Common questions
Is the free scan actually free?
Yes — no card, no trial, no catch, just a free account (sign-up takes 30 seconds). Free gives you one passive scan a month on one URL: security headers, TLS/SSL config, and certificate health. No active probes on the free tier.
What counts as an "active" probe, and what's "deep"?
Active scans (One-off and Monitor) send crafted requests to your app — checking for exposed Supabase tables/buckets, leaked secrets in JS bundles, and rate-limiting on login endpoints. Deep scans (Monitor only) add a Nuclei vulnerability-template sweep on top. Non-destructive: we never write to your database or delete anything. You verify ownership first so we know you consented.
Do I need to install anything?
No. No SDK, no agent, no npm package. You give us a URL, we give you a report. The ownership verification is a single DNS TXT record or a file you drop in /public — takes about 90 seconds.
How does the badge work?
After an active scan, we generate a cryptographically signed badge token. Embed the badge snippet in your site. It links to a stripped public report showing what we checked and what passed. It's valid for 30 days — on One-off, that also lines up with when your plan reverts to Free; re-scan (or stay on Monitor) to keep it current.
What happens to my data?
Scan results are stored in your account. We keep anonymised aggregate statistics ("X% of scanned apps have missing CSP headers"). We never share identifiable data. Email us any time to delete your account and everything goes — reports, findings, badge history.
Can I scan a staging environment?
Yes — as long as it's reachable from the public internet. Private IPs and localhost are not supported. Staging scans count against your URL limit the same as production.
What happens after my One-off 30 days are up?
Your account reverts to the Free plan automatically — no charge, no action needed. Your report and findings stay in your account, but the badge stops being valid and you're back to Free's one-scan-a-month limit. Buy another One-off scan anytime to unlock active scanning again for another 30 days.