All comparisons

Compare

Decloak vs Detectify

decloak.dev
Pricing
Free; £29, £79 or £99 per month, flat
Free scan
Yes - 15 seconds, no account
Pentesting
Included in Enterprise (£99/mo)
Best for
Websites, web apps and compliance evidence
Detectify logo

External attack surface management & DAST

Pricing
€0 to €15,000 a year platform fee, plus per-asset costs
Free scan
Starter plan with no platform fee
Pentesting
Crowdsourced payload testing
Best for
Large external attack surfaces

Detectify is built for mapping and continuously testing large external attack surfaces, with payloads sourced from a network of 400+ ethical hackers and 600+ subdomain takeover methods. Decloak is the better fit when you want one predictable plan covering web app DAST, sandboxed AI pentesting, client-side supply chain analysis and compliance control mapping, starting with a free scan that needs no account.

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.

By Stephen Gray, CEO & Co-founder · Published · Last verified

Detectify: External attack surface management & DAST, Sweden

Key takeaways

  • Detectify charges an annual platform fee (€0 to €15,000) plus per-asset costs. Decloak is a flat £29 to £99 per month.
  • Detectify is stronger on attack surface breadth: crowdsourced payloads, 600+ takeover methods, internal scanning, cloud connectors and a PCI ASV option.
  • Decloak adds sandboxed exploitation-confirmation (sqlmap, dalfox, commix and more) with proof-of-exploit evidence on Enterprise.
  • Decloak inspects what loads in the browser (tag managers, third-party scripts, JavaScript CVEs) and maps findings to eight compliance frameworks.

Decloak vs Detectify feature comparison

“Not advertised” means we could not confirm the capability from Detectify's public website, not that it is absent.

Feature-by-feature comparison of Decloak and Detectify, last verified 2 October 2026
CapabilityDecloakDetectify
Detectify logo
Getting started & pricing
Free scan with no account
Yes

Single-page scan in about 15 seconds, no login, shareable report

Partial

Starter plan has no platform fee; scanned assets are billed

Published, self-serve pricing
Yes

Monthly plans, cancel any time

Partial

Platform fees published; per-asset prices are not

What it costs

Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo

Platform fee €0, €2,500, €5,000 or €15,000 per year, plus costs per asset, domain and environment

Web application & external surface
Web application DAST
YesEnterprise+

Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes

Yes

Application Scanning with deep crawling and dynamic fuzzing

Authenticated (logged-in) scanning
PartialEnterprise+

Logged-in session capture via browser extension (works with passkeys); no scripted login replay

Yes

Recorded login flows

API discovery & testing
YesEnterprise+

REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery

Partial

REST and GraphQL

Subdomain discovery & takeover detection
YesStarter+

Wordlist and certificate transparency discovery, dangling-CNAME takeover checks

Yes

Surface Monitoring with 600+ subdomain takeover methods

DNS, email-auth & TLS checks
YesStarter+

SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength

Not advertised
Client-side & supply chain
Vulnerable JavaScript library detection
Yes

Retire.js database, exact file and version, CVE linked

Not advertised
Third-party script & domain mapping
Yes

Every external domain a real browser contacts, with registration age and threat intel

Not advertised
Tag manager (GTM) inspection
Yes

GTM containers, tags, triggers and where they send data

Not advertised
AI app-builder checks (Supabase, Lovable, Base44, Bubble)
Yes

Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs

Not advertised
Pentesting
Exploitation-confirmation (AI pentesting)
YesEnterprise+

Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day

Partial

Payload-based tests informed by 400+ crowdsourced ethical hackers; no sandboxed pentest toolkit advertised

Infrastructure & cloud
Network / infrastructure vulnerability scanning
Partial

For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner

Partial

IPs, ports and protocols within Surface Monitoring

Internal network scanning
No

External scanning only

Yes

Internal Scanning (Professional plan includes one environment)

Cloud account connectors (AWS / Azure / GCP)
Planned

Decloak Cloud Connect is scoped on our roadmap

Not advertised
Compliance & reporting
Per-finding compliance control mapping
YesPro+

ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA

Partial

PCI ASV scanning as a €500/yr add-on; per-control mapping not advertised

Plain-English AI executive summary
Yes

On every scan, plus a ranked Priority Remediation Plan on Starter and up

Not advertised
Audit evidence export
YesStarter+

PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up

Not advertised
White-label reports
YesPro+

Your logo, colours and fonts on every PDF

Yes

White-labeled reports on Professional and up

Workflow & integrations
Ticketing & chat integrations
PartialPro+

Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned

Yes

Standard integrations on every plan

API & MCP server for AI agents
YesPro+

REST API with OpenAPI docs plus an MCP server

Yes

API plus an MCP server

SSO (SAML / OIDC)
Planned

SAML / OIDC for Enterprise teams is proposed on our roadmap

Yes

Okta, Ping Identity, OneLogin, SAML 2.0 (Standard and up)

Detectify figures come from its public pricing page: annual platform fees by plan, with additional costs for assets, domains, environments and IP ranges that are not listed publicly. Decloak prices are flat monthly plans with no per-target add-ons.

Where Decloak is stronger

Flat pricing, no per-asset maths

Decloak plans are £29, £79 and £99 a month. Detectify adds per-asset, per-domain and per-environment costs on top of a platform fee that reaches €15,000 a year.

Sandboxed exploitation confirmation

Decloak Enterprise runs real tools (sqlmap, dalfox, commix, nuclei, ffuf, jwt_tool) in an isolated sandbox against targets your scan already found, and attaches the exact request and response that proved each finding.

Client-side supply chain visibility

Decloak records every request a real browser makes and inspects tag manager containers, third-party scripts and vulnerable JavaScript libraries. Detectify does not advertise this layer.

Compliance mapping and AI summaries

Pro and above tag each finding to ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA controls, and every scan gets a plain-English AI executive summary.

Where Detectify is stronger

Attack surface breadth and research depth

Detectify continuously maps domains, subdomains, IPs, ports and technologies, and its Crowdsource network turns newly disclosed vulnerabilities into scanner tests. Its subdomain takeover coverage (600+ methods) is wider than our CNAME checks.

Internal scanning and PCI ASV

Detectify offers internal scanning and a PCI ASV scanning option. Decloak is external-only and is not a PCI ASV.

Enterprise identity and workflow

Detectify supports SSO and standard integrations on its plans. Decloak SSO and native Jira and Microsoft Teams integrations are proposed on our roadmap, not available yet.

Which should you choose?

Detectify logo

Choose Detectify if…

  • You manage a large, fast-changing external footprint and want continuous discovery across it.
  • You need internal scanning or a PCI ASV scan.
  • Your organisation requires SSO before a tool can be piloted.
The right fit
decloak.dev

Choose Decloak if…

  • You want a predictable monthly price rather than a platform fee plus per-asset costs.
  • You want exploitation-confirmed findings with proof-of-exploit evidence, not only payload-based detection.
  • You need third-party script, tag manager and JavaScript library visibility on the pages customers load.
  • You need findings mapped to ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF or EU CRA controls for auditors.

Decloak vs Detectify: frequently asked questions

Is Decloak a good Detectify alternative?

For teams focused on websites and web apps, yes. Decloak covers DAST, API testing, subdomain takeover detection, AI pentesting and compliance mapping on a flat £99/month Enterprise plan. Detectify is stronger for very large external attack surfaces, internal scanning and SSO.

How much does Detectify cost?

Detectify lists annual platform fees of €0 (Starter), €2,500 (Standard), €5,000 (Professional) and €15,000 (Enterprise), with additional costs for scanned assets, domains and environments. Decloak is free for single-page scans, then £29, £79 or £99 per month.

Does Decloak detect subdomain takeovers like Detectify?

Yes, on Starter and above. Decloak discovers subdomains through a wordlist and certificate transparency logs and checks each CNAME against commonly hijacked services such as GitHub Pages, Heroku, S3, Azure and Netlify. Detectify advertises a larger set of takeover methods.

Sources

Detectify details are taken from the sources above and were last checked on 2 October 2026. Product names belong to their owners and Decloak is not affiliated with Detectify. If anything here is out of date, email support@decloak.dev and we will correct it.

More comparisons

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary