VICE audits your web app the way an attacker would: leaked secrets in your bundles, Supabase RLS misconfigurations, exposed APIs, weak headers and infrastructure.... The engine is open source and free today, as a CLI or a GitHub Action. The hosted Platform adds the full loop: verify your domain, run a full audit, get findings with evidence, apply a suggested fix, then retest to confirm it's gone.
This is the 2nd launch from VICE Platform. View more
VICE Platform - Public Beta
Launching today
Secure the product you are building
VICE audits your web app the way an attacker would: leaked secrets in your bundles, Supabase RLS misconfigurations, exposed APIs, weak headers and infrastructure.... The engine is open source and free today, as a CLI or a GitHub Action. The hosted Platform adds the full loop: verify your domain, run a full audit, get findings with evidence, apply a suggested fix, then retest to confirm it's gone.
Hey Product Hunt 👋
Modern stacks make it trivial to ship something that works, and just as easy to ship a secret into your client bundle, or a Supabase table anyone can read anonymously. The app runs fine. Nothing looks broken. That's the trap: "it works" and "it's actually protected" are two different questions, and most of us only ever test the first one.
The tools that answer the second question exist. They start around $200/month and are built for compliance teams. Or they're CLIs built for pentesters. If you're a solo builder or a small team, there's nothing in between.
What's free today:
- The VICE engine is open source: automated DAST + SAST checks, Supabase/RLS analysis, API, GraphQL and WebSocket coverage, security headers and infrastructure checks.
- Run it as a CLI or drop the GitHub Action into your CI.
What's opening today: the hosted Platform, in public beta!
Forge