◆ free & open source · Apache 2.0

See what's actually exposed on your Linux box.

Not another CPU-and-memory dashboard. securitytide scores your host's real security posture — what's listening beyond localhost, who's failing to log in, whether your firewall is even on, and how far behind you are on patches. One command. No config, no account.

pip install securitytide-cli
securitytide
✓ Localhost only by default ✓ No shell, no command execution ✓ Read-only ✓ Python 3.9+
posture
metrics
network
services
logs
terminal
Securitytide posture dashboard showing a graded security score
Posture. A 0–100 score with a letter grade — and every single point deduction shown. Nothing hidden, nothing black-box.
Per-core CPU, memory, load average and disk usage
Metrics. Per-core CPU, memory and swap, load average, network throughput, disk usage, and top processes.
Network interfaces and listening ports
Network. Every interface and every listening socket, with anything reachable beyond localhost flagged.
systemd service states
Services. Is your firewall active? fail2ban? auditd? AppArmor? Read-only via systemctl — it observes, never controls.
Journal entries with errors highlighted
Logs. Recent journal entries with errors and warnings surfaced, so failures don't hide in the noise.
Terminal posture report
Terminal. securitytide --once prints the whole report to stdout. Add --json and pipe it anywhere.
What it checks

The things that actually get a box owned.

Resource monitors tell you the CPU is busy. They don't tell you Redis is listening on 0.0.0.0 with no password. That's the gap this fills.

◈

Exposed surface

Every listening port, with anything reachable beyond localhost flagged — and known-risky services (Redis, RDP, SMB, unauthenticated Mongo, Telnet) called out by name.

◉

Failed logins

Brute-force attempts over the last 24 hours, aggregated by source IP so a real attack stands out from ordinary noise.

▣

Security services

Firewall (firewalld / ufw / nftables), fail2ban, auditd, AppArmor, SSH — what's actually running versus what you assumed was running.

↑

Pending patches

How many security updates you're behind, via apt or dnf. The simplest question in security, and the one most often unanswered.

◆

An explainable score

A 0–100 posture grade where every deduction is itemised. You always know why you scored what you scored, and what to fix first.

▤

Full system monitoring

Per-core CPU, memory, load, disks, processes, interfaces, and journal logs — the ordinary monitoring you'd want anyway, in the same pane.

Install

Running in under a minute.

One pip install. No agent to register, no config file, no account to create.

01

Install

From PyPI. Python 3.9 or newer, on Linux.

pip install securitytide-cli
02

Run

Starts on 127.0.0.1:8787 and opens your browser.

securitytide
03

Or stay in the terminal

One-shot report, or JSON to pipe into anything.

securitytide --once
securitytide --once --json
04

Viewing remotely?

Tunnel over SSH. Don't expose the port — the dashboard maps your weak points.

ssh -L 8787:127.0.0.1:8787 you@host
Safe by design

A security tool shouldn't be the hole.

This dashboard maps your host's weak points. So it's built, deliberately, to keep that map to yourself — and to be incapable of doing anything to your system even if someone did reach it.

▣
Localhost onlyBinds to 127.0.0.1. Binding anywhere else needs an explicit flag and a typed confirmation.
▣
No shell, everThere is no terminal, no command execution, no eval. Nothing you send the API can make it run anything.
▣
Strictly read-onlyFixed, read-only system queries. It cannot start, stop, or change a single thing on your box.
▣
Same-origin lockedNo wildcard CORS. A website you visit can't script your local instance.
▣
Open sourceApache 2.0. Read every line before you run it — that's the point.
One host, or many

The free tool is complete on its own.

securitytide is scoped to one machine — yours — and it isn't crippled. You only need the cloud version when one host becomes a fleet, and a fleet becomes someone's job.

  securitytidefree, open source, self-hosted Securitytide Cloudfor fleets and teams
Hosts1Unlimited
Posture score & findings✓✓ fleet-wide
Exposed ports, failed logins, services✓✓
Metrics, processes, logs✓✓
Pending security updates✓✓ with CVE detail
Full CVE cross-reference (NVD)—✓
AI-assisted triage & remediation—✓
Anomaly detection & baselining—✓
Alerting (Slack, email, PagerDuty)—✓
Compliance reporting (CIS, NIST)—✓
Teams, roles, audit log—✓
PriceFree foreverIn development
◆ in development

When one host becomes a hundred.

Securitytide Cloud takes the same posture engine across your whole fleet — with real CVE cross-referencing, AI-assisted triage that ranks by actual exploitability, anomaly detection, alerting, and compliance reporting. Built for the people who get paged.

✓ CVE cross-reference ✓ AI triage ✓ Anomaly detection ✓ CIS / NIST reporting