Compare
Unified security platform & practitioner-led services
Offload Security is a unified cybersecurity platform covering cloud posture, code, a dedicated DAST suite, containers, vulnerability management and compliance across 15 frameworks, alongside practitioner-led pentesting and compliance services. Decloak is narrower: a self-serve web scanner with published pricing, AI pentesting and client-side supply chain analysis.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Offload Security: Unified security platform & practitioner-led services, India
“Not advertised” means we could not confirm the capability from Offload Security's public website, not that it is absent.
| Capability | Decloak | Offload Security |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Not advertised |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | No Get a quote; platform licensing with no per-seat fees |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Not advertised Pricing not published |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Yes Dedicated DAST suite using ZAP, Nuclei and OWASP API Top 10 testing |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Yes Authenticated testing of the live application and its APIs |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes OWASP API Top 10 testing |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Not advertised |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Not advertised |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Not advertised |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Extra cost Practitioner-led external, internal, web, API and cloud pentests; AI pentesting not mentioned |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Yes Vulnerability management and network penetration testing |
| Internal network scanning | No External scanning only | Yes Internal network penetration testing service |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Yes Cloud posture across AWS, GCP and Azure |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Yes 15 frameworks including ISO 27001, SOC 2, PCI DSS 4.0.1, HIPAA, GDPR, DPDP Act and NIST CSF 2.0 |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Partial AI-assisted triage and remediation guidance |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Not advertised |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Yes 24 integrations including Jira, ServiceNow, GitHub, GitLab, Jenkins, Wazuh and Splunk |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Not advertised |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Not advertised |
Offload Security does not publish prices; its site describes platform licensing without per-seat fees and asks visitors to get a quote. Decloak prices are flat monthly plans in GBP.
Decloak shows every price and scans a page in about 15 seconds with no account. Offload Security works by quote.
Decloak Enterprise includes sandboxed sqlmap, dalfox, commix, nuclei, ffuf and jwt_tool runs with proof-of-exploit evidence. Offload's pentesting is practitioner-led.
Decloak inspects third-party scripts, tag manager containers and vulnerable JavaScript libraries. Offload does not advertise this layer.
Decloak checks Supabase, Lovable, Base44 and Bubble apps, and Pro includes a REST API and MCP server.
Offload covers cloud posture, code, containers, Kubernetes, vulnerability management and SIEM integration. Decloak is an external web scanner.
Offload offers practitioner-led pentests, assessments and compliance readiness. Decloak has no human services.
Offload lists 15 frameworks including DPDP Act and ISO 42001, and 24 integrations including Jira and ServiceNow.
If you want a self-serve web scanner with published pricing and AI pentesting, yes. If you want a broad platform with cloud, code and human-led services from one vendor, Offload covers more ground.
Offload Security quotes platform licences and does not publish prices. Decloak is free for single-page scans, then £29, £79 or £99 per month.
No. Decloak AI pentests run automatically in a sandbox with proof-of-exploit evidence and no human sign-off.
Offload Security details are taken from the sources above and were last checked on 7 October 2026. Product names belong to their owners and Decloak is not affiliated with Offload Security. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: