60 modern security features

Everything
Decloak does.

16 features available on the free tier. 18 more unlock on Starter, 15 more on Pro, plus 11 Enterprise-only active testing, AI Pentesting, and authenticated scanning features. Filter below to see exactly what you get at each level.

Free16 features included
Starter18 additional features unlocked
Pro15 more for teams & compliance evidence
Enterprise11 more with active testing, AI Pentesting & authenticated scans

All features

Free

Scanning

Single-page instant scan

Paste any URL and get a complete security snapshot across all 8 layers in under 15 seconds. No account, no setup.

Free

Scanning

8-layer security analysis

HTTP/TLS, HTML, network traffic, JavaScript CVEs, tag managers, third-party supply chain, platform misconfigurations, server/CMS software CVE checks, and AI synthesis all run on every scan.

Free

Platform Security

Vibe-coded platform security

Detects the most common security failures in apps built with Lovable, Supabase, Base44, Bubble, and similar AI app builders - publicly readable databases, exposed service_role keys, and known platform CVEs.

Free

Scanning

JavaScript CVE detection

Retire.js + OSV database checks against every JS library identified on the page. Pinpoints the exact file and version with the CVE ID linked.

Free

Scanning

Server software CVE detection

Web server software disclosed in response headers (Apache, nginx, IIS, PHP, and more) is matched against the National Vulnerability Database, with the exact version and CVE ID shown for anything found.

Free

Scanning

CMS & platform fingerprinting

Detects the CMS or e-commerce platform a site runs on - WordPress, Joomla, Drupal, Magento, Shopify, Wix, Squarespace, Webflow, and more - and checks any self-hosted, version-disclosed platform against the National Vulnerability Database.

Free

Scanning

Third-party domain mapping

Every external domain your page contacts - categorised by purpose, checked for registration age, and flagged if they match threat intelligence signals.

Free

Scanning

HTTP security headers

Full checklist of CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy, cookie flags, CORS, and server version disclosure.

Free

Scanning

Tag manager intelligence

Identifies every GTM container, lists all active tags and their firing triggers, and flags tags sending data to unrecognised or newly-registered domains.

Free

Scanning

Security score and grade

Every scan produces a weighted 0-100 score and A-F grade calculated from finding severity across all 8 layers. Comparable across scans over time.

Free

Scanning

Network traffic capture

Headless browser records every request made on page load - third-party scripts, WebSocket connections, dynamically injected tags, and storage writes.

Enterprise

Active Testing

Active Security Testing (DAST)

Enterprise scans go beyond passive observation with safe, non-destructive active probes - forced browsing, reflected-input canaries, CORS and HTTP-method checks, postMessage handler auditing, and more.

Enterprise

Active Testing

Independent Active Testing Score

Active-testing checks are scored separately from your overall report - a dedicated grade for what was actively probed, alongside your regular security score.

Enterprise

Active Testing

Authenticated scan mode

Capture a logged-in session via our browser extension and the agent crawls behind your login - the only mechanism that works for passkey/WebAuthn auth, since there is no credential to script or store.

Enterprise

Active Testing

Executive DAST report (PDF)

A standalone, boardroom-ready PDF scoped to Active Testing results only - severity donut, a full "what we tested" checklist, and remediation excerpts.

Enterprise

API Security

API endpoint discovery & testing

Finds REST, GraphQL, and SOAP APIs via OpenAPI/Swagger specs, GraphQL introspection, WSDL definitions, and a common-path scan of both a wordlist and your site's own JavaScript - then runs safe, non-destructive tests on each: does it require auth when it should, is GraphQL introspection left open in production, does it leak data via misconfigured CORS.

Enterprise

AI Pentesting

Real exploitation-confirmation testing

Sandboxed runs of sqlmap (SQL injection, including login forms), dalfox (XSS), ffuf (hidden parameter discovery), nuclei (exposure & misconfiguration deepening), and jwt_tool (JWT weak-secret cracking) against targets your scan already flagged - a fixed toolkit, not an AI improvising attacks.

Enterprise

AI Pentesting

Proof-of-exploit evidence

Every confirmed finding carries the exact request and response that proved it, not just a plausible-looking signal - and results that were blocked or inconclusive (a WAF, a TLS handshake failure) are labelled as such rather than shown as a false clean or false positive.

Enterprise

AI Pentesting

Sandboxed, consent-gated testing

Each run happens in an ephemeral, isolated sandbox with network egress scoped to only the domain being tested. Requires its own explicit consent checkbox on top of Active Testing's - real exploitation attempts, not passive observation.

Enterprise

AI Pentesting

Independent Pentest Score

Computed only from confirmed pentest findings and shown alongside - never blended into - your overall security score and your Active Testing Score, so you can see exactly what real exploitation attempts found.

Enterprise

AI Pentesting

Standalone Pentest Report PDF

A dedicated, auditor-ready PDF scoped to pentest results only - proof-of-exploit evidence included - separate from both your main report and your DAST report.

Enterprise

AI Pentesting

Evidence package bundling

The Pentest Report PDF is bundled into the same audit evidence ZIP export as your main and DAST reports, ready to hand to an auditor without hunting down a third download.

Starter

DNS & Subdomains

DNS record analysis

SPF, DMARC, DNSSEC, CAA, mail and nameserver records - every check shown, even when clean, so you can see exactly what was verified.

Starter

DNS & Subdomains

SSL/TLS certificate analysis

Certificate issuer, expiry, protocol version, cipher suite, and key strength - flagging weak or expiring certificates before they become an outage or a warning page.

Starter

DNS & Subdomains

Subdomain discovery

Finds forgotten staging, dev, and admin subdomains via common-name enumeration plus a certificate transparency log lookup (real hostnames a public CA has issued a certificate for), with a quick reachability check on each - and a one-click button to run a full scan on any of them.

Starter

DNS & Subdomains

Subdomain takeover detection

Every discovered subdomain's CNAME record is checked against commonly-hijacked services (GitHub Pages, Heroku, S3, Azure, Netlify, and others) for dangling or unclaimed targets an attacker could register and serve content from.

Free

Scanning

IP address & bare domain scanning

Scan a bare domain or IP directly - no scheme required. Automatically tries HTTPS, HTTP, and common alternate ports, and always reports what it found.

Starter

Scanning

Open port & service discovery for IP scans

When you scan a bare IP directly, a passive connect-only probe checks common non-web service ports (databases, remote access, file transfer) for exposure, captures any banner offered, and runs a reverse DNS (PTR) lookup - never sends payloads or attempts exploitation.

Starter

AI Investigation

Full-site AI agent

An AI agent crawls your entire site - or a defined scope - running all 8 layers on every page it decides is worth investigating.

Starter

AI Investigation

Live reasoning trace

Watch the agent explain every decision in real time as it investigates. Each step is logged with the finding that triggered it - useful as an audit trail.

Starter

AI Investigation

Source map analysis

When an exposed .map file is found, the agent fetches it and reconstructs original source to check for hardcoded secrets and internal architecture leaks.

Starter

AI Investigation

GTM container deep-dive

Goes beyond identifying the container ID - fetches and parses the full tag configuration, including nested tags, custom HTML tags, and variable definitions.

Starter

AI Investigation

Domain threat intelligence

Every third-party domain your site contacts is checked against a live malware/phishing database and flagged for suspicious registration patterns (unusual TLDs, numeric-heavy names).

Starter

AI Investigation

Per-finding remediation

AI-written remediation steps specific to each finding - not generic advice. Tells your developer exactly what to change and why.

Starter

AI Investigation

Priority Remediation Plan

A ranked top-25 fix list from your latest scan, deduplicated and written in plain English, exportable as a PDF you can hand straight to a client or developer without them opening the full report.

Free

Reports

AI executive summary

Plain-English summary of your security posture written by an LLM that has read all findings holistically. Readable by a CTO, auditor, or board member.

Free

Reports

Shareable public link

Every free report gets a public URL you can send to a developer, client, or auditor. Sign up to save reports to your account permanently.

Starter

Reports

PDF evidence export

Timestamped, formatted PDF with your scan details, findings, and an attestation block. Accepted by auditors for SOC2, ISO 27001, NIS2, and DORA evidence.

Starter

Reports

Full scan history

Every scan you run is preserved indefinitely. Filter by domain, date, or severity to find any past report instantly.

Starter

Reports

Comparison reports

Side-by-side diff between any two scans of the same site. See exactly what findings are new, what has been resolved, and what has changed severity.

Pro

Reports

Evidence packages

Export a date-range ZIP of all scan history - formatted for auditor handoff. Includes all PDFs, finding logs, and scan attestation metadata.

Pro

Reports

White-label PDF branding

Put your own logo, name, accent colour, and font on every PDF report, DAST report, and evidence package you export - no Decloak branding, ready to hand straight to your clients.

Pro

Compliance

ISO 27001 control mapping

Every finding is automatically tagged to the relevant ISO 27001 Annex A controls. Filter your report to show only findings relevant to a specific control.

Pro

Compliance

SOC2 criteria mapping

Findings tagged to SOC2 Trust Services Criteria (Security, Availability, Confidentiality). Makes it straightforward to respond to auditor questions by control.

Pro

Compliance

NIS2 control mapping

Findings tagged to NIS2 Article 21 risk-management measures - built for the EU directive’s October 2026 compliance deadline, now covering roughly 160,000 in-scope entities.

Pro

Compliance

DORA control mapping

Findings tagged to DORA ICT risk-management and third-party risk articles - for financial-sector and critical-infrastructure entities under the EU’s Digital Operational Resilience Act.

Pro

Compliance

Remediation tracking

Mark each finding as Open, In Progress, Resolved, or Accepted Risk and assign it to a teammate - upgrades the Priority Remediation Plan and All Findings from view-only to fully editable. Auditors need to see that findings are being acted on - this closes that loop.

Pro

Compliance

Audit trail

Every scan is stamped with who triggered it, when, from where, and with which configuration. Full chain of custody for compliance evidence.

Pro

Compliance

Audit activity log

A per-domain log of every scan, deletion, and finding change - who did it and when. Recorded from day one, so it’s already there the moment you upgrade to Pro.

Starter

Automation

Scheduled recurring scans

Set a weekly, monthly, or quarterly cadence and scans run automatically. Never miss a security check-in for SOC2, ISO 27001, NIS2, or DORA again.

Starter

Automation

Email alerts

Get notified when a scheduled scan completes or when a new critical or high severity finding is detected - before your next scheduled check.

Pro

Automation

Slack notifications

New critical findings delivered to a Slack channel of your choice within minutes. Useful for security channels and on-call workflows.

Pro

Automation

Webhook integration

Push findings to any system - Jira, Linear, PagerDuty, or your own. Signed payloads (HMAC), per-endpoint event selection, and a delivery log.

Pro

Automation

API access

Trigger scans programmatically and pull results via a REST API - poll status, fetch findings, list scans for a domain. Full OpenAPI docs included.

Pro

Automation

MCP server for AI agents

Let Claude, Cursor, or any MCP-compatible AI agent trigger scans and poll results directly - create_scan, get_scan, list_scans, and wait_for_scan tools, no glue code required.

Starter

Support

AI assistant

A chat assistant that knows your scan results - ask it to explain a finding, walk through remediation, or find the right guide, right from the report or dashboard you're already on.

Free

Team

Visual scoreboard dashboard

A glanceable, colour-coded report card for your whole account and every domain - security score, findings by severity, DNS/TLS posture, active testing, and compliance coverage all in one grid. Free for every account; paid tiers unlock more tiles as you upgrade.

Free

Team

Multi-domain dashboard

Your account shows all scans organised by domain - current grade, last scanned, open findings. Free for all accounts. Pro adds team sharing and bulk actions.

Pro

Team

Multi-user access

Invite team members with role-based permissions. Developers see findings and remediation; managers see scores and reports; admins manage everything.

Pro

Team

Assign findings to developers

Tag any finding to a specific team member, with bulk-assign by category or by scan. A dedicated "My Assigned Findings" page tracks status and remediation notes.

60 of 60 features shown

FreeStart immediately

No account needed. Paste a URL on the homepage and get your report in 15 seconds.

Scan free now
StarterFull investigation from £29/mo

AI agent investigation, DNS/SSL analysis, scheduled scans, PDF evidence export, and everything above.

ProTeam & compliance from £79/mo

Everything in Starter, plus ISO 27001/SOC2/NIS2/DORA mapping, team access, audit evidence packages, and API access.

EnterpriseActive testing & AI Pentesting - £99/mo

Active Security Testing (DAST), AI Pentesting exploitation-confirmation testing, and authenticated scan mode via session capture, on top of everything in Pro.