Publish your app securelywithout being an expert.
Run a free security, domain, email, and AI-search scan on your app, with no sign-up and instant results. Create an account and the full technical analysis runs on your app, with feedback from real developers.
Test your app now
How far the free no-signup scan reaches
The free scan looks at your domain from the outside, without touching the site or reaching the logged-in area. It costs nothing and asks for no sign-up. Tests that act on the app, and the privacy-compliance analysis, are for owners who prove the site is theirs.
- Home page security headers (CSP, HSTS, Permissions-Policy) and what they give away about your server
- SSL/TLS certificate: validity, expiry and the HTTPS redirect
- DNS and domain: DNSSEC, CAA, dangling subdomain and registration expiry
- Domain e-mail (SPF, DKIM and DMARC)
- Public files and AI search: robots.txt (including the private paths it gives away), sitemap, /llms.txt, structured data and technical SEO
- Real homepage performance: Core Web Vitals (LCP, CLS, INP), the PageSpeed score and what is holding the load back
- A score from 0 to 100 and a report with the evidence behind every finding
How far each level goes
The scan on this page runs right now, with no signup. Creating an account is free and opens the technical analysis inside your app. Paid plans raise how much each analysis covers.
Free scan
on this pageNo signup, no card
Looks at your domain from the outside. It does not browse the site or enter the logged-in area.
- Security headers on the home page (CSP, HSTS, Permissions-Policy)
- TLS certificate: validity, expiry and the redirect to HTTPS
- DNS and domain: DNSSEC, CAA, dangling subdomain and registration expiry
- Domain email: SPF, DKIM and DMARC
- Public files and AI search: robots.txt, sitemap, /llms.txt and technical SEO
- A score from 0 to 100 and one problem from each front on screen
With an account
freeSignup, no card
This is the technical analysis, inside My apps. It goes into the site: it maps the pages, logs in and tests the backend.
- Everything in the free scan, plus its full report with the evidence behind each finding
- 10 analyses per month
- Maps up to 5 pages of the site
- 1 login per analysis, to reach the authenticated area
- Up to 25 API endpoints tested
- Backend and BaaS (Supabase, Firebase and others), payment and privacy
- Pentest with the critical and high severity corpus
- No active DAST pass, no comparison between two logins and no step by step fix
Paid plans
Pro and PremiumThe same analysis, with far more reach
No new test is switched on here. What grows is how much each analysis covers, and the finding starts coming with the fix.
- Everything in the free tier, without the three limits above
- 60 to 200 analyses per month
- 50 to 300 pages mapped per analysis
- 250 to 1500 API endpoints tested
- 2 to 3 logins per analysis, with the cross account reading (what account A reaches in B)
- Active DAST pass against the APIs we find
- Pentest with the corpus up to medium (Pro) and low (Premium) severity
- A step by step fix on every finding, ready to paste into your AI
No plan switches a test off: what changes is how much each one covers, and when a limit cuts, the report says "covered up to your plan limit". Verifying domain ownership unlocks the pentest and takes the BaaS out of read-only mode, and that works the same on every level.
What else is here besides the scan.
The scan is one part. The rest is real people using your app, a feedback button on your site and ecoa inside your AI assistant.
Sign up, verify domain ownership and unlock the full scan.
After you sign up, ecoa catalogues your site's pages and the APIs they call, reads your privacy policy and checks what it promises, signs in to the logged-in area with a test account, looks for one customer's data reachable by another, examines the checkout bridge and runs the penetration test. Every finding comes with the evidence that proved it.
Sign upBring ecoa into your AI assistant
Claude, Cursor, VS Code, or straight from the terminal: your copilot reads your app's real echoes and acts for you, without leaving the chat.
Hear your users in the chat
Summaries and real feedback on demand, without opening the dashboard.
Security and LGPD on command
Trigger the full technical analysis straight from a conversation.
Ship versions by chatting
New versions and their highlights, all in the same place.
It answers from your own data
Instead of guessing, the assistant reads your app's echoes and findings before it replies.
Two sides of the same echo.
Register your app for free to get feedback, or test community apps and help other makers.
Give feedback, get feedback. That is the cycle that moves the community.
Feedback on your site with one line of code
A lightweight, dependency-free <script> that puts a feedback button in the corner of the screen. Hear from the people using your product on the page where the friction happens. Feedback lands straight in your ecoa dashboard.
Paste and go
A <script> snippet before </body>, with your key already filled in. No dependencies.
Context per page
Every submission arrives with a rating, the source page, and the label you defined.
Passive or at the end of a flow
A button always in the corner of the screen, or open the widget at the right moment (e.g. post-purchase).
Or let your AI install it
Via MCP: ask Claude or Cursor and it adds the code for you.
Don't launch headfirst into the darkness
ecoa scans your app and reveals the security and quality flaws your AI left behind. Before they turn into losses.
If you have no idea what half of this means, you can bet your AI never even considered it.
AI models are built to please you. If you don't ask for the exact requirements, they won't chase them on their own.

You have seen what is open. Now close it.
Create your account to unlock the full report: the evidence behind every finding and the steps to fix it. Takes 2 minutes and asks for no card.