For compliance & security teams
Teams using AppCheck, Qualys, or Tenable for monthly SOC2 and ISO 27001 evidence pay thousands per year for reports that still need a pentester to interpret. Decloak maps findings to SOC2, ISO 27001, NIS2, and DORA controls, tracks remediation, and adds Enterprise-tier active security testing (DAST) - at a fraction of the cost.
Security Score
Good - board-ready
client-portal.com
just now
CORS misconfiguration - reflects arbitrary origin
ISO 27001 A.8.20 · SOC2 CC6.6
Content-Security-Policy header missing
ISO 27001 A.8.20 · SOC2 CC6.6
2 findings marked "In Progress" since last scan
Remediation tracking · assigned to dev team
AI Summary
Overall posture is strong with two open items. Both are mapped to ISO 27001 Annex A controls and already assigned for remediation - export the evidence package when ready.
Features for compliance & security teams
Scanning
Web server software disclosed in response headers (Apache, nginx, IIS, PHP, and more) is matched against the National Vulnerability Database, with the exact version and CVE ID shown for anything found.
Scanning
Detects the CMS or e-commerce platform a site runs on - WordPress, Joomla, Drupal, Magento, Shopify, Wix, Squarespace, Webflow, and more - and checks any self-hosted, version-disclosed platform against the National Vulnerability Database.
Active Testing
Enterprise scans go beyond passive observation with safe, non-destructive active probes - forced browsing, reflected-input canaries, CORS and HTTP-method checks, postMessage handler auditing, and more.
Active Testing
Active-testing checks are scored separately from your overall report - a dedicated grade for what was actively probed, alongside your regular security score.
Active Testing
Capture a logged-in session via our browser extension and the agent crawls behind your login - the only mechanism that works for passkey/WebAuthn auth, since there is no credential to script or store.
Active Testing
A standalone, boardroom-ready PDF scoped to Active Testing results only - severity donut, a full "what we tested" checklist, and remediation excerpts.
API Security
Finds REST, GraphQL, and SOAP APIs via OpenAPI/Swagger specs, GraphQL introspection, WSDL definitions, and a common-path scan of both a wordlist and your site's own JavaScript - then runs safe, non-destructive tests on each: does it require auth when it should, is GraphQL introspection left open in production, does it leak data via misconfigured CORS.
AI Pentesting
Sandboxed runs of sqlmap (SQL injection, including login forms), dalfox (XSS), ffuf (hidden parameter discovery), nuclei (exposure & misconfiguration deepening), and jwt_tool (JWT weak-secret cracking) against targets your scan already flagged - a fixed toolkit, not an AI improvising attacks.
AI Pentesting
Every confirmed finding carries the exact request and response that proved it, not just a plausible-looking signal - and results that were blocked or inconclusive (a WAF, a TLS handshake failure) are labelled as such rather than shown as a false clean or false positive.
AI Pentesting
Each run happens in an ephemeral, isolated sandbox with network egress scoped to only the domain being tested. Requires its own explicit consent checkbox on top of Active Testing's - real exploitation attempts, not passive observation.
AI Pentesting
Computed only from confirmed pentest findings and shown alongside - never blended into - your overall security score and your Active Testing Score, so you can see exactly what real exploitation attempts found.
AI Pentesting
A dedicated, auditor-ready PDF scoped to pentest results only - proof-of-exploit evidence included - separate from both your main report and your DAST report.
AI Pentesting
The Pentest Report PDF is bundled into the same audit evidence ZIP export as your main and DAST reports, ready to hand to an auditor without hunting down a third download.
Expert Mode
Switch your team into Expert Mode to get named, reusable Scan Profiles: requests-per-second throttling, crawl depth and page limits, retries/backoff, custom User-Agent/headers/cookies, and URL exclusions - so a scan behind an aggressive WAF slows down instead of getting blocked halfway through.
Expert Mode
Turn individual tools (sqlmap, dalfox, ffuf, nuclei, jwt_tool) on or off per Scan Profile, exclude specific paths from testing, and opt into an Aggressive tier (elevated sqlmap risk/level, dalfox WAF-bypass) behind its own explicit liability confirmation.
Expert Mode
See real request counts, throttle rate, and retries as a scan runs, and every finished report carries a summary of exactly which Scan Profile settings applied - so what ran is never a guess.
DNS & Subdomains
Every discovered subdomain's CNAME record is checked against commonly-hijacked services (GitHub Pages, Heroku, S3, Azure, Netlify, and others) for dangling or unclaimed targets an attacker could register and serve content from.
AI Investigation
A ranked top-25 fix list from your latest scan, deduplicated and written in plain English, exportable as a PDF you can hand straight to a client or developer without them opening the full report.
Reports
Timestamped, formatted PDF with your scan details, findings, and an attestation block. Accepted by auditors for SOC2, ISO 27001, NIS2, and DORA evidence.
Reports
Side-by-side diff between any two scans of the same site. See exactly what findings are new, what has been resolved, and what has changed severity.
Reports
Export a date-range ZIP of all scan history - formatted for auditor handoff. Includes all PDFs, finding logs, and scan attestation metadata.
Compliance
Every finding is automatically tagged to the relevant ISO 27001 Annex A controls. Filter your report to show only findings relevant to a specific control.
Compliance
Findings tagged to SOC2 Trust Services Criteria (Security, Availability, Confidentiality). Makes it straightforward to respond to auditor questions by control.
Compliance
Findings tagged to NIS2 Article 21 risk-management measures - built for the EU directive’s October 2026 compliance deadline, now covering roughly 160,000 in-scope entities.
Compliance
Findings tagged to DORA ICT risk-management and third-party risk articles - for financial-sector and critical-infrastructure entities under the EU’s Digital Operational Resilience Act.
Compliance
Mark each finding as Open, In Progress, Resolved, or Accepted Risk and assign it to a teammate - upgrades the Priority Remediation Plan and All Findings from view-only to fully editable. Auditors need to see that findings are being acted on - this closes that loop.
Compliance
Every scan is stamped with who triggered it, when, from where, and with which configuration. Full chain of custody for compliance evidence.
Compliance
A per-domain log of every scan, deletion, and finding change - who did it and when. Recorded from day one, so it’s already there the moment you upgrade to Pro.
Support
A chat assistant that knows your scan results - ask it to explain a finding, walk through remediation, or find the right guide, right from the report or dashboard you're already on.
Team
A glanceable, colour-coded report card for your whole account and every domain - security score, findings by severity, DNS/TLS posture, active testing, and compliance coverage all in one grid. Free for every account; paid tiers unlock more tiles as you upgrade.
Starter and up
A control mapping is only half the story auditors want - the Priority Remediation Plan turns a scan into a ranked, deduplicated top-25 fix list with AI remediation guidance, exportable as a PDF. On Pro, each item's status and assignee close the loop auditors actually ask for: proof that findings are being acted on, not just catalogued.
Every finding scored by severity, then whether a CVE is involved, then how long it has sat open - so the list is always "fix this first," not just "everything we found."
Each item comes with specific, actionable remediation advice - not a CVE ID and a shrug.
Hand a finished plan straight to a client or developer - no one has to click into individual findings to know what to do next.
Mark items Open, In Progress, or Resolved and assign them to a teammate, right from the plan - a Pro-plan upgrade on top of Starter.
Pricing
Both at a fraction of what AppCheck, Qualys, or Tenable charge for the same evidence.