Compare
Autonomous application & API security platform
Aptori is an autonomous application and API security platform that joins source code analysis, runtime validation, autonomous pen testing and automatic code fixes. It sells by demo. Decloak is an external scanner: no code access, a free scan, published flat plans, and client-side supply chain checks.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Aptori: Autonomous application & API security platform, Not stated on its website
“Not advertised” means we could not confirm the capability from Aptori's public website, not that it is absent.
| Capability | Decloak | Aptori |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Not advertised |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | No Book a demo |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Not advertised Pricing not published |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Yes Runtime-driven testing and semantic runtime validation |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Not advertised |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes API security testing, authorization validation and BOLA testing |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Not advertised |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Not advertised |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Partial Software composition analysis of dependencies |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Yes Autonomous penetration testing with exploitability validation |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Partial Kubernetes and IaC security |
| Internal network scanning | No External scanning only | Not advertised |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Not advertised |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Partial EU CRA, UK TSA and SOC 2 Type II mentioned |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Not advertised |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Not advertised |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Yes Source control, CI/CD, Jira and ServiceNow |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Not advertised |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Not advertised |
Aptori does not publish pricing on its website; it directs visitors to book a demo. Decloak prices are flat monthly plans in GBP.
Decloak scans the live website from the outside. Aptori's strongest features depend on connecting source code, APIs and runtime.
Decloak publishes every price and scans a page in about 15 seconds with no account. Aptori sells by demo.
Decloak inspects third-party scripts, tag manager containers and every external domain contacted. Aptori does not advertise this layer.
Decloak checks Supabase, Lovable, Base44, Bubble and Next.js apps for readable databases and exposed service keys, on the free tier too.
Aptori joins AI SAST, API testing and runtime evidence, and generates fix pull requests. Decloak does not scan source code or open pull requests.
Aptori describes authorization validation and BOLA testing across identities and workflows. Decloak's API testing is lighter and runs on Enterprise.
Aptori lists Jira and ServiceNow. Decloak has Slack, signed webhooks and email today; native Jira is planned.
If you want an outside-in website scan at a published price, yes. If you need code analysis, deep API authorization testing and automatic fixes in one platform, Aptori covers that and Decloak does not.
Aptori does not publish pricing. Decloak is free for single-page scans, then £29, £79 or £99 per month.
Yes. Aptori works from code and runtime inside your pipeline; Decloak shows what an outside visitor sees on the live site, including third-party scripts.
Aptori details are taken from the sources above and were last checked on 7 October 2026. Product names belong to their owners and Decloak is not affiliated with Aptori. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: