Skip to content

Documentation

Everything you need to secure your AI-built projects

Quickstart

Getting Started

Quickstart

From first scan to first fix with no installation. Paste a URL, review the available evidence, verify ownership when you want heavy coverage, and confirm each fix.

1. Run your first scan

Paste your site’s URL on the homepage and start the scan — no signup required. The no-signup scan starts only the bounded pre-verification wave:

  • 17 public modules run now: they expose the maximum available finding names, evidence, category counts, severity counts, and coverage limits without requiring ownership proof.
  • Heavy scanners do not start anonymously: Injection, XSS, Ports, Nuclei, ZAP, and Medusa unlock only after a signed-in owner verifies the domain. All six then settle independently.

Before that verified-owner wave settles, the overall Security Score and grade remain N/A. N/A means coverage is incomplete, never zero and never passed.

2. Read the results

The free preview shows the maximum available lightweight finding names plus category and severity counts. It keeps the overall score and grade N/A until owner verification and final settlement of all six heavy scanners. Work top-down by severity: CRITICAL > HIGH > MEDIUM > LOW > INFO.

  • Once the report is assessable, any confirmed critical finding caps the score at 30 — no amount of good headers outweighs an exposed secret.
  • Scoring is evidence-first: findings without captured proof are automatically downgraded, so the number reflects what was actually verified.

The full scoring model — weights, caps, and score-withholding rules — is documented in How the Security Score works.

3. Unlock the full report

Unlock with a pay-per-report credit. Enterprise subscriptions include full report access. Care, Pro, and Team keep full reports pay-per-report. The full report adds everything you need to act:

  • Captured evidence for every finding — the exact URL, header or response that proves it
  • Step-by-step fixes written for your stack
  • AI fix prompts for Cursor, Lovable, Bolt, Claude Code, Replit, v0 and Windsurf
  • Compliance mapping and PDF export

See Understanding your report for a section-by-section walkthrough.

4. Fix and verify

Start with the criticals. Paste the finding’s fix prompt into your AI coding tool, or apply the deterministic autofix template where one exists. Then rescan — findings close only when the new scan captures evidence that the issue is gone, never on faith.

The full find-fix-prevent loop is covered in The AI Security Workflow.

5. Stay protected

A clean scan is a snapshot. The Care plan keeps it current:

  • Weekly deep scans of your domains
  • Uptime, SSL, DNS and blocklist monitoring
  • Alerts via email, Slack or webhook when something regresses
  • A live security badge you can embed on your site

FAQ

Is scanning safe for production?

Yes. The pre-verification scan uses bounded, non-destructive, rate-limited public probes. Heavy scanners are not admitted until a signed-in owner verifies the domain.

Do I need an account for the first scan?

No — the lightweight finding names, category counts, severity counts, and coverage state are available without signup. A final score is not promised at this stage. Sign in and verify ownership to unlock all six heavy scanners. Full report detail and scan history have their own access rules.

Why should I verify my domain?

Verification proves that you control the target. It allows eligible in-process Injection, XSS, and Ports scanners and external Nuclei, ZAP, and Medusa engines to continue in the background without delaying the base Security Audit. See Scanning for details.