Agencies and consultants using decloak.dev aren't using it just for their own sites. They're running scans as a lead-generation tool, a Supabase RLS finding or a missing CSP header is a genuinely persuasive opener for a security or dev-services pitch, and they're running it as part of actual client engagements, audits, retainers, pre-launch checklists. In both cases, a report with our branding on it undercuts the thing they're actually selling: their own expertise and their own relationship with the client.
White-label reporting removes that friction entirely. The finding is still ours. The scan engine is still ours. But the document that lands in a client's inbox is unmistakably yours.
Built with Lovable, Supabase, Base44, or Bolt? Decloak scans your app for the security issues AI builders consistently skip, starting with the #1 vibe-coder failure: a Supabase database left publicly readable because Row Level Security was never turned on. It auto-detects your platform, checks 8 layers including exposed API keys and leaked service_role keys, and returns a graded report in 15 seconds. Free, no account or card required.
We built it because we were tired of watching AI-generated presentations turn into manual reformatting projects. The problem was not getting slides made. The problem was getting them made in the right brand, the right layouts, and the right standard for teams that actually ship work.
Someone from our businesses (executives, stakeholders, advisors etc) would generate a presentation on Gamma, or Kimi, or Beautify, and then say "Re-format this in our brand format".