DATA ARMOUR

Know what's vulnerablebefore it's exploited.

Test your website, code, and APIs for real security vulnerabilities before attackers find them.

https://

Scans are paid. There is no free tier.You see the cost before a scan starts.

See how it works

01 The problem

Code ships faster than it gets tested.

A year of one team’s work. One square of it was ever checked for security problems.

1,204 pushes this year1 security test
Quiet dayBusy dayThe one security test
Testing gets delayedA security test has to be booked and paid for, so it waits.
Code ships every dayEverything released after a test is untested again.
Problems go unnoticedA vulnerability can sit in production until someone looks for it.

02 What you hand over

Three ways in. You pick one.

A web address on its own is enough to start. You never have to hand over source code.

Paste the address of your site

https://acme-store.comStart scan
What you are handing overOnly what the public can already see
What that catches

It changes a number in the address

It signs in as an ordinary customer, opens one of its own records, then edits the address to point at someone else's and sees what comes back.

What that looks like
GET /invoices/4471 200 yours GET /invoices/4470 200 theirs
What we can seeOnly what the public can
Setting it up takesAbout ten seconds
What you get backThe exact requests it sent

03 How it works

From broken to protected in one click.

Built your site with AI? Drop the code in. We read every line, explain what's wrong, and fix it for you.

04 What you get back

One issue. One fix.

Every finding shows what was tested, what happened, why it matters, and how to fix it.

HighGET /api/v1/invoices/{id}

Any signed in customer can read another customer’s invoices.

  1. GET /api/v1/invoices/4471

    Signed in as an ordinary customer. This invoice is ours.

  2. GET /api/v1/invoices/4470

    Same login. One number changed in the address, nothing else.

    HTTP/1.1 200 OK
    
    { "customer": "Brightline Ltd",
      "address":  "14 Wharf Road, Leeds",
      "card":     "**** 4417" }

The change that closes it

- const invoice = await db.invoice.findUnique({
-   where: { id },
- })
+ const invoice = await db.invoice.findFirst({
+   where: { id, accountId: session.accountId },
+ })

The route looks the invoice up by its number and never checks who is asking. Tie the lookup to the account on the session and the second request returns nothing.

HighSomeone could reach your customers’ data today, with no special skill.MediumThey could, with effort, or alongside one more mistake.LowWorth fixing, but not a way in on its own.

One of seven findings on this shop, each written the same way.1 high2 medium4 low

05 Is it safe

The questions everyone asks first.

You are inviting software to attack your own systems. Fair questions to ask first.

01

Will it break my site?

No

It tests without making destructive changes. It does not delete data, change settings or place orders. Where a test could do real damage it stops and reports what it would have done.

02

Can I test something I do not own?

No

You confirm you own the target, or are allowed to test it, before a scan starts. Every request it sends is logged.

03

What happens to my code?

Removed

Your code is used only for the scan and removed after it finishes. If you hand over only a web address, we never had it at all.

04

Can I see what it tested?

Yes

The requests it sent and the results it got are in the report, including the tests it stopped itself from running.

None of this is a setting. It works this way on every scan.

06 Pricing

You pay for what it runs.

There is no free tier. Every scan uses credits, and you need a plan to run one.

01

A plan gives you credits

Every plan includes a monthly credit allowance. Credits do not expire while the plan is running.

02

Every scan spends credits

A quick scan of a small site costs about 75 credits. Reading a whole codebase costs more. You see the figure before the scan starts.

03

Top up when you run out

Buy more credits at any point in the month, or move up a plan and pay less per credit.

Solo

$10/ month

1,000credits a month

100 credits a dollar

One developer, every pull request read before it merges.

  • Up to 2 targets
  • A web address
  • Pull requests reviewed
  • The full report, with every fix
Start on Solo
Starter

$20/ month

2,200credits a month

110 credits a dollar

One small site, checked before you ship.

  • Up to 5 targets
  • A web address only
  • The full report, with every fix
Start on Starter
Business

$500/ month

60,000credits a month

120 credits a dollar

Several services, and customers asking for the report.

  • Up to 80 targets
  • A web address only
  • The full report, with every fix
  • Hand over an API
Start on Business
Enterprise

Talk to us

Credits to suit

Priced on what you run

Everything you own, source included.

  • As many targets as you need
  • A web address only
  • The full report, with every fix
  • Hand over an API
Book a call

Every plan is paid. There is no free tier and no trial scan.Seats are free on every plan.Move up or down at any time.Prices in US dollars, excluding tax.

Find out what an attacker would find.

Enter your target to see the scan cost before you start.

https://

Or scan an API instead, or review your code.

Nothing to install

It runs on our machines. Nothing goes near your servers.

You see the cost first

The credits a scan will spend are shown before it starts.

$10 to start

Solo is one developer, every pull request read before it merges.