See what your app reveals to attackers.
Give us a public URL. Lockvane reads the pages, delivered code, and configuration any visitor already receives, then reports what an attacker could do with it, ranked by what to fix first.
What we look at, stated plainly
No credentials. No agents. No traffic your users wouldn’t generate.Severity is assigned, not guessed
Every finding carries a level and a weight, and the exposure index is the sum of the weights of what is still open. Anything we could not reproduce twice is marked OBSERVED, never CONFIRMED, and an observation counts half.
GET /assets/index-4f9c.js
-> 200 · 412 KB · text/javascript
line 1, col 84210
const SUPABASE_KEY = "eyJhbGciOiJIUzI1NiIsInR5cCI6..."
decoded: { "role": "service_role", "exp": 2051222400 }
reproduced 2/2 · unauthenticated · no headers setYou pay for the work, not for the app
Connecting is always free. Adding an app has never been the billable event.Enough to find out whether you have a problem.
- Unlimited public scans, no account
- Connect every project and repository you have
- The full findings table and the fix for each one
Always-on protection for everything you have connected.
- Continuous monitoring, with alerts when something new appears
- Weekly security digest
- One-click fixes on GitHub and Supabase
- Fair-use deep scans included
For occasional checks and one-off client audits.
- 10 deep-scan credits
- Redeem any time within 12 months
- No subscription
A deep scan is one reachability run against one verified project. It queries your database, which is why it is metered and why the public scan never is. Card payments run through Stripe, and MonCash is available if you are in Haiti.