Compare
Autonomous AI web application pentesting
Intrudify sells autonomous AI penetration tests of web applications, authenticated into your app and reviewed by senior pentesters, with compliance-ready reports in under 24 hours. Pricing is not published. Decloak combines scanning and AI pentesting in published flat plans, with a free scan and client-side supply chain analysis, but its AI pentest reports have no human review.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Intrudify: Autonomous AI web application pentesting, Not stated on its website
“Not advertised” means we could not confirm the capability from Intrudify's public website, not that it is absent.
| Capability | Decloak | Intrudify |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Not advertised |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | Not advertised Pricing not published |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Not advertised Pricing not published; claims up to 90% lower cost than traditional pentests |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Not advertised |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Yes Authenticates into the application |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Not advertised |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Not advertised |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Not advertised |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Not advertised |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Yes Autonomous web app pentest in under 24 hours, reviewed by senior pentesters; tests every deploy (3-6 hour runtime) |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Not advertised |
| Internal network scanning | No External scanning only | Not advertised |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Not advertised |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Partial Reports described as SOC 2 Type II, ISO 27001 and NIS 2 ready |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Partial AI remediation guidance for every finding |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Yes Compliance-ready pentest reports |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Not advertised |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Not advertised |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Not advertised |
Intrudify does not publish pricing on its website. Its homepage compares itself with traditional pentests priced at $10k-$30k and claims up to 90% lower cost. Decloak prices are flat monthly plans in GBP.
Decloak publishes every price and scans a page in about 15 seconds with no account. Intrudify does not list pricing or a free option.
Decloak Enterprise (£99/month) combines DAST, API discovery and sandboxed AI pentesting with continuous scanning on lower tiers.
Decloak inspects third-party scripts, tag manager containers and vulnerable JavaScript libraries. Intrudify does not advertise this layer.
Decloak checks Supabase, Lovable, Base44 and Bubble apps, and Pro includes a REST API and an MCP server.
Intrudify says its autonomous tests are reviewed by senior pentesters, which some auditors and procurement teams prefer. Decloak AI pentests have no human sign-off.
Intrudify describes reasoning about each parameter after authenticating into the app. Decloak's authenticated scanning uses a browser-extension session capture with no scripted login replay.
Intrudify is built around a pentest report mapped to SOC 2 Type II, ISO 27001 and NIS 2 readiness.
If you want continuous scanning and AI pentesting at a published flat price, yes. If you need a pentest report reviewed by senior pentesters, Intrudify offers that and Decloak does not.
Intrudify does not publish pricing. Decloak is free for single-page scans, then £29, £79 or £99 per month, with AI pentesting included on Enterprise.
Yes, on Enterprise: Decloak captures a logged-in session through a browser extension (it works with passkeys). It does not replay scripted logins.
Intrudify details are taken from the sources above and were last checked on 7 October 2026. Product names belong to their owners and Decloak is not affiliated with Intrudify. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: