Will it break my site?
NoIt tests without making destructive changes. It does not delete data, change settings or place orders. Where a test could do real damage it stops and reports what it would have done.
Test your website, code, and APIs for real security vulnerabilities before attackers find them.
Scans are paid. There is no free tier.You see the cost before a scan starts.
See how it works01 The problem
A year of one team’s work. One square of it was ever checked for security problems.
02 What you hand over
A web address on its own is enough to start. You never have to hand over source code.
Paste the address of your site
https://acme-store.comStart scanIt signs in as an ordinary customer, opens one of its own records, then edits the address to point at someone else's and sees what comes back.
What that looks like03 How it works
Built your site with AI? Drop the code in. We read every line, explain what's wrong, and fix it for you.
Bold colors, soft cotton, free shipping.
Buy nowAnyone can run commands on your server just by typing into the address bar.
Anyone can read your whole database through the search box.
04 What you get back
Every finding shows what was tested, what happened, why it matters, and how to fix it.
GET /api/v1/invoices/4471
Signed in as an ordinary customer. This invoice is ours.
GET /api/v1/invoices/4470
Same login. One number changed in the address, nothing else.
HTTP/1.1 200 OK { "customer": "Brightline Ltd", "address": "14 Wharf Road, Leeds", "card": "**** 4417" }
The change that closes it
- const invoice = await db.invoice.findUnique({ - where: { id }, - }) + const invoice = await db.invoice.findFirst({ + where: { id, accountId: session.accountId }, + })
The route looks the invoice up by its number and never checks who is asking. Tie the lookup to the account on the session and the second request returns nothing.
One of seven findings on this shop, each written the same way.1 high2 medium4 low
05 Is it safe
You are inviting software to attack your own systems. Fair questions to ask first.
It tests without making destructive changes. It does not delete data, change settings or place orders. Where a test could do real damage it stops and reports what it would have done.
You confirm you own the target, or are allowed to test it, before a scan starts. Every request it sends is logged.
Your code is used only for the scan and removed after it finishes. If you hand over only a web address, we never had it at all.
The requests it sent and the results it got are in the report, including the tests it stopped itself from running.
None of this is a setting. It works this way on every scan.
06 Pricing
There is no free tier. Every scan uses credits, and you need a plan to run one.
Every plan includes a monthly credit allowance. Credits do not expire while the plan is running.
A quick scan of a small site costs about 75 credits. Reading a whole codebase costs more. You see the figure before the scan starts.
Buy more credits at any point in the month, or move up a plan and pay less per credit.
$10/ month
1,000credits a month
100 credits a dollarOne developer, every pull request read before it merges.
$20/ month
2,200credits a month
110 credits a dollarOne small site, checked before you ship.
$500/ month
60,000credits a month
120 credits a dollarSeveral services, and customers asking for the report.
Talk to us
Credits to suit
Priced on what you runEverything you own, source included.
Every plan is paid. There is no free tier and no trial scan.Seats are free on every plan.Move up or down at any time.Prices in US dollars, excluding tax.
Enter your target to see the scan cost before you start.
Or scan an API instead, or review your code.
It runs on our machines. Nothing goes near your servers.
The credits a scan will spend are shown before it starts.
Solo is one developer, every pull request read before it merges.