About Decloak.dev
Decloak (decloak.dev) is a web security intelligence tool built for developers, indie hackers, small businesses, agencies, and compliance teams. It scans a live URL across 8 attack surfaces — exposed API keys and secrets in JavaScript bundles, missing security headers (CSP, HSTS, etc.), known CVEs in outdated JS libraries, DNS/TLS misconfigurations, hidden trackers, and platform-specific misconfigurations common to AI app builders like Supabase, Lovable, and Base44 (most notably, publicly readable databases from disabled Row Level Security).
The free tier requires no account or card and returns a graded A-F report with an AI-written executive summary in under 15 seconds. Paid tiers add full-site agent investigation, scheduled recurring scans, PDF evidence exports, ISO 27001/SOC2 control mapping for compliance teams, and Enterprise-tier active security testing (DAST).
What Decloak.dev does
Decloak provides automated web security intelligence that generates a scored security report within 15 seconds. It caters to the needs of vibe coders, small businesses, compliance teams, agencies, solo builders, and security teams. The platform detects critical security vulnerabilities and generates audit-ready evidence mapped to various compliance standards.
Users can begin by pasting a URL into the platform without any account setup. Decloak's AI agent scans multiple layers of the website, checking for vulnerabilities, misconfigurations, and security exposures. It then generates a graded report with actionable insights and ensures compliance evidence is readily available for various standards.
Decloak is designed for a diverse user base, including vibe coders and solo builders who need quick security assessments, small businesses looking for affordable security solutions, compliance and security teams needing automated compliance evidence, and agencies needing to manage multiple client domains efficiently.
Based on decloak.dev, read on Sep 16, 2026.
Key features
- Automated web security intelligence