Skip to content
SolutionsFor enterprise

Many sites, many teams, roles that keep them apart

At this size the problem is not finding issues. It is knowing which of forty properties moved this week, and making sure the person who can fix it is the person who can see it.

app.pixyscan.com/w/…/settings/members
Workspace members: people with their roles, and the invitation flow.
Sound familiar?

If any two of these are true, this page is for you

None of them is unusual. They are what happens to a site that ships regularly and is only ever looked at deliberately.

  • Forty domains, six teams, and no single view of which of them regressed.
  • Access is all-or-nothing, so nobody is comfortable handing out logins.
  • Retention matters - an audit trail that only goes back a month is not an audit trail.
  • Procurement wants to know where the data sits before anyone can trial anything.

What PixyScan does

3 things, specifically

Each one is a mechanism in the running product, not a positioning statement.

  1. 01

    Roles at two levels

    Per workspace and per site. A team gets its own properties without inheriting the rest of the estate, and invitations arrive by email.

  2. 02

    What the larger plans carry

    Pro brings 25 sites, 10 seats, 125,000 URL credits a month, five concurrent scans, two years of history, JavaScript rendering and white-label reports. Enterprise sets each of those by contract. Sign-in is email and password with an emailed one-time code at signup, or Continue with Google.

  3. 03

    Retention set by contract

    History runs to two years on Pro and up to ten by contract, so a scan from three years ago is still a scan you can open.

How it fits your week

Day one, then every week after

When you would actually open it. A tool you have to remember is a tool that gets forgotten, so most of this runs without you.

  1. Step 1

    Day one: the estate, mapped to teams

    Each property becomes a site; each team gets membership on its own sites; the platform team keeps the workspace role. Decide the role map before inviting anyone - roles are set per workspace and per site, invitations go out by email, and sign-in is email and password with an emailed one-time code at signup, or Continue with Google.

  2. Step 2

    Every week: a portfolio ranked by health

    Forty sites on schedules produce forty Changes screens, and the portfolio view orders them by score so the ones that moved are at the top. The teams read their own; the platform team reads the ranking.

  3. Step 3

    Every quarter and every audit: history that goes back

    Any run within retention reopens in full - the score, the findings, the arithmetic behind the number - as it was on that day. Two years on Pro and up to ten by contract is long enough for an audit trail to be an audit trail.

Worth knowing

  • Unlimited sites, seats and URL credits on Enterprise, with limits set per contract.
  • Data is hosted in the European Union (Frankfurt, Germany).
  • A named support contact rather than a shared queue.
  • Every scan records its branch and environment, so a staging estate stays separate from production.

What it will not do for you

  • No SSO - no SAML, no OIDC, no SCIM or directory sync - and no SOC 2 or ISO certification. We would rather say so than imply any of it is in progress.
  • No public REST API yet, which matters if you were planning to pipe results into a warehouse.

Above the signup button on purpose

A month in

What is different four weeks later

Each of these is something you could check, not something you would have to take on trust.

  • One view of which properties regressed this week, across every team.
  • Access that is narrow by default: a team sees its sites, a contractor sees one.
  • A scan from before any given release is still openable, for as long as the contract keeps it.
  • Staging and production estates measured separately, on the same schedules, without one polluting the other.

Before you ask

Things people in your position ask first

Plans, edges, and the honest answer to the question this page is most often found by.

Where is the data hosted?

In the European Union, in Frankfurt, Germany. The data processing addendum and the subprocessor list are published on this site and linked from the footer.

What certifications do you hold?

None yet - no SOC 2 and no ISO 27001. There is also no SSO: no SAML, no OIDC, no SCIM or directory sync. Sign-in is email and password with an emailed one-time code at signup, or Continue with Google, and access is controlled by roles per workspace and per site. We would rather state all of that plainly than imply any of it is in progress. The security practices and the DPA are available for your review on request.

Is there an API for piping results into our warehouse?

Not a public one yet. Today results leave the product as PDF, CSV or the CLI's exit code and log. If a documented endpoint is a condition of purchase, tell us in the demo and we will say honestly where it sits on the roadmap.

See what is actually on your site

Point PixyScan at a URL and read the first report in a few minutes. The free plan covers one site and 500 URLs a month - enough to find out whether any of this is true.

No card required · 500 URLs a month on the free plan