Compare
Vulnerability management & attack surface monitoring
Intruder is a strong choice if you need infrastructure, cloud-account and internal network vulnerability scanning in one place. Decloak is the better fit if your risk lives in your website and web app: it covers the client-side supply chain (JavaScript libraries, tag managers, third-party scripts), maps every finding to eight compliance frameworks, and includes DAST and sandboxed AI pentesting on a £99/month self-serve plan.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Intruder: Vulnerability management & attack surface monitoring, London, UK
“Not advertised” means we could not confirm the capability from Intruder's public website, not that it is absent.
| Capability | Decloak | Intruder |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | No 14-day free trial with an account |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | Yes Online price calculator, priced per target |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Cloud from £227/mo (5 infrastructure targets); about £56/mo per authenticated web app; Pro from £379/mo; Enterprise custom |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Yes ZAP-powered, 75+ application checks, single-page apps supported |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Yes Scans behind login pages |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes API security testing |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Yes Attack surface monitoring with subdomain and shadow IT discovery |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Partial Covered through its infrastructure scanning engines |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Yes "Vulnerable components" in web app scans |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Extra cost AI web app pentests from $3,500 per test |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Yes Tenable Nessus, OpenVAS, Nuclei and Nmap; port monitoring scales by plan |
| Internal network scanning | No External scanning only | Yes Agent-based internal scanning (Pro and up) |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Yes Agentless AWS, Azure and Google Cloud checks |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Partial Reports used for SOC 2, ISO 27001 and Cyber Essentials; per-control mapping not advertised |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Partial GregAI analyst for triage and prioritisation |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Partial Compliance-ready reports |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Yes 15+ including Jira, Slack, Teams, GitHub, GitLab and ServiceNow |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Partial API access |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Partial Okta listed as an integration |
Intruder figures come from its public pricing calculator at monthly billing in GBP; annual billing saves 20%. Web app licences are added on top of the infrastructure plan. Decloak prices are flat monthly plans with no per-target add-ons.
Decloak renders every page in a real browser and records every request, so it sees third-party scripts, tag manager containers and data flows that an infrastructure-focused scanner is not built to inspect. That is where Magecart-style skimming and leaky analytics live.
On Pro and above, each finding is tagged to ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA controls, with remediation tracking and date-range evidence packages for auditors.
Intruder prices AI pentests per engagement from $3,500. Decloak Enterprise (£99/month) includes sandboxed exploitation-confirmation runs with sqlmap, dalfox, commix, nuclei, ffuf and jwt_tool, one run per domain per day.
Paste a URL and get a full scored report in about 15 seconds, with no account and no trial clock. Intruder starts with a 14-day trial.
Intruder runs commercial and open-source engines across every exposed port, plus agents for internal devices. Decloak only probes about 18 common service ports on IP targets and does not scan internal networks.
Intruder connects to AWS, Azure and Google Cloud accounts and scans container images. Decloak Cloud Connect is scoped on our roadmap but not built, and we do not scan container images.
Intruder lists 15+ integrations including native Jira, Microsoft Teams and ServiceNow. Decloak has Slack, signed webhooks, a REST API and an MCP server today; native Jira and Teams integrations are planned.
For web application and website security, yes. Decloak covers DAST, API testing, authenticated scans, AI pentesting and compliance mapping on a £99/month Enterprise plan. If you mainly need infrastructure, internal-network or cloud-account scanning, Intruder covers that and Decloak does not.
Intruder Cloud starts at £227 per month on monthly billing for five infrastructure targets, with authenticated web app scanning at about £56 per app per month on top, and AI pentests from $3,500 per test. Decloak is free for single-page scans, £29/month for Starter, £79/month for Pro and £99/month for Enterprise with DAST and AI pentesting included.
No. Decloak is an external scanner focused on websites, web apps, APIs, DNS/TLS and subdomains. It has no internal agents. Cloud account connectors for AWS, Azure and Google Cloud are scoped on our roadmap but not available yet.
Yes. A common split is Intruder for infrastructure and cloud, and Decloak for the website layer: client-side supply chain, tag managers, JavaScript CVEs, compliance-mapped evidence and AI pentesting of web apps.
Intruder details are taken from the sources above and were last checked on 2 October 2026. Product names belong to their owners and Decloak is not affiliated with Intruder. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: