Compare
Multi-surface automated security assessment
Nanotesting is a low-priced automated assessment platform covering web apps, APIs, GitHub repositories, mobile binaries, cloud accounts and smart contracts, with compliance evidence mapped to eight frameworks. Decloak is narrower and deeper on the website: it renders pages in a real browser, analyses third-party scripts and tag managers, checks AI app-builder platforms, and adds a plain-English AI summary and sandboxed AI pentesting in Enterprise.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Nanotesting: Multi-surface automated security assessment, Not stated on its website
“Not advertised” means we could not confirm the capability from Nanotesting's public website, not that it is absent.
| Capability | Decloak | Nanotesting |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Partial Free plan (account needed): 1 verified target, 1 scan per month |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | Yes Free, Starter, Growth and Agency plans are listed |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Free; Starter $31/mo; Growth $63/mo; Agency $159/mo (annual billing); Enterprise custom |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Partial Read-only by default; active attack payloads via a $299/mo invasive testing add-on |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Not advertised |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes OWASP API Top 10 (BOLA/BFLA), GraphQL and WebSocket authentication |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Not advertised |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Partial Security headers, cookies and CORS checks; DNS not listed |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Partial Dependency scanning for connected GitHub repositories |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Extra cost Invasive testing add-on; AI pentesting not mentioned |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Not advertised |
| Internal network scanning | No External scanning only | Not advertised |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Yes AWS, Azure and GCP auditing |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Yes ISO 27001, SOC 2, PCI DSS 4.0, NIST CSF, CIS, HIPAA, DORA and OWASP Top 10 |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Not advertised |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Yes PDF evidence packs and immutable scan snapshots for audit windows |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Not advertised |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Not advertised |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Partial Enterprise plan |
Nanotesting figures come from its public pricing page, in US dollars with a 20% saving on annual billing, per verified target. Decloak prices are flat monthly plans in GBP.
Decloak renders pages in a real browser and inspects third-party scripts, tag manager containers, vulnerable JavaScript libraries and every external domain contacted. Nanotesting does not advertise this layer.
Decloak checks Supabase, Lovable, Base44, Bubble and Next.js apps for readable databases, exposed service keys and known platform CVEs, on the free tier too.
Every Decloak scan has an AI-written executive summary, and Enterprise runs sandboxed sqlmap, dalfox, commix, nuclei, ffuf and jwt_tool with proof-of-exploit evidence. Nanotesting mentions neither.
Decloak Pro and above include a REST API with OpenAPI docs, an MCP server, Slack and signed webhooks. Nanotesting lists none of these.
Growth covers 15 targets for $63/month and Agency 50 targets for $159/month, which is lower than Decloak for many-site portfolios.
Nanotesting also scans GitHub repositories, mobile apps, cloud accounts and smart contracts. Decloak does not read source code, mobile binaries or cloud accounts.
Nanotesting offers a free plan and a 14-day trial on paid plans. Decloak's free tier is a single-page scan, with no free trial of paid plans.
Nanotesting lists signed scan attestations, a public risk badge, and CIS and HIPAA control mapping. Decloak maps ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA.
If your focus is the website and its third-party scripts, and you want AI pentesting and an AI-written summary, yes. If you need the lowest price across many targets or want repository, mobile and cloud scanning, Nanotesting covers more surfaces.
Nanotesting has a free plan, Starter at $31 per month (3 targets), Growth at $63 (15 targets) and Agency at $159 (50 targets), billed annually. Decloak is free for single-page scans, then £29, £79 or £99 per month.
Nanotesting describes chaining established open-source scanners and does not mention AI features. Decloak adds an AI executive summary on every scan and sandboxed AI pentesting in Enterprise.
Nanotesting details are taken from the sources above and were last checked on 7 October 2026. Product names belong to their owners and Decloak is not affiliated with Nanotesting. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: