Compare
Vulnerability scanner & pentest platform
Astra Security sells a vulnerability scanner and pentests, from autonomous pentests to manual testing by certified experts, with compliance-ready reports. Decloak takes a different route: a free no-account scan, flat plans where DAST and AI pentesting are included in Enterprise at £99/month, and client-side supply chain checks.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Astra Security: Vulnerability scanner & pentest platform, India and United States
“Not advertised” means we could not confirm the capability from Astra Security's public website, not that it is absent.
| Capability | Decloak | Astra Security |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Partial $7 one-week trial of the DAST scanner |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | Yes Scanner, Pentest Auto, API and Cloud plans are listed |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Scanner Lite $69/mo; Scanner $199/mo; Agency $499/mo (5 targets); Pentest Auto $199/mo; Pentest Expert $5,999/yr |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Yes 15,000+ tests covering OWASP, SANS and CVEs |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Yes Authenticated scans from Scanner Lite |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes Separate API DAST Scanner and API Security Pro plans |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Not advertised |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Not advertised |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Not advertised |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Yes Autonomous Pentest Auto, or manual pentest by certified experts with CREST, PCI-ASV and CERT-IN reports |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Not advertised |
| Internal network scanning | No External scanning only | Extra cost Internal application scanning on Enterprise Pentest |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Yes Cloud Security plans for AWS, Azure and GCP |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Partial Compliance view for SOC 2, ISO 27001, PCI DSS and HIPAA |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Partial AI-powered conversational fixing assistance |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Yes Pentest reports for SOC 2, ISO 27001 and HIPAA; PDF, CSV and JSON exports |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Yes CI/CD, Slack and Jira |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Not advertised |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Not advertised |
Astra figures come from its public pricing page and are in US dollars, listed per target (the Agency plan covers a pool of 5). Plans offer monthly or annual billing. Decloak prices are flat monthly plans in GBP.
Decloak scans a page in about 15 seconds with no sign-up and no payment. Astra's entry point is a $7 one-week trial.
Decloak Enterprise at £99/month includes DAST and sandboxed AI pentesting. On Astra these are separate Scanner and Pentest plans, each per target.
Decloak inspects third-party scripts, tag manager containers and vulnerable JavaScript libraries. Astra does not advertise this layer.
Decloak checks Supabase, Lovable, Base44, Bubble and Next.js apps for readable databases and exposed service keys, on the free tier too.
Astra Pentest Expert uses certified testers and issues CREST, PCI-ASV and CERT-IN compliant reports with expert re-scans. Decloak has no human-reviewed reports.
Astra sells cloud security scans for AWS, Azure and GCP, and API plans with live traffic capture and shadow API detection. Decloak is an external web scanner; cloud connectors are only scoped on its roadmap.
Annual Scanner plans include four expert-vetted scans to remove false positives. Decloak findings are automated and are not vetted by a person.
If you want automated, continuous web scanning with AI pentesting at a flat price, yes. If you need an expert-led pentest report from certified testers, Astra offers that and Decloak does not.
Astra's Scanner is $199 per month for one target, and Pentest Auto starts at $199 per month. Decloak is free for single-page scans, then £29, £79 or £99 per month, with DAST and AI pentesting in Enterprise.
No. Decloak AI pentests run automatically in a sandbox and attach proof-of-exploit evidence, but no human engineer reviews or signs off the report.
Astra Security details are taken from the sources above and were last checked on 7 October 2026. Product names belong to their owners and Decloak is not affiliated with Astra Security. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: