Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- Does Decloak provide auditor - ready evidence for compliance frameworks?
- How does the free scan help with SOC 2 and ISO 27001 preparation?
- What extra value do paid tiers add for compliance evidence?
- Which layer detects misconfigurations that matter for SOC 2?
- How does Decloak map findings to SOC 2 and ISO 27001?
- Can I integrate Decloak scans into CI/CD pipelines?
- Do I need to run active penetration tests to satisfy auditors?
- How fast is the whole process from scan to audit evidence?
- Where can I read more about Decloak’s compliance mapping?
- What should I do next?
Key takeaways
- Decloak’s free scan produces a graded report in about 15 seconds and includes eight core security layers.
- Paid plans add Evidence Packages that contain timestamped request/response data, source files and proof of each finding.
- Every finding is automatically mapped to SOC 2, ISO 27001 and six other frameworks, so you can copy - paste the mapping into your audit worksheet.
- No manual pen - testing scripts are required; the scanner runs entirely from the outside and records what it observes.
Does Decloak provide auditor - ready evidence for compliance frameworks?
Yes, Decloak creates audit - ready proof by bundling the raw scan data and a framework mapping into a downloadable Evidence Package. The package contains the exact HTML, network logs and JavaScript files that triggered each finding, along with timestamps and a cryptographic hash that auditors can verify.
How does the free scan help with SOC 2 and ISO 27001 preparation?
The free scan runs eight core layers - HTTP/TLS posture, static HTML analysis, rendered - page network behaviour, JavaScript CVE scanning, tag manager intelligence, third - party domain mapping, vibe - coded platform security and an AI - written executive summary - and returns a graded, shareable report in about 15 seconds. The executive summary already references the relevant control families for SOC 2 and ISO 27001, giving you a quick view of where you stand.
What extra value do paid tiers add for compliance evidence?
Paid tiers generate an Evidence Package that can be exported as a ZIP file. Inside you will find:
- The full list of findings with URLs, request/response logs and the exact code fragments that caused the flag.
- A JSON manifest that maps each finding to the eight built - in compliance frameworks, including SOC 2 and ISO 27001 sub - categories.
- Cryptographic hashes of every artifact so auditors can verify that the data has not been altered after the scan. These artifacts are self - contained, so you can hand the ZIP to an auditor without giving them dashboard access.
Which layer detects misconfigurations that matter for SOC 2?
Layer 7 - vibe - coded platform security - fingerprints the app builder (Supabase, Bubble, Next.js, etc.) and checks for real - world misconfigurations such as a publicly readable Supabase table or an exposed service_role key. These are the exact types of control failures that SOC 2 Security CC6.2 and ISO 27001 A.12.1 flag.
How does Decloak map findings to SOC 2 and ISO 27001?
After the scan finishes, the platform cross - references each finding with the eight compliance frameworks it supports. For SOC 2 it links to the relevant Trust Services Criteria (e.g., Security, Availability). For ISO 27001 it links to Annex A controls. The mapping is visible in the report and is also exported in the Evidence Package, so you can paste the mapping directly into your audit evidence matrix.
Can I integrate Decloak scans into CI/CD pipelines?
Yes. Pro and higher plans expose a REST API endpoint (POST /api/v1/scans) that you can call with an API key from your build system. The API returns the scan ID, and you can poll for completion. When the scan finishes you can programmatically download the Evidence Package and feed it into your compliance automation tooling.
Do I need to run active penetration tests to satisfy auditors?
Not for the initial evidence. Decloak’s core layers are passive and safe; they never exploit a vulnerability without explicit consent. If you need confirmed exploitability, the Enterprise tier offers Active Security Testing and AI Pentesting, which run non - destructive probes and only report findings that are proven exploitable. Those confirmed findings can be added to the same Evidence Package.
How fast is the whole process from scan to audit evidence?
A free scan finishes in about 15 seconds and gives you an executive summary with framework references. A paid scan that generates an Evidence Package typically completes within a few minutes, depending on site size. You can download the ZIP and hand it to auditors the same day, eliminating weeks of manual documentation.
Where can I read more about Decloak’s compliance mapping?
- Compliance Mapping Explained: Turning Security Findings Into Audit Evidence
- Compliance Mapping Now Covers NIST CSF 2.0 and the EU Cyber Resilience Act
What should I do next?
- Run a free scan on your public URL to see the quick grade and executive summary.
- Upgrade to a Starter or Pro plan if you need an Evidence Package.
- Trigger the scan via the REST API as part of your CI/CD pipeline.
- Export the Evidence Package and attach the framework - mapping section to your SOC 2 and ISO 27001 audit worksheets.
Related guides
How to Build Continuous Web - Security Scans with Scheduled Decloak Checks and Ticket Automation
Learn how to schedule Decloak scans via the REST API, compare results across runs, and push new or regressed findings to Jira or Linear automatically.
How can I quickly scan my single-page app for exposed secrets and vulnerable third - party scripts?
Use Decloak’s free 15 - second scan to detect hard - coded keys, outdated libraries, missing SRI and mixed content in a single - page app before a formal audit.
How to Fix a Missing Content - Security - Policy Header
Learn concrete steps to add, test, and harden a Content - Security - Policy header, from server configuration to iterative reporting and verification.