
Decloak is automated web security intelligence for the modern era. Made for vibe coders, small businesses, compliance teams, agencies, solo builders, security teams, and MSPs. Paste a URL and Decloak scans 8 attack surfaces simultaneously - JavaScript CVEs, hidden trackers, third-party data flows, DNS/TLS posture, subdomains, security headers, and vibe-coded platform misconfigurations across Supabase, Lovable, and Base44 - delivering a scored, graded report in under 15 seconds. Free, no account required. Most tools check one thing. Decloak correlates findings across every layer to surface risks single-purpose scanners miss - from exposed API keys in production JS bundles to publicly readable Supabase databases left unprotected because Row Level Security was never turned on. Beyond the free single-page scan, paid plans deploy an AI security agent that investigates rather than just scans - reading each finding, deciding what to look at next, fetching scripts, checking domains against threat intelligence, and producing per-finding remediation guidance across full-site coverage. For compliance and security teams, Decloak replaces expensive scanners like AppCheck, Qualys, or Tenable for SOC2 and ISO 27001 evidence - with scheduled recurring scans, automatic control mapping, PDF evidence packages, and remediation tracking, at a fraction of the cost. Enterprise plans add Active Security Testing (DAST): safe, non-destructive active probes including forced browsing, CORS misconfiguration checks, and authenticated scans behind a real login, rolling up into an independent Active Testing Score and a boardroom-ready report. Start free at decloak.dev.