Developer Tool, SaaS, AI

Decloak

Automated web security intelligence to find exposed keys, vulnerabilities, and misconfigurations.

Decloak

About Decloak

Decloak checks websites and apps for security vulnerabilities across multiple layers. It scans JavaScript for exposed API keys, identifies known library CVEs, detects hidden tracking scripts, reveals missing HTTP headers, and flags database misconfigurations like unencrypted or publicly readable Supabase tables. Users can run deeper automated agent investigations, continuous penetration tests behind logins, and generate audit-ready compliance evidence mapped to SOC 2 and ISO 27001.

Who is Decloak for?

Solo builders, vibe coders, compliance teams, and agencies who launch web applications quickly but skip deep security reviews. Before this, they had to manually audit code bases, check for leaked environment variables in client bundles, monitor domain DNS health, and piece together fragmented reports from multiple single-purpose tools, risking critical data leaks or failing compliance audits due to overlooked misconfigurations.

How does Decloak work?

Users begin by pasting their website URL into the interface to get a scored security report. Next, they deploy an autonomous agent that crawls every sub-page, subdomain, and asset to uncover deeper issues. Finally, the platform generates structured compliance evidence and runs scheduled scans to flag new exposures, vulnerable libraries, or DNS anomalies over time.

More Developer Tool, SaaS, AI

  • Trama

    Go headless without setting your store on fire.

    Developer Tool, SaaS, AI