Agencies and consultants using decloak.dev aren't using it just for their own sites. They're running scans as a lead-generation tool, a Supabase RLS finding or a missing CSP header is a genuinely persuasive opener for a security or dev-services pitch, and they're running it as part of actual client engagements, audits, retainers, pre-launch checklists. In both cases, a report with our branding on it undercuts the thing they're actually selling: their own expertise and their own relationship with the client.
White-label reporting removes that friction entirely. The finding is still ours. The scan engine is still ours. But the document that lands in a client's inbox is unmistakably yours.
Built with Lovable, Supabase, Base44, or Bolt? Decloak scans your app for the security issues AI builders consistently skip, starting with the #1 vibe-coder failure: a Supabase database left publicly readable because Row Level Security was never turned on. It auto-detects your platform, checks 8 layers including exposed API keys and leaked service_role keys, and returns a graded report in 15 seconds. Free, no account or card required.