Free · No account · Results in 15 seconds

Automated web security intelligence
for vibe coders, small businesses, compliance teams, agencies, solo builders, security teams, MSPs

Decloak scans 8 attack surfaces simultaneously - JavaScript CVEs, hidden trackers, third-party data flows, DNS/TLS posture, subdomains, security headers, vibe-coded platform security, CMS detection and checking - and delivers a scored, graded report in under 15 seconds.

8 scan layersCVE databaseAI summaryFree - no card required

See it in action

From free scan to compliance evidence - in one video.

A two-minute walkthrough of the free scan, the AI agent investigation, and what changes when you need audit-ready evidence.

What Decloak finds

Your website is doing things you don't know about.

Eight attack surfaces, one scan - JavaScript CVEs, hidden trackers, exposed subdomains, DNS/TLS misconfigurations, publicly readable Supabase databases, and more. Most tools check one thing. Decloak correlates findings across every layer to surface risks single-purpose scanners miss.

Findings below marked Free come from the free single-page scan - Starter+ findings (subdomains, DNS/TLS) need a full agent scan.

CriticalLayer 10 · PlatformFree

Supabase database publicly readable via anon key

GET /rest/v1/users?select=* → 200, 3 rows

CriticalLayer 4 · JavaScriptFree

Stripe API key exposed in production bundle

sk_live_4xK9mRpQ2...

HighLayer 4 · CVEFree

jQuery 1.12.4 - CVE-2019-11358 (XSS)

/assets/vendor.js · loaded on 3 pages

HighLayer 5 · Tag ManagerFree

GTM firing to 3 unrecognised domains

cdn-analytics-2847.io · reg. 6 weeks ago

MediumLayer 1 · HTTPFree

Content-Security-Policy header missing

No CSP policy found across 12 pages

MediumLayer 2 · HTMLFree

Hidden 1×1 tracking pixel - doubleclick.net

<img width="1" height="1" style="display:none">

InfoLayer 4 · SourceFree

Source map exposed - /dist/app.js.map

Original source code reconstructable

CriticalLayer 10 · PlatformFree

Supabase service_role key exposed in client JS

Masked key: eyJhbGciOi...4kD9x2

MediumLayer 9 · SubdomainsStarter+

Forgotten staging subdomain still live

staging.example.com · exposed admin login

HighLayer 9 · TLSStarter+

TLS certificate expires in 4 days

issuer: Let's Encrypt · no auto-renewal detected

HighLayer 1 · CMSFree

WordPress 6.2 - CVE-2023-2745 (Directory Traversal)

wp-includes/version.php · plugin/theme fingerprinting also run against Shopify, Magento, and 15+ other platforms

Free tier · Built with AI

Shipped it fast?
We check what got skipped.

Apps built with Lovable, Supabase, Base44, Bubble, and similar AI app builders share the same handful of recurring security failures - most famously, a Supabase database left publicly readable because Row Level Security was never turned on. Decloak fingerprints your stack and checks for the specific misconfigurations reported for it, on every scan, free tier included.

See vibe-coder features

Publicly readable database detection

Checks whether your Supabase tables can be read by anyone using your own public anon API key - the single most common security failure in AI-app-builder projects.

Exposed service_role key detection

Flags a leaked Supabase service_role key sitting in your client-side JavaScript before an attacker finds it - that key bypasses Row Level Security entirely.

Platform fingerprinting

Automatically detects Lovable, Supabase, Base44, Bubble, and Next.js - no configuration needed, no platform to select.

Known platform CVEs

Checks for named, high-impact vulnerabilities like the Next.js middleware authorization bypass (CVE-2025-29927).

Who it's for

One scanner. Four very different jobs.

From a five-minute sanity check on a weekend project to monthly audit evidence across a whole client portfolio.

Vibe coders & solo builders

Shipped fast with AI and skipped the security review? Paste your URL and see exposed keys, missing headers, and vulnerable libraries before your users find them.

Scan your app free

Small & growing businesses

Scheduled scans, DNS/TLS checks, and forgotten-subdomain discovery - real security posture without an enterprise scanner budget.

See what you get

Compliance & security teams

SOC2, ISO 27001, NIS2, and DORA evidence, mapped automatically, plus Enterprise-tier Active Security Testing (DAST) with an independent score.

View compliance features

Agencies & MSPs

One dashboard across every client domain - subdomain discovery, DNS/TLS posture, and team seats so the whole account team can see it.

See team features

Free scan

Free scan: three steps. Fifteen seconds.

This is the free, single-page tier - no account needed. Want full-site coverage? That's the paid agent investigation below.

01

Paste any URL

No account, no setup, no browser extension. Just a URL. Free tier results in under 15 seconds.

02

AI scans 8 attack surfaces

HTTP headers, HTML, live network traffic, JavaScript CVEs, tag managers, third-party supply chain, vibe-coded platform misconfigurations, CMS/platform fingerprinting, and behavioural analysis - simultaneously.

03

Get your scored report

A graded A–F report with an AI-written executive summary. Shareable by link. Readable by anyone.

Full agent scan · Starter and up

Full agent intelligence:
It doesn't scan. It investigates.

The free tier scans one page. Paid plans deploy an AI security agent that reads each finding and decides what to look at next - following threads, fetching scripts, checking domains - until it has complete site coverage.

  • Reads findings and decides what to investigate next
  • Fetches and scans every identified JavaScript file
  • Checks domains against threat intelligence databases
  • Reconstructs source code from exposed source maps
  • Produces per-finding remediation guidance
  • Shows its reasoning at every step
agent · investigation log
live
00:01statusStarting investigation of example.com
00:04pageLayer 1–8 scan complete · 4 findings
00:06agentExposed source map detected at /dist/app.js.map
00:08fetchFetching source map · 1,847 source files found
00:11findingHardcoded API key in src/utils/analytics.ts
00:13agentGTM container GTM-X4K9P2 detected - fetching
00:16page14 active tags · 3 firing to unknown domains
00:19findingcdn-analytics-2847.io · registered 6 weeks ago
00:24agentChecking DNS records and TLS certificate (Layer 9)
00:27findingSPF record missing · spoofing risk
00:30agentEnumerating subdomains
00:34findingstaging.example.com discovered · exposed admin login
00:37fetchCross-referencing WHOIS for 3 third-party domains
00:40agentWriting per-finding remediation guidance
00:43doneInvestigation complete · 15 findings · 3 critical

For compliance teams

Replace your compliance scanner.

Teams using AppCheck, Qualys, or Tenable for monthly SOC2 and ISO 27001 evidence pay thousands per year for reports that still need a pentester to interpret. Decloak delivers the same scheduled scan cadence, maps findings to SOC2, ISO 27001, NIS2, and DORA controls, and produces PDF evidence packages - at a fraction of the cost.

View compliance features

Scheduled recurring scans

Automated weekly, monthly, or quarterly cadence keeps your SOC2, ISO 27001, NIS2, and DORA evidence current without manual effort.

PDF evidence packages

Timestamped, exportable PDFs with a scan attestation block, formatted for evidence review.

ISO 27001 / SOC2 / NIS2 / DORA mapping

Findings automatically tagged to ISO 27001 Annex A controls, SOC2 Trust Services Criteria, NIS2 Article 21 measures, and DORA ICT-risk articles.

Scan history and comparison

Compare each scan against the last - show auditors exactly which findings have been resolved.

Remediation tracking

Mark findings as Open, In Progress, Resolved, or Accepted Risk. Auditors need to see action was taken.

Multi-domain dashboard

One view across all your domains - current grade, last scan date, and open critical findings.

Audit activity log

A per-domain log of every scan, deletion, and finding change - who did it and when, ready for change-control evidence.

Enterprise

Go beyond observation.
Actively test it.

Enterprise scans add safe, non-destructive active probes on top of the full investigation - forced browsing, CORS misconfiguration checks, reflected-input canaries, and authenticated scans behind a real login. Results roll up into an independent Active Testing Score and a standalone, boardroom-ready DAST report.

See Active Testing features

Active Security Testing (DAST)

Forced browsing, CORS misconfiguration probes, HTTP method checks, and postMessage handler auditing - beyond passive observation.

Independent Active Testing Score

A dedicated grade for what was actively probed, shown alongside your regular security score.

Authenticated scan mode

Capture a logged-in session via our browser extension - the only path that works for passkey/WebAuthn auth.

Executive DAST report (PDF)

A standalone, boardroom-ready PDF scoped to Active Testing results - severity breakdown and a full "what we tested" checklist.

Starter and up

1,000 findings. 7 things to fix first.

A full scan can surface hundreds of findings - useful for coverage, useless for a Monday morning to-do list. The Priority Remediation Plan collapses duplicates, ranks what's left by severity, and hands you a top-25 fix list in plain English, exportable as a PDF you can send straight to a client or developer without them ever opening the full report.

See Priority Remediation Plan features

Top 25, ranked

Every finding scored by severity, then whether a CVE is involved, then how long it has sat open - so the list is always "fix this first," not just "everything we found."

Plain-English AI guidance

Each item comes with specific, actionable remediation advice - not a CVE ID and a shrug.

Client-ready PDF export

Hand a finished plan straight to a client or developer - no one has to click into individual findings to know what to do next.

Status & assignment tracking

Mark items Open, In Progress, or Resolved and assign them to a teammate, right from the plan - a Pro-plan upgrade on top of Starter.

Pricing

Start free. Scale when you need to.

Free for individual page checks. Paid plans unlock full AI agent investigations, scheduled scans, and compliance reporting - at a fraction of enterprise scanner costs.

Free

£0
  • 1-page scan per submission
  • All 8 scan layers
  • Vibe-coded platform security scan (Supabase, Lovable, Base44 & more)
  • AI executive summary
  • Scan history in your account
  • Re-scan and delete anytime
  • Shareable public link
Create free account

Starter

Popular
£29/ month
  • Full AI agent investigation
  • Up to 50 pages per scan
  • Per-finding remediation guidance
  • Priority Remediation Plan (top fixes, AI-written, exportable PDF)
  • AI assistant chat
  • DNS & SSL/TLS security analysis
  • PDF evidence export
  • Scheduled recurring scans
  • Scan comparison reports
  • Email alerts for new criticals
Get started

Pro

£79/ month
  • Everything in Starter
  • Up to 200 pages per scan
  • ISO 27001 / SOC2 / NIS2 / DORA control mapping
  • Remediation tracking
  • Team access and finding assignment
  • Slack and webhook notifications
  • API access
  • Audit evidence packages
  • Audit activity log
  • White-label PDF branding
Get started

Enterprise

Full DAST
£99/ month
  • Everything in Pro
  • Active Security Testing (DAST)
  • Independent Active Testing Score
  • Forced browsing, CORS, reflected-input probes
  • Authenticated scan mode (session capture)
  • Enable active testing via API / MCP
  • Priority support
Get started

The Decloak Journal

Security news & platform updates.

Stories from around the web security world, plus release notes and changes to Decloak itself.

View all posts