Security decision engineSecurity of apps and domains before you decide

Don't guess.
Verify.

See what is exposed. Find out what is missing. Decide what comes next. Before you connect, deploy, buy or trust.

Free and without an account. We open the site the way any visitor does and bypass nothing.

Each point is one observation

  • evidence
  • risk
  • unknown
  • out of scope

00 · Paste anything

Paste anything. We'll tell you what it is.

A key, a token, a .env file, headers, a URL, a CVE number. You see right away what it is, what follows from it and what to do next. No account, no waiting.

Recognition runs in this browser tab. Nothing you paste leaves it: we don't send it and we don't store it.

Examples with made-up data

What we recognize

  • an app URL or domain, including defanged ones written as hxxp and [.]
  • keys and tokens: Stripe, AWS, GitHub, OpenAI, Anthropic, Supabase and more
  • a JWT: header, payload, role, expiry
  • the contents of a .env file
  • an agent's MCP server configuration
  • HTTP headers copied from browser developer tools
  • a CVE number
  • a file or password hash
  • an IP address and a CIDR range
  • an email address
  • text in Base64 or URL-encoded

For each item: what it is, what it means for your decision and what to do next. You can pass an app URL straight to a full assessment.

01 · Mechanism

Four steps from question to decision. Each one leaves a trace.

  1. 01 · context

    Context

    First we ask why.

    What you use it for, what data goes in, who has access. Without that, every result answers a question nobody asked.

    • goal: release a client dashboard
    • data: invoices, contact details · clients: 34
    • authorization level: L0 · active tests: blocked
  2. 02 · observe

    Observation

    Only what anyone can see.

    Plain GET requests, like a visitor's browser. No sign-in, no bypassing rate limits, no probing.

    • GET / 200 · 38 ms
    • GET /privacy-policy 200
    • GET /.well-known/security.txt 404
    • data recipients outside the domain: 3
  3. 03 · verify

    Verification

    A test starts only with authorization.

    Anything that touches a live system needs an entry in the authorization ledger. Without one, the queue rejects the job. This is not a warning in the interface.

    • authorization UP-0142 · staging · until 30.09
    • tenant_a → /rest/v1/invoices?owner=tenant_b
    • 200 OK · 14 rows · read policy: none
  4. 04 · decide

    Decision

    A verdict with scope and date.

    Risk, evidence strength, exposure and what we don't know, each on its own. No single number hiding all of it.

    • verdict: conditional
    • risk: high · evidence: L2 · exposure: internet
    • unknown: 2 · decision expires 14.11.2026
  5. sample · synthetic data

02 · Evidence map

Every decision has a path. We'll show it to you.

Pick a node. Everything that leads to it and everything that follows from it lights up. A dashed line marks a place where there is no evidence.

03 · Decision

You don't get a number. You get a decision you can defend.

Example · synthetic data

Releasing an app for an agency's client

Client portal, Supabase deployment

Conditional
Why
  1. 1The invoices table is readable by a signed-in user from another account. Reproduced on two test identities.
  2. 2The service key reaches the browser in one of the admin views.
  3. 3The attachments bucket has no read policy, and file URLs are predictable.
What we don't know (2)
  • No confirmation of who has administrative access to the production environment.
  • Backup configuration and a restore test were not shared.
Conditions before rollout
  • Close the read policy on the invoices table and add a regression test.

    agency team · due before release

Not checked
  • production environment
  • payment integrations
  • performance under load
  • mobile app

Decision scope: repository, configuration, access policies, public surface

Assessed on: 14 August 2026

Evidence level: L2, read-only access to the repo and schema

Decision expires: 14 November 2026

Human review: yes, before the decision was issued

  1. A verdict, not a score

    Four states: accept, conditional, reject, unknown. Each has a symbol and a word, not just a color.

  2. Why

    Every reason leads to evidence you can open and reproduce.

  3. What we don't know

    Separate and up front. Missing evidence is neither “safe” nor “critical”.

  4. Conditions

    With an owner and a deadline. We close a finding only after a passed retest.

  5. What was not checked

    Listed explicitly, so missing information does not look like no problem.

  6. Scope, date, expiry

    The decision covers a specific state on a specific day and has an expiry date.

04 · Surfaces

Six things you can check. The result always has the same form.

What changes is what you give us and the authorization level. The result format does not: evidence, unknowns, conditions, a dated decision.

surface 01 / 06L0 · public surface

App URL

you provideThe address of a site any visitor can see.

We don't sign in, we don't bypass rate limits, we don't probe anything.

we check

  1. 1who the site passes data to
  2. 2who is behind it and how long the domain has existed
  3. 3where forms submit, encryption, keys left in the code

05 · Boundary under test

This is what evidence looks like. A promise looks different.

Most apps claim that customer data is kept apart. We check it, with authorization, and leave a record that can be reproduced.

replay · data boundary test · sample, synthetic data
verdict right nowConditional
  1. 00:00.000authorization UP-0142 · staging · L3 · valid until 30.09
  2. 00:00.214identity tenant_a · identity tenant_b
  3. 00:01.020tenant_a → GET /rest/v1/invoices?owner=tenant_b
  4. 00:01.188← 200 OK · 14 rows · read policy: none
  5. 00:01.402finding F-031 · evidence: 2 identities, request, response · sha 9c1e04
  6. +2 daysfix: invoices_select using (organization_id = my_organization())
  7. +2 daysregression test added: tenant_a ↛ tenant_b
  8. +2 daystenant_a → GET /rest/v1/invoices?owner=tenant_b
  9. +2 days← 200 OK · 0 rows · read policy: active
  10. +2 daysF-031 closed · retest passed
  11. +2 daysdecision: conditional · unknown: 2 · expires 14.11.2026

07 / 07Decision

The finding is closed only after a passed retest. Two unknowns remain, so conditional, not “safe”.

06 · Before you decide

Know
before you decide.

Paste a URL. In a moment you see what is exposed, what cannot be established from the outside and what to do about it.

Free and without an account. We open the site the way any visitor does and bypass nothing.

arLET’S is not an automated penetration test and does not issue security certificates. It tells you what is known, on what evidence, what is unknown and until when that knowledge holds.