Vulnerability scanning, live host metrics, network discovery, threat intel and compliance checks — one dashboard, one API, one CLI. Real data only; nothing mocked.
# install the CLI npm i -g @rootwatch/cli # point it at the control plane rootwatch login --server https://app.rootwatch.dev --token rw_… # scan this machine rootwatch scan ✓ secrets ✓ dependencies ✓ repo hygiene — findings pushed to dashboard
Sixty seconds from zero to your first scan.
Sign up at app.rootwatch.dev — your organization is created automatically.
Dashboard → Access Control → New token. Pick scopes (read, scan, write, admin). Tokens are rw_…, shown once, hashed at rest.
CLI, MCP agent, desktop app, or curl — every client authenticates with the same token against the same org-scoped data.
One trust boundary — the server. Four ways in.
Secrets, dependency and hygiene scans on any repo or host. Results land in the dashboard.
npm i -g @rootwatch/cli rootwatch login --server https://app.rootwatch.dev \ --token rw_… rootwatch scan # secrets · deps · hygiene rootwatch scan --depsnpm · build from source: cli/
Streamable HTTP MCP server with 11 tools — or the stdio bridge for desktop MCP clients.
// claude_desktop_config.json / mcp.json { "mcpServers": { "rootwatch": { "url": "https://app.rootwatch.dev/mcp", "headers": { "Authorization": "Bearer rw_…" } } } }stdio bridge: rootwatch mcp
Org-scoped Bearer-token API. Score, hosts, scans, vulnerabilities, events, reports.
curl -H "Authorization: Bearer rw_…" \ https://app.rootwatch.dev/api/v1/score curl -H "Authorization: Bearer rw_…" \ https://app.rootwatch.dev/api/v1/vulnerabilitiesscopes: read · scan · write · admin
Electron thin client for Linux — AppImage, deb, snap. Same login, same data, native shell.
# grab a build from releases github.com/homezloco/rootwatch → Releases → RootWatch-*.AppImagelinux · experimental flatpak
A rule engine plus real collectors — no sample data, ever.
SSH config, firewall state, pending security updates, Docker socket exposure, failed-login spikes, unexpected public listeners. Failures become findings; recoveries resolve them.
Neighbor table discovery plus TCP connect scans — open ports, risky exposed services, per-device history and risk scores.
CISA KEV feed for exploited-vuln awareness, Trivy filesystem scans for real CVEs in installed packages.
Live-data HTML reports, compliance check rows, audit log — every surface org-scoped.
The whole control plane runs anywhere Node 20 and Postgres do.
git clone https://github.com/homezloco/rootwatch && cd rootwatch npm install && cp .env.example .env # set DATABASE_URL npm run db:migrate && npm run dev # http://127.0.0.1:5000 # production: Dockerfile included — npm run build && npm start