

Signed certificate of restoration, verifiable by a third party

It's the document your host or your insurer can check without taking our word for it.

Survey carried out on 25 August 2026 on the vendors' public pages — offers, pricing and documentation. These products change: if a line becomes inaccurate, write to us and we'll correct it. Comparing honestly is part of what we sell.

Nothing to install

No extension, no account. An address to analyse, your hosting access details to repair.

A one-off job, not a subscription

€199, once. Ongoing cover exists, but it's your choice.

Proven or reverted

Every action re-tested on your live site, otherwise undone.

Attested, signed, verifiable

An enforceable document that anyone can verify.

Trois products

One answers for today. The other answers for tomorrow.

"Is my site compromised?" and "will it still be safe tomorrow?" are two distinct questions, and a single tool cannot honestly answer both. Each is purchased separately and works on its own.

The action, after the finding

Restore reinstates the state published by your editors.

An attacker modified thirty files in the core, your extensions and your theme. Their thirty modifications disappear all at once — including those no signature would have caught, since we aren't looking for them.

This is possible because we know what your site should look like: the official fingerprints published by your CMS vendor, and the official packages of your extensions.

It rewrites only what the publisher releases

No content is guessed. Without an official original, the file is left as is — and named.

Any file set aside remains recoverable

A file whose sole purpose is malicious goes to quarantine. It can be restored in one click.

Proven, or cancelled

Your site is re-checked after every batch. At the first sign of breakage, the whole batch is rolled back.

What belongs to you stays intact

Configuration, content, media, caches: they are never rewritten, even when they diverge.

Restore is added to a product

It can't run on its own: the list of files to restore is derived from an analysis, and without it we wouldn't know what to replace them with. So it's added to one or the other of the two products — Record + Restore to repair today, Watch + Restore so that it's done every night without you.

In two steps

You connect your site. You start the analysis.

Nothing to install, nothing to download, nothing to delete afterwards. The tool handles the rest.

01

You connect your site

Its address, and the access credentials your host sent you when you opened your account. One minute.

02

You launch the analysis

You have nothing left to do. The result is displayed, and your documents are issued.

You install nothing, none of your files are modified without the Restore option, and nothing is kept by us.

Free, and in your browser

Check for yourself.

Everyone in this market asks you to trust them. We'd rather give you what you need to do without it.

Fingerprint of our public key · Ed25519

a453 d9ec 0e45 e928 512b 13cd b2eb 3fa1

Download

A document we actually issued. No file paths, no site data inside.

Drop it in

The file never leaves your computer. The computation runs in your browser, offline if you wish.

Compare

The fingerprint displayed must be exactly the one above. If it differs, the document is not ours.

What you leave with

Three documents for three distinct uses

A hacked merchant handles three difficult conversations alone: with their host, with their insurer, sometimes with the data protection authority. All three ask for the same thing — dated facts, verifiable by someone other than them.

The findings

You, your insurer, the data protection authority

What was found, when it started, what was done, what remains. It records facts — including the bad ones — and it is never refused.

It doesn't claim the site is clean, and it says so itself.

The document for your host

The abuse team that took your site offline

Short, factual, with a "how to verify it yourself" section. Every file named carries its own proof of belonging: the abuse desk recomputes THAT line and reaches its own conclusion, without ever receiving the list of your files. One goal only: getting your site back online.

No sales pitch. A document that sells ends up in the trash.

The attestation

A client, a buyer, a partner

The positive statement: on this date, every executable file had a named provenance. It is backed by the fingerprint of the inventory.

It withholds itself. As long as a single file remains unexplained, it is not issued.

The mix-up that would cost the most

Showing an incident report while believing you're showing a clean bill of health. That's why every document states its type in full, and why the verification page explicitly warns you when it reads one.

See how a third party verifies
What stays with you

The blind spots are on the front page

They appear in the signed document, not in a footnote. A tool that names its limits lets you know what you still have to do.

We read the site's files, not your database — except for whatever it reveals in the pages served.

We never keep your hosting credentials: they are used to deposit and then remove the agent — or you deposit it yourself, and they are never sent to us.

“Justified” does not mean “safe”: a fully justified site may still have a known vulnerability or a stolen password.

A file's date can be forged with a single command. When we date an intrusion, this caveat is written into the signed document.

How many files on your site can justify their presence?

You'll get the exact number, every file named, and the means to prove it to someone else.

aiwebsitesecurity · aiwebsitesecurity · aiwebsitesecurity ·