We built decloak.dev as the web intelligence service for the modern era. Start for free with features for vibe coders all the way through to Enterprise!

London
We've just launched Decloak on @peerpush_com! Click the link below and help us reach more people! We're on a mission ot help everyone get better at improving their web security! Whether you're a vibe coder or a professional pentester! 🚀 peerpush.com/p/decloak
33
23
121
decloak.dev retweeted
Decloak by @decloakdev Exposed API keys. Misconfigured DBs. Vulnerable libraries. Catch them all🔥 AI agent runs full site investigation + penetration testing. Available - decloak.dev/?ref=microlaunch Paste your URL + your scored security report (15 secs)
3
1
5
183
1/ A company that sells identity theft protection got breached by a phone call. A thread on three recent stories.
1
35
26
144
3/ Trezor's vendor breach kept getting worse. First, 67K more customers exposed because the vendor kept data it was required to delete. Then attackers used the breach itself to send fake "security alert" phishing emails to 347K addresses, weaponizing the trust a real breach notification depends on.
1
2
4
1/ A green padlock tells a visitor almost nothing about whether the connection behind it is actually well configured. Four separate things can each quietly go wrong while it stays green.
1
42
30
186
2/ Expiry's the one everyone knows. Chain validation is invisible until it breaks for the wrong client. Protocol version, still accepting TLS 1.0/1.1? And cipher strength, the one almost nobody checks manually, because there's no browser warning for it.
1
33
25
122
3/ A cert can be freshly issued, correctly chained, and still served over a deprecated protocol with a weak cipher. Still shows the padlock. Still fails a real review. We check all four automatically. Full breakdown: decloak.dev/journal/your-ssl…
2
Decloak has just launched on @MicroLaunchHQ! Thanks for your help @SaidAitmbarek We'd appreciate any upvotes to help with our listing😄 We've launched an exclusive promotion for 50% off for two months no ANY paid plan, which you can find on our page! microlaunch.net/p/decloakweb…
2
52
58
256,990
1/ Every report now includes a literal OWASP Top 10:2025 checklist. Ten rows, always present. Confirmed, Clean, or Not Tested.
1
56
39
242
3/ Most scanners either silently skip what they can't test or quietly overclaim coverage. We'd rather say exactly why something's out of scope. That's a trust signal, not a weakness.
1
3
The race for #20 this week on Launch Llama tools is heating up Christian Baltes and @decloakdev Winner gets a feature in our weekly newsletter
1
1
22
1/ Most scanners stop at the login page. Decloak's authenticated scan mode doesn't, and for passkeys specifically, the usual workaround (script the login) doesn't even apply.
1
54
38
227
2/ WebAuthn is built so there's no credential to store or script. The login ceremony requires a physical gesture on the actual device. Nothing to paste into an automation script, by design.
1
43
29
145
Decloak now reports on what findings map to the OWASP Top 10 categories. This brings our security intelligence platform feature count to 66! And we keep going! Onto the next build...
1
48
41
204