The Decloak Journal
Stories from around the web security world, plus release notes and changes to Decloak itself.

A green padlock tells a visitor almost nothing about whether the connection behind it is actually well configured. Certificate expiry, issuer trust, protocol version, and cipher strength are four separate things that can each quietly go wrong while the padlock stays green.

Ten rows, always present, on every report: Confirmed, Clean, or Not Tested, with an honest reason given for anything we genuinely can't assess from outside. And along the way, we found our own reference table was still citing the outdated 2021 standard.

Compliance mapping now covers six frameworks. PCI DSS v4.0 added two requirements specifically to catch Magecart-style card skimming, and it turns out Decloak was already built to catch exactly that.

Every Decloak PDF was a dark-themed HTML page forced into PDF form, raw markdown leaking through, text cut off at page edges, no table of contents, no page numbers. We rebuilt it from scratch as a real, print-safe document system, because for a lot of customers, this PDF is the actual deliverable.

Three views instead of one wall of data, confidence tiers on every finding, a real fix-it plan instead of just a grade, and full visibility into what actually got checked. The free scan grew up too, same report, same rigor, real evidence from your own site.

Built for the professionals who told us they wanted actual control, Expert Mode unlocks named, reusable Scan Profiles that tune the crawler, Active Testing, and AI Pentesting independently, and shows you exactly what effect each setting actually had.

A missing header that's true of every page on your site used to show up as one finding card per page, ten cards for ten pages, eighty-three for eighty-three. Now it's one card, with every affected location listed underneath.

Every other layer in Decloak observes and flags things that look wrong. AI Pentesting is the one that actually attempts exploitation, inside a sandbox, with a fixed toolkit of five real, named tools, and only calls something confirmed once it's proven, not pattern-matched.

Most of what a modern web app actually does happens through an API, and most API vulnerabilities never show up in a page-level scan. Decloak Enterprise now systematically discovers and lightly tests REST, GraphQL, and SOAP endpoints as part of Active Security Testing.

When the scan target is a raw IP address rather than a domain, Decloak now passively checks around 18 commonly-abused ports, databases, remote access, file transfer, for anything open and reachable, plus a reverse DNS lookup. Connect-only, no probe data sent.

A wordlist can only ever find the subdomains someone thought to guess. Decloak now also queries certificate transparency logs, the public record of every hostname a certificate authority has ever issued an SSL cert for, so subdomains nobody guessed still get found.

A subdomain pointing at a third-party service you stopped using isn't just clutter, it's claimable. Decloak now checks every discovered subdomain's CNAME record for exactly that, live on every Starter+ scan, no extra step required.

A full scan can surface hundreds of findings, useful for coverage, useless for a Monday-morning to-do list. The new Priority Remediation Plan collapses that into a ranked top-25, with the ranking logic shown, not hidden.

A chat widget lives in the bottom-right corner of every page now. For free accounts it's a curated FAQ router. For paid plans it's a scan-aware agent that can pull your actual findings, look up a real CVE, and explain a compliance control, without you leaving the report.

Every finding Decloak detects is now mapped to NIS2 and DORA controls alongside SOC 2 and ISO 27001. Same 36 finding categories, same underlying scan, two more frameworks to help you get ahead of this October's NIS2 deadline.

Pro and above can now brand their Decloak PDF reports end to end: your logo, your accent color, your fonts, your footer. Built for agencies, consultants, and anyone using security scans as part of client work or lead generation.