Useful before you buy anything
None of these need an account. One of them tests your running deployment and returns a real result; the others ask you questions and are honest about the fact that an answer you gave is not evidence. Each card says which it is.
Test a deployed app from outside, with no account
Give it an address and it tests the running deployment: transport security, response headers, cookie flags and error handling. It names the controls a URL cannot reach as uncovered rather than passing them, so the result is a floor and not a verdict.
The list an investor works, from either side of the table
Founder and investor modes over the same items, covering access, data, secrets, dependencies, recovery, scale, practice, architecture and the team questions that are not about software. Each item says what would settle it, read from the control pack rather than asserted.
Work through row level security table by table
Policies per command, owners derived from the session rather than from the request, storage buckets, and security definer functions. It runs in your browser and sends nothing anywhere, so it reads only what you tell it.
Score your own readiness before someone else does
A scored self-assessment across the areas a launch tends to fail on. The score reflects the answers you gave, which makes it a way to find your own gaps rather than evidence you can hand to anybody else.
The pre-launch pass for an AI-built app
Twelve checks to work through before real users arrive, with your progress kept as you go. Entirely in the browser, and aimed at the failures that fast AI-assisted builds leave behind most often.
Where a free check stops
A scan from outside cannot establish authorisation, data-layer or backup posture, and a checklist cannot establish anything at all about your application. Those need access, which is what the audits are for.