Compare

Enterprise DAST & infrastructure vulnerability scanning
AppCheck is a mature enterprise scanner with scripted multi-step login flows (GoScript), infrastructure scanning and CI/CD integrations, sold on quote-based, per-target licences. Decloak is a self-serve alternative for teams that want DAST, AI pentesting and ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA evidence mapping on a published £99/month plan, plus client-side supply chain checks AppCheck does not advertise.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
AppCheck: Enterprise DAST & infrastructure vulnerability scanning, England, UK
“Not advertised” means we could not confirm the capability from AppCheck's public website, not that it is absent.
| Capability | Decloak | AppCheck![]() |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | No Free trial on request |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | No Contact sales for a quote |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Not published; licensed by target scope, with unlimited scans and users within it |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Yes Web application scanning with a browser-based SPA crawler |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Yes GoScript scripted multi-step user journeys |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes Swagger/OpenAPI, GraphQL and SOAP |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Partial Asset discovery and OSINT |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Not advertised |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Partial Known-vulnerability detection via the hourly-updated VulnFeed |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Yes Automated penetration testing with proof of exploit |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Yes Internal, external, cloud and self-hosted infrastructure |
| Internal network scanning | No External scanning only | Yes Internal infrastructure scanning |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Partial Scans cloud-hosted systems; account connectors not advertised |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Not advertised |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Not advertised |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Partial Detailed reports with remediation guidance |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Yes Azure DevOps, Jenkins and TeamCity |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Partial Open API |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Not advertised |
AppCheck does not publish prices. Its site describes target-based licences with unlimited scans and users within the licensed scope. Decloak prices are flat monthly plans with no per-target add-ons.
Decloak plans are £29, £79 and £99 a month, self-serve, cancel any time. AppCheck is quote-based with no public prices, which usually means a sales conversation before the first scan.
Decloak records every request a real browser makes and inspects tag manager containers and third-party scripts, the ground PCI DSS v4.0 payment-page script rules cover. AppCheck does not advertise client-side supply chain analysis.
Pro and above tag every finding to ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA controls, with remediation tracking, an audit activity log and date-range evidence packages.
Every scan gets a plain-English AI executive summary, and Starter and above add a ranked, deduplicated Priority Remediation Plan your developers can work through.
AppCheck GoScript models multi-step login and user flows as scripts that replay before each scan. Decloak captures a logged-in session through a browser extension, which works with passkeys but does not replay scripted login flows.
AppCheck scans internal, external, cloud and self-hosted infrastructure. Decloak is external and web-focused, with only a light port probe for IP targets.
AppCheck integrates with Azure DevOps, Jenkins and TeamCity and offers unlimited users per licence. Decloak has a REST API and MCP server but no CI plugins today, and SSO is proposed on our roadmap.

For teams that want web app DAST, API testing, AI pentesting and compliance-mapped evidence without a sales process, yes. Decloak Enterprise is £99/month self-serve. If you rely on scripted multi-step login flows or need internal infrastructure scanning, AppCheck covers those and Decloak does not.
AppCheck does not publish pricing. It sells target-based licences through its sales team. Decloak publishes its prices: Free, Starter £29/month, Pro £79/month and Enterprise £99/month.
Yes. On Pro and above, Decloak tags each finding to ISO 27001 Annex A controls and SOC 2 Trust Services Criteria (plus NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA), and exports timestamped PDF reports and date-range evidence packages for auditors.
Partly. Decloak Enterprise scans behind a login using a session captured with its browser extension, which also works with passkey logins. It does not replay scripted multi-step login flows the way GoScript does.
AppCheck details are taken from the sources above and were last checked on 2 October 2026. Product names belong to their owners and Decloak is not affiliated with AppCheck. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: