StackAttestTechnical Trust
Free check

Check your AI-built app, before someone else does

Paste the address of a deployed application and get a real result: what we could establish against the running system, and what a public URL genuinely cannot reach. No account, and nothing is published.

No account needed. We fetch the address you give us and nothing else.

What this check does

It fetches your address the way any visitor would and reads what comes back. Four things can be established that way, and each is observed against your running deployment rather than inferred from anything:

  • Transport security

    Whether TLS is valid and whether plain HTTP redirects to HTTPS.

  • Security response headers

    HSTS, Content-Security-Policy, X-Content-Type-Options, clickjacking protection and Referrer-Policy.

  • Cookie flags

    Whether cookies are set with Secure and HttpOnly.

  • Error handling

    Whether an error response discloses stack traces or database internals.

What it deliberately does not do

It does not try to log in, bypass anything, enumerate your data or send destructive requests. It is the check a careful visitor could run, not an attack. That also means it cannot see your source, your database policies or your server-side authorisation, and the result says so for each control rather than quietly passing it. If you want those answered, that is what connecting a repository and running a full validation is for.

Questions

Do I need an account?

No. The check runs on a public address and returns a result immediately. An account is only needed to connect a repository or to publish a Passport.

Is this safe to run against my app?

Yes. It is a passive check. It fetches your address the way any visitor would, reads the response, and requests one path that does not exist to see how errors are handled. It sends no destructive requests, does not attempt to log in, and does not try to bypass anything.

What can a public URL check actually establish?

Transport security, security response headers, cookie flags, and whether error responses disclose internals. Those are observed against your running deployment, so they are runtime verified rather than inferred.

What can it not tell me?

Whether one account can reach another account's data, whether your database policies are correct, whether a privileged key is committed in your source, and whether your dependencies carry known vulnerabilities. Those need the source or an authenticated runtime validation, and the result names them as uncovered rather than passing them.

Does this create a public page about my app?

No. An anonymous check produces a result for you to read and nothing else. A Passport is a claim about a real product, so publishing one requires an account and a deliberate decision.

Can I check someone else's site?

The check only does what any visitor's browser does, so it is safe by construction, but it is rate limited and results are cached briefly so it cannot be used to send traffic at a third party.

Vibe code auditAI app security auditProduction readiness checklistVibe coding checklist