Confirmed
Missing Content-Security-Policy header
The submitted page response did not include the header.
Security checks for AI-built web apps
Start with a free check of your live app and get evidence you can act on. When the public view cannot answer a server-side question, SafeForProd shows what source access or expert review would resolve it.
Free first look · No account · Evidence attached
A value matching a privileged-key pattern appears in a referenced bundle. The free scan does not use the value or call the provider.
What the free scan can show
Result state is separate from severity and confidence. A serious-looking signal can still need authorized verification.
Read the methodologyConfirmed
The submitted page response did not include the header.
Needs verification
The pattern is visible; provider role and current validity still need verification.
Informational
These values are commonly publishable; security depends on server-side policy.
Not tested
The free scan does not query tables or exercise user permissions.
Coverage grows with access
The free scan earns attention with concrete public evidence. Each unknown then names the stronger source-backed or human check that could resolve it.
01
Free entry point
A submitted live URL. No account.
What it covers: Public HTML, referenced JavaScript, source exposure, security headers, and browser-visible configuration.
Boundary: No login, private-route probing, API calls, data queries, RLS tests, authorization tests, or rate-limit tests.
02
Planned product
Account, ZIP or read-only GitHub, written authorization, and domain verification.
What it covers: Source, dependencies, configuration, auth and data-flow patterns, plus bounded runtime validation inside the approved scope.
Boundary: Not exhaustive and not a security certification. Nothing outside the verified target is tested.
03
Scoped expert service
Agreed source/runtime access and a written scope.
What it covers: High-risk business logic, architecture, access control, and data paths, with a prioritized signed report.
Boundary: Coverage is limited to the signed scope; it is not unlimited penetration testing or a guarantee.
Safe by design
It fetches the submitted page and assets that page references. It does not guess admin paths, call discovered APIs, query databases, log in, introspect GraphQL, or test rate limits.
Every report records what was observed, how the evidence was classified, what was not tested, and what kind of access would be needed for a stronger conclusion.
Start with the free scan
Send the live URL you own or are authorized to assess. Start with the limited outside-in view; the report explains when planned source-backed validation or a scoped human review would add value.
No credit card. No signup. We only test what's publicly accessible.