Modules

Domain audits

Light, full and custom audits run inside the selected workspace with live progress. First results land in about a minute.

$ vice scan acme.dev
▸ headers ········· 12 checks
▸ tls ············· valid, HSTS on
▸ files ··········· no .env exposed
▸ supabase ········ 1 RLS gap
score 82/100 · grade B · 4 findings
01

Add a domain

Every domain becomes its own workspace: audits, findings, modules and history in one place.

02

Verify ownership

One DNS TXT record proves the domain is yours and unlocks the deeper checks.

03

Run the audit

Light for a quick pulse, full for the complete picture, custom when you know what you want.

04

Fix and re-score

Apply the AI fix, mark the finding solved, and watch the score climb on the next run.

Security reports you can actually read

No compliance theater, no fear-mongering. Findings, evidence, and the exact fix. Written for builders, not CISOs.

A score worth showing off

One number out of 100, tracked over time, with an embeddable badge. Proof that your product takes security seriously.

headerstlssupabase82

Evidence, not vibes

Every finding keeps its raw evidence next to the remediation, so you can verify the problem is real before you fix it.

$ GET acme.dev/.env200 OK# .env · productionDATABASE_URL=••••••••••••STRIPE_SECRET_KEY=sk_live_51H…SUPABASE_SERVICE_ROLE=••••••RESEND_API_KEY=••••••••

Resources