We built decloak.dev as the web intelligence service for the modern era. Start for free with features for vibe coders all the way through to Enterprise!
1/ A green padlock tells a visitor almost nothing about whether the connection behind it is actually well configured. Four separate things can each quietly go wrong while it stays green.
1/ Most scanners stop at the login page. Decloak's authenticated scan mode doesn't, and for passkeys specifically, the usual workaround (script the login) doesn't even apply.
Decloak now reports on what findings map to the OWASP Top 10 categories. This brings our security intelligence platform feature count to 66! And we keep going!
Onto the next build...
1/ PCI DSS v4.0 added a requirement that every script on a payment page has to be inventoried and justified. Another requires detecting unauthorized changes to those scripts. Both exist because of Magecart-style card skimming.
1/ Your PDF report used to be a webpage forced into PDF form. Raw markdown leaking through. Text cut off at page edges. No table of contents, no page numbers. For a report customers hand to auditors, that wasn't good enough.
1/ MCP has quietly become the standard way AI agents connect to real tools. 97M+ monthly SDK downloads, adopted by every major AI lab. Decloak now ships an MCP server.
We've completely redesigned our PDF cybersecurity reports to be more professional and ready to send to a colleague or auditor. Previous PDF reports were more like PDF versions of the web report.
The new ones are in a whole different ballgame! This applies to our free reports, agentic reports, and our active testing (DAST) and AI pentesting.
1/ We rebuilt the scan report from the ground up. Not a redesign pass, a rethink of how a report should actually work. And it's not just paid customers who benefit.
1/ "One fixed behavior for every scan" works for most people. It's exactly wrong for the professionals who know precisely what they want tuned. Expert Mode is for them.
1/ A security professional evaluating us said their 76-page scan came back as "1,706 findings, 103 groups" and asked why the header issue true of the whole site wasn't just one line.
That wasn't a feature request. It was a correctness bar.
We've just launched "Expert Mode" on Decloak, so cybersecurity and pentesting professionals have full control over how our agentic security scans work!
1/ Everything else we do is signal detection. It observes and flags things that look wrong. AI Pentesting is different: it actually attempts exploitation, in a sandbox, and only calls something confirmed once a real tool has proven it.
1/ An auditor doesn't want a login to your dashboard. They want something they can file, reference, and hand to their own reviewers without your tool needing to still exist in six months.
1/ A misconfiguration-detection tool got weaponized into the exact attack it was built to prevent. One of three real stories from the last couple of weeks. A thread.
1/ Scanning a bare IP now checks for exposed databases and open ports too. Redis, MongoDB, an unauthenticated Docker API, these show up unauthenticated in the wild far more often than they should.
1/ A single-page scan checks one URL. Most real sites aren't one page.
The full-site AI agent decides for itself which pages on your domain are actually worth investigating, and runs the full 8-layer check on each one.
1/ 380,000 publicly accessible apps built with AI coding tools. Not hacked. Just left with default settings nobody thought to check. A thread on five stories from the last few months.
1/ Scared to add a Content-Security-Policy because it might break something?
That's the right instinct, actually. The wrong move is skipping it entirely. The right move is report-only mode first, so you see exactly what it would break before it does.
1/ The Supabase mistake that's worse than a missing RLS policy: the service_role key sitting in your client-side JavaScript.
That key bypasses Row Level Security entirely, by design. If it's in a bundle your browser downloads, your carefully written policies don't matter anymore.
1/ staging.yourcompany.com from a redesign two years ago is probably still online right now.
Still resolving. Still running whatever was live the day everyone stopped thinking about it. And finding it doesn't require guessing, Certificate Transparency logs make every subdomain you've ever had a certificate for permanently searchable.
1/ Your production site might be shipping its own uncompiled source code right now, comments included.
Not through a vulnerability. Through a debugging feature (source maps) that most build tools leave on by default and nobody remembers to turn off before deploying.
1/ NIS2's compliance deadline lands this October. It now covers roughly 160,000 EU entities, up from about 10,000 under the old NIS directive.
If your org wasn't in scope before, there's a real chance it is now.
1/ You could always run a security scan on a client's site. Handing them the PDF with our logo on it was the part that never quite worked.
Not anymore.
1/ One HTTP header stops most XSS attacks from being exploitable even after the vulnerability exists.
Almost nobody sets it.
Not because it's expensive. Not because it's hard. Because a badly configured one can silently break your site, and there's rarely an obvious error beyond a console warning nobody checks.
1/ Row Level Security is off by default on every new Supabase project.
That single setting is behind the most common security failure we see in apps built with AI tools. Anyone with your public anon key can read every row in every table, no exploit required.
Is your app affected? Genuinely worth checking today.