Decloak icon
Decloak icon

Decloak

Vibe coding gets you from idea to live app in hours, but the security review is usually the first thing that gets skipped. Decloak is built to catch what shipping fast leaves behind.

Decloak screenshot 1

Cost / License

  • Freemium (Subscription)
  • Proprietary

Application type

Platforms

  • Online
  • Software as a Service (SaaS)
0likes
0articles
Save

Features

Properties

  1.  Security-focused
  2.  AI-Powered

Features

  1.  No Coding Required
  2.  No registration required
  3.  Ad-free
  4.  Dark Mode
  5.  Penetration Testing
  6.  Web-Based

Decloak News & Activities

Highlights All activities

Recent activities

Decloak information

  • Developed by

    GB flagSparrow Technology Ltd
  • Licensing

    Proprietary and Freemium product.
  • Pricing

    Subscription ranging between $39 and $132 per month + free version with limited functionality.
  • Alternatives

    17 alternatives listed
  • Badge

    Get an embeddable badge for Decloak
  • Supported Languages

    • English
Decloak was added to AlternativeTo by Stephen Gray on and this page was last updated .

No comments or reviews, maybe you want to be first?

Official Links

Page may contain affiliate links. Affiliate links never affect ranking.

What is Decloak?

Vibe coding gets you from idea to live app in hours, but the security review is usually the first thing that gets skipped. Decloak is built to catch what shipping fast leaves behind.

Paste a URL and Decloak automatically fingerprints your platform (Lovable, Supabase, Base44, Bubble, Next.js) and checks for the misconfigurations known to affect each one, most commonly a Supabase database left publicly readable because Row Level Security was never turned on. It also flags exposed API keys in client-side JS, vulnerable libraries, missing security headers, and hidden trackers, across a full 8-layer scan that correlates findings instead of checking each one in isolation.

Beyond the initial scan, Decloak's AI agent investigates rather than running a fixed checklist: it follows threads across your whole site, reconstructs exposed source code from source maps, and cross-references suspicious domains against threat intel. Enterprise plans add AI-powered penetration testing (sandboxed sqlmap, nuclei, and jwt_tool runs confirming real exploitability) and compliance mapping to SOC2, ISO 27001, NIS2, and DORA, with exportable audit evidence.

Built by a solo founder who's spent 25 years in code intelligence and governance tooling, and got tired of watching security get skipped every time speed won.