What we did NOT check
A scan runs at one of three tiers. Nothing above free is unlocked by anything except a paid key (audit or Pro) or a verified ownership token — and nothing, at any tier, changes or deletes your data.
Free surface scan — ≤20 unauthenticated GETs against your live URL. No login, no database access, no write of any kind.
Pro / verified-ownership — adds live proof: Supabase/Firebase discovery, anonymous-read checks, and a few short test prompts to AI endpoints. Checks between signed-in users are coming later. Never changes your data.
Active engines — dependency scan (OSV), web/API DAST (Nuclei), AI/MCP config audit. Gated the same way as Pro/verified-ownership. Login attempts and exploit payloads are excluded.
If we did not reach your app, the report says so and claims nothing.
Free surface scan (≤ 20 unauthenticated GETs)
- source maps
- supabase RLS runtime
- BOLA matrix
- rate-limit probes
- Stripe trust boundary (static, needs repo)
- dep reachability
- cost-abuse dynamic
- auth/session behaviour
Pro / verified-ownership (read-only live proof)
- A→B cross-user proof (needs your test accounts)
- write paths (never probed)
- storage/RPC runtime
- write paths (refused in M2)
- storage/RPC runtime (M3)
- rate-limit probes (M3)
- payments (static only)
Active engines — dependency scan, DAST, AI config audit (Pro / verified-ownership only)
- call-graph reachability (grep-level only)
- transitive exploit paths
- authenticated flows
- OOB/interactsh checks (disabled)
- default-credential login attempts (never tried)
- exploit payloads (RCE, SQLi, XSS, LFI, SSRF templates are excluded)
- tool descriptions for prompt injection
- authenticated AI routes
- tool-call abuse
- multi-turn jailbreaks