Skip to main content
Free check

Free security check for your site or app

Paste your address and see what anyone can already read: API keys left in the code, missing protections, software that stopped getting security fixes. About ten seconds, and no signup to see the results.

What we found on

Want this as a report you can forward?

A PDF with every finding and what to do about it — the thing to hand to whoever pays for the fix. We read the same report before we reply, so if something here needs a person, you will hear from an engineer rather than a sales sequence.

Your report is ready.

Download the PDF

An engineer reads the same findings. If anything in there is urgent, you will hear from us today.

What this check does, and what it refuses to do

It reads

  • · The page you give us, and the scripts it loads from its own domain
  • · Response headers: encryption, framing, content rules, cookie flags
  • · Published keys: Stripe, AWS, OpenAI, Anthropic, GitHub, Supabase service-role
  • · Debug output, source maps, end-of-life PHP, an old WordPress

It never

  • · Guesses at admin paths or hidden files
  • · Tries a login, a payload, or anything resembling an attack
  • · Touches your database or your users' data
  • · Stores the findings longer than an hour, unless you ask for the report

That line is deliberate. Everything above is already being served to anyone who opens your page; going further would be unauthorised access, whoever asked for it. The deeper checks — whether row-level security actually holds, whether a webhook can be replayed — happen in the system review, with your permission and your credentials.

Questions people ask before they run it

Yes. It requests your page and the scripts that page loads, exactly as a browser does, and reads what comes back. It does not guess at hidden files, try to log in, or send anything that could change your data. Everything it reports was already being served to every visitor.
The anon key is designed to be public, so seeing it in your bundle is normal. It is only safe if row-level security is switched on for every table that holds user data — without that, the anon key reads the lot. The service_role key is a different story: it ignores row-level security entirely and must never leave your server. This check tells you which one you have published.
Yes, in seconds. Anything shipped to the browser can be read by anyone who opens developer tools, and bots scan published bundles for keys automatically. A Stripe secret key, an AWS key or an OpenAI key in a bundle is spent or abused within hours, not weeks.
The findings appear on screen before we ask for anything. The email buys the same findings as a PDF you can forward to whoever pays for the fix, and it tells us something is worth a reply. An engineer reads it, not a sales sequence.
The result is held for an hour so the report can be generated, then it is gone. If you ask for the PDF we keep your name, email and the address you checked, because that is the enquiry. What we store and for how long is on our data protection page.
A bot wall answers us with a challenge page instead of your site, so there is nothing honest to report. That protection is doing its job. Send us the address and we will look at it with you instead.

Have something to build — or something that is stuck?

Tell us what you are working on. You will talk to an engineer, not a salesperson.

Before you go — have a system that's stuck, or needs AI?

We build what's missing, put AI where it earns its place, and keep it running.