What we did NOT check

A scan runs at one of three tiers. Nothing above free is unlocked by anything except a paid key (audit or Pro) or a verified ownership token — and nothing, at any tier, changes or deletes your data.

Free surface scan — ≤20 unauthenticated GETs against your live URL. No login, no database access, no write of any kind.
Pro / verified-ownership — adds live proof: Supabase/Firebase discovery, anonymous-read checks, and a few short test prompts to AI endpoints. Checks between signed-in users are coming later. Never changes your data.
Active engines — dependency scan (OSV), web/API DAST (Nuclei), AI/MCP config audit. Gated the same way as Pro/verified-ownership. Login attempts and exploit payloads are excluded.

If we did not reach your app, the report says so and claims nothing.

Free surface scan (≤ 20 unauthenticated GETs)

Pro / verified-ownership (read-only live proof)

Active engines — dependency scan, DAST, AI config audit (Pro / verified-ownership only)