SiteGov
For agencies and digital service providers

Go-live day. DNS needs to update. Nobody can log in to the registrar.

Know who controls every provider behind every client site.

SiteGov maps the registrar, DNS, hosting, email, and SSL behind every domain. Your team records who controls each one. Whether it’s go-live day, a migration, or a renewal, you’ve already got the answer.

No credit card required. Your first scan in under five minutes.

The client owns the domain. Your team owns the emergency.

Projects don’t stall because of missing code. They stall because of missing ownership.

Before a project goes live, someone needs access to DNS. Before a domain renews, someone needs to own the registrar account. Before a site migrates, someone needs to know which provider controls the hosting, and who the login belongs to. When that information is missing, everything stops. None of it was hidden. It was all discoverable on day one. Nobody looked.

Access blockers at launch

The site is built. The client is ready. The DNS is still managed by an agency that stopped returning emails six months ago. The registrar login went to someone’s personal Gmail. The project is not going live today. This was all visible before the project started.

Hidden ownership risk

A critical provider account belongs to someone who left eighteen months ago. Nobody documented a backup admin. Nobody actually knows if MFA is enabled. Everything is fine. Right up until it isn’t. It was there on day one. Nobody documented it.

Handoff failures

A client switches agencies. The incoming team inherits a tangle of accounts, personal logins, and extremely confident guesses. The outgoing agency is pretty sure the domain is in a GoDaddy account. Probably. What should take a day takes three weeks. The information existed. It just lived in three people’s heads and one personal inbox.

The highest-cost moment

When the project needs to go live, the information is already there — or it isn’t.

Kickoff

Start the project knowing what you’re working with.

Without SiteGov, discovery happens mid-project. Who registered the domain, who controls DNS, who holds the registrar login — all of it surfaces after the timeline is already set.

With SiteGov: scan on day one, complete infrastructure map before the first meeting.

Migration

Move the site without a last-minute search party.

Without SiteGov, hosting and DNS details are scattered across old emails. Moving platforms means discovering mid-project who has the login and whether it still works.

With SiteGov: every provider is already documented before the project starts.

Go-live day

The cutover window is open. You already have what you need.

Without SiteGov, go-live day is when you find out the DNS is still controlled by a previous agency. The cutover window closes. The project doesn’t ship today.

With SiteGov: credentials are documented, the admin is identified, the path is already clear.

From emergency response to operational control.

A clear record of who controls what, across every client site.

Not compliance paperwork. Not a new workflow. A maintained record of who controls every provider behind every client site, built from automated scans and kept current by your team.

Scan a domain and SiteGov maps the registrar, DNS, hosting, email platform, and SSL authority from live data. Then document who manages each asset: who the backup admin is, where credentials are stored, whether MFA is confirmed. One governance record per asset. When a project needs to move, the information is already there.

  • Client site stayed live through the migration. DNS was already documented. The admin was already identified. The cutover happened on schedule.

  • Offboarding was clean — no access left behind. Every provider had a named backup admin. When the team member left, there was nothing to recover.

  • Renewal didn’t lapse — we had 60-day warning. The domain expiry was tracked. The responsible admin was on file. The renewal happened before anyone noticed.

  • Domain transfer went through on go-live day. The registrar login was documented. The transfer was ready before the cutover window opened.

christophercross.com High Risk
DACS 34
Registrar GoDaddy
PARTIAL
Nameservers Cloudflare
GOOD
Hosting WP Engine
PARTIAL
SSL ↑ 14 days
EXPIRING
Email G Workspace
MISSING
Former employee listed as DNS admin
SSL cert expiring in 14 days

How it works

Map every provider in four steps.

1

Add your clients

Paste a list of domains or upload a spreadsheet. SiteGov creates a client record for each one immediately.

2

Scan a domain

SiteGov scans DNS, SSL, WHOIS, hosting signals, and email records from live sources. No agents. No integrations. No manual data entry.

3

See every gap

Infrastructure findings surface what is missing, expiring, or mis-assigned. Missing admins, unverified MFA, and unknown credential locations are listed alongside them.

4

Document who controls each asset

Record who the primary is, who the backup is, where credentials live, and whether access recovery is documented. One record per provider. Updated as things change.

Governance Record: DNS (Cloudflare)

Primary Admin

Kenny Loggins

kenny@kennyloggins.com

Backup Admin
Not documented
MFA Status
Verified
Credentials

1Password (shared vault)

Recovery
Not documented
Partial: 2 items missing Last updated 3 days ago

The core artifact

One governance record per asset.

Every provider behind a client site gets its own governance record: who manages it, who can get in if that person is unavailable, where the credentials live, and whether the account is locked down.

Infrastructure scans verify what is actually in place. Governance records document who is responsible. Together, they answer the question every agency eventually needs to answer: can we access this if we have to?

  • Primary and backup admin per asset
  • MFA verification status
  • Credential location (password manager, email, unknown)
  • Recovery documentation status
  • Completeness score and open items

Platform

Built for agencies managing websites they didn’t build.

From kickoff scans to go-live days to annual reviews. Every feature fits a situation agencies already deal with.

LIVE · Infrastructure Change Alerts

When a client’s nameservers, registrar, IP addresses, CNAME chain, or domain lock status changes between scans, SiteGov detects it immediately and emails your team.

Silent infrastructure changes are caught before they become an incident: a DNS hijack, a registrar transfer, a nameserver swap nobody authorized.

CRIT

christophercross.com — registrar changed

47 min ago · Registrar layer

WARN

steelydan.com — nameservers replaced

2 hr ago · DNS layer

INFO

tototheband.com — IP address changed

3 hr ago · Service layer

WARN

hallandoates.com — domain lock removed

1 day ago · Registrar layer

Infrastructure Scan

Live scans pull registrar, DNS, hosting, email, and SSL data from the source. No manual entry. No stale spreadsheets. Always current.

Governance Records

Track the primary admin, backup admin, MFA status, credential location, and recovery documentation per asset. The go-to record when access is the question.

Infrastructure Map

A structured control map showing every provider layer behind a domain: domain controls, service infrastructure, and manual systems, in one organized view.

Findings and Risk Signals

Infrastructure and governance findings ranked by severity: former employee as admin, no backup documented, SSL expiring, domain renewal coming due. Each expiry includes who is responsible for acting on it.

DACS Score

The Digital Asset Control Score (0–100) measures infrastructure and access health per domain. One number that reflects how controlled each client’s web presence actually is.

Client Portfolio Dashboard

Every client, every domain, and every missing record in one view. Sorted by risk. Always current. The first page open during a client call or a project kickoff.

A key distinction

Owning it, accessing it, and controlling it are three different things.

Most website problems aren’t technical. They’re definitional. Someone assumed ownership meant access. Someone assumed access meant control. Nobody asked which one they actually had.

Ownership

Who holds legal or organizational claim over an asset. The domain registrant, the account holder, the name on the contract.

“The registrar is in the client’s name but the agency has had the login for three years.” Ownership didn’t transfer when the login did.

Access

Who has working credentials. A username, a password, a shared inbox, an API key. The ability to authenticate with a provider right now.

“The developer who set this up left six months ago. The credentials went with them.” Access without a documented backup has an expiry date.

Control

Who can actually make a change when it matters. Right now, under pressure, before a launch stalls or a domain lapses. Access plus authority plus knowing what you’re touching.

Control is the point. On go-live day, ownership doesn’t open the DNS panel. Access doesn’t help if the password is wrong. Control is what actually moves the deadline.

SiteGov documents ownership, access, and control for every provider behind a client site. One governance record per asset, kept current as infrastructure changes.

Map your first domain

For agencies

The infrastructure layer your retainers have been missing.

The providers behind each client site are messy by default. Domains registered by founders, DNS managed by previous agencies, hosting billed to personal accounts, SSL certs nobody is tracking. SiteGov gives your team a structured record of who controls what across every client, before you need it.

  • Onboarding a new client. Scan on day one. Complete infrastructure map before the second meeting.
  • Scoping a redesign. Know who controls DNS, hosting, and the registrar before the project timeline is set.
  • Shipping the site. Every credential is documented before the cutover window opens. No go-live surprises.
  • Handoffs and offboarding. Clean transfer when clients move on. Infrastructure knowledge stays when people leave.

Clients rarely ask for this until the domain expires, the launch stalls, or the handoff goes wrong. Agencies that track this proactively are the ones clients call first and leave last.

Data Ownership

Your clients keep their records. Always.

SiteGov governance records belong to the domain owner, not the agency that built them. If a client relationship ends, the records go with the client.

Think of it like medical records. A doctor can maintain them, but they belong to the patient. Your client’s access history is theirs to keep.

Common questions

What agencies usually ask.

Q·01

We already have a spreadsheet for this.

A spreadsheet holds what someone typed. SiteGov holds what’s actually running. It finds the DNS provider your spreadsheet doesn’t list, the SSL cert expiring in 11 days, and the nameserver that changed last Tuesday. The spreadsheet is a good intention. SiteGov is a live record.

Q·02

Our clients manage their own infrastructure. This isn’t our problem.

Most agencies say that until a migration stalls because the client can’t find the registrar login, or a domain renewal lapses because it was registered under an email address nobody checks. SiteGov maps who controls what before you need it, not after you’re already on a call trying to recover it.

Q·03

We’d have to enter all of this manually.

The scan is automatic. SiteGov probes the domain and populates registrar, DNS provider, nameservers, hosting, SSL, and email infrastructure without manual entry. What you add is who controls each one: who has the login, MFA status, credential location. That part takes minutes per domain, once, and stays current.

Q·04

What happens to our client’s data if the relationship ends?

The governance record belongs to the domain owner, not the agency that built it. If the relationship ends, the record transfers to the client. It’s not lost, and it’s not locked in. Think of it like medical records: the provider maintains them, but they belong to the patient. Your client’s infrastructure history is theirs to keep.

Get started

Every client has a gap.
Find yours in five minutes.

Add a domain and run your first scan. You might be surprised what turns up.

No credit card required. Five minutes to find out what nobody on your team actually knows.