Compare
External attack surface management & DAST
Detectify is built for mapping and continuously testing large external attack surfaces, with payloads sourced from a network of 400+ ethical hackers and 600+ subdomain takeover methods. Decloak is the better fit when you want one predictable plan covering web app DAST, sandboxed AI pentesting, client-side supply chain analysis and compliance control mapping, starting with a free scan that needs no account.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Detectify: External attack surface management & DAST, Sweden
“Not advertised” means we could not confirm the capability from Detectify's public website, not that it is absent.
| Capability | Decloak | Detectify |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Partial Starter plan has no platform fee; scanned assets are billed |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | Partial Platform fees published; per-asset prices are not |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Platform fee €0, €2,500, €5,000 or €15,000 per year, plus costs per asset, domain and environment |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Yes Application Scanning with deep crawling and dynamic fuzzing |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Yes Recorded login flows |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Partial REST and GraphQL |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Yes Surface Monitoring with 600+ subdomain takeover methods |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Not advertised |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Not advertised |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Partial Payload-based tests informed by 400+ crowdsourced ethical hackers; no sandboxed pentest toolkit advertised |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Partial IPs, ports and protocols within Surface Monitoring |
| Internal network scanning | No External scanning only | Yes Internal Scanning (Professional plan includes one environment) |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Not advertised |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Partial PCI ASV scanning as a €500/yr add-on; per-control mapping not advertised |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Not advertised |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Not advertised |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Yes White-labeled reports on Professional and up |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Yes Standard integrations on every plan |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Yes API plus an MCP server |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Yes Okta, Ping Identity, OneLogin, SAML 2.0 (Standard and up) |
Detectify figures come from its public pricing page: annual platform fees by plan, with additional costs for assets, domains, environments and IP ranges that are not listed publicly. Decloak prices are flat monthly plans with no per-target add-ons.
Decloak plans are £29, £79 and £99 a month. Detectify adds per-asset, per-domain and per-environment costs on top of a platform fee that reaches €15,000 a year.
Decloak Enterprise runs real tools (sqlmap, dalfox, commix, nuclei, ffuf, jwt_tool) in an isolated sandbox against targets your scan already found, and attaches the exact request and response that proved each finding.
Decloak records every request a real browser makes and inspects tag manager containers, third-party scripts and vulnerable JavaScript libraries. Detectify does not advertise this layer.
Pro and above tag each finding to ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA controls, and every scan gets a plain-English AI executive summary.
Detectify continuously maps domains, subdomains, IPs, ports and technologies, and its Crowdsource network turns newly disclosed vulnerabilities into scanner tests. Its subdomain takeover coverage (600+ methods) is wider than our CNAME checks.
Detectify offers internal scanning and a PCI ASV scanning option. Decloak is external-only and is not a PCI ASV.
Detectify supports SSO and standard integrations on its plans. Decloak SSO and native Jira and Microsoft Teams integrations are proposed on our roadmap, not available yet.
For teams focused on websites and web apps, yes. Decloak covers DAST, API testing, subdomain takeover detection, AI pentesting and compliance mapping on a flat £99/month Enterprise plan. Detectify is stronger for very large external attack surfaces, internal scanning and SSO.
Detectify lists annual platform fees of €0 (Starter), €2,500 (Standard), €5,000 (Professional) and €15,000 (Enterprise), with additional costs for scanned assets, domains and environments. Decloak is free for single-page scans, then £29, £79 or £99 per month.
Yes, on Starter and above. Decloak discovers subdomains through a wordlist and certificate transparency logs and checks each CNAME against commonly hijacked services such as GitHub Pages, Heroku, S3, Azure and Netlify. Detectify advertises a larger set of takeover methods.
Detectify details are taken from the sources above and were last checked on 2 October 2026. Product names belong to their owners and Decloak is not affiliated with Detectify. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: