Active Monitoring
Your agents ship on Tuesday afternoon and nobody reads it. A scan tells you what was true when you ran it. This is the same read, running on its own, across everything you have live.
Early access is free and handed out by key, so nobody is charged yet. The prices below are what it will cost when it opens. See the tiers.
Free
$0forever
One read, whenever you ask for it.
- The full seven surface read on your repo
- URL scan on anything you have live
- Shareable report, no account
- Unlimited runs
Builder
$49per month, three projects
The read keeps running without you.
- Everything in Free, on a schedule
- Hosts found from one domain, through certificate transparency
- New hosts read as they appear
- Findings that only exist across hosts
- A dated record of every read
- Ten projects $149. Extra project $15
Enterprise
Customper organisation
Your source never leaves your network.
- Everything in Builder
- Engine runs inside your network
- Findings leave. Source does not
- Self hosted GitLab
- Named reviewer attestation
How it runs
- 1Connect one domain. We read certificate transparency for the names ever issued a certificate under it, then check which of those still resolve. That is a floor and not an inventory: a host behind a wildcard or a private authority never appears in a public log.
- 2It reads, on its own. An hourly job takes the projects that are due, on a cadence you set from six hours to monthly, and reads the hosts that have gone longest without one.
- 3You hear only when it matters. A signed webhook, and only when something changed: a new finding, a new host, or a finding that is no longer observable. Silence means it ran and nothing moved. Email and Slack are not built yet.
Nobody stopped reading code on purpose
The volume outran the habit, and it happened to professionals, not beginners.
+31%more pull requests are merged with no review at all, human or agentic, at the teams that adopted AI hardest.Faros AI, 2026 · telemetry from 22,000 developers
48%of professional developers always check AI-written code before committing it. 96% say they do not fully trust it.Sonar, Jan 2026 · 1,100+ professional developers
10.5%of AI-generated code passes a security review, though 61% of it runs correctly.OX Security, 2026
Automations
What starts a read without you asking, and what does not start one yet.
Running today
- On a schedule
- Six hours to monthly, per project. An hourly job checks what is due, and a domain nobody has proved control of is never read.
- On a new host
- Discovery stores a subdomain the first time it sees it, and the next run reads whatever has never been read.
Not built yet
- On push
- The receiver checks the signature GitHub sends and records the event. It does not start a read.
- On pull request
- The same receiver and the same limit. Nothing is posted on the diff.
- On deploy
- Reading what is actually served asks a different question from reading the repository, which is why it is on the list.
- On a new detector
- When it exists it will read your code again rather than replay an old read, because we do not keep your source.
We do not keep your source once a read finishes: it is unpacked, read, and the whole directory is removed, so the redacted report is the only thing that stays. What leaves your machine, and what does not.
The detail, if you want it
Why per project, and never per host
One database credential, served from production, staging and dev, with row policies enforced on exactly one of them. No single scan sees that, and most products that would sell you one bill per host, so you would pay three times to find it.
A project is one repository plus every host it deploys to. The moment you hesitate to add staging. because it costs more, we have priced ourselves out of the thing we exist to find.
What you get from us running the engine
- Nothing to maintain. No version to bump, no rule set to keep current. The day a detector improves, your next read uses it.
- Detectors come from measured work. Each is scored against a corpus of real applications before it ships, so the list grows on evidence rather than recollection.
- Findings map to published standards. OWASP, a CWE identifier, and the AIUC-1 crosswalk. No score we invented.
- The method is published. What gets read, and how. The engine is deterministic, so anyone can re-run the same check.
What you are buying when we find nothing
Most months, nothing is wrong. You are not buying findings. You are buying the fact that somebody looked, at a stated frequency, on a stated method, and wrote down what they saw. Nobody asks their uptime checker to justify a green week.
What is left is a record: dated, scoped, and repeatable by anyone who wants to check our work. A pile of Seatbelt reports is not proof your app is secure. It is proof you checked.
The standard already puts a number on how often
AIUC-1 is the assurance standard for AI systems, and Lovable certified against it in July 2026. Every requirement in it carries a frequency, printed next to whether it is mandatory.
| Requirement | Applies | Frequency |
|---|---|---|
| A008 Prevent leakage of credentials and secrets | Mandatory | Every 12 months |
| C006 Prevent output vulnerabilities | Mandatory | Every 3 months |
| C008 Monitor AI risk categories | Optional | Every 12 months |
Nobody who writes a standard thinks a control that ran in March is still running in November. What we map to, and the one requirement we refuse to claim.
The Proof of Read
The console produces a document you can forward. It is the answer to the question a customer, an acquirer or an auditor asks after they ask whether you check: show me.
What it states:
- What was read. The domain, whether you proved control of it, every host found and which of them were actually read, the date, and the engine version that read them.
- All seven risk surfaces. What each one showed, and for the ones a read from outside cannot reach, that it could not reach them. Coverage is stated rather than implied.
- Every finding. Named, with the hosts serving it, and with the redacted cue rather than the secret.
- AIUC-1 output evidence. The four code relevant requirements, the frequency each one carries, and what this read produces for it.
It carries a reference that resolves to a page anyone can open. That page is the point: a document nobody can check is a document anybody can write, which is why there is no seal on it and never will be.
It is not a certificate, not a compliance attestation and not a penetration test, and the document says so in its own body rather than in a footnote. It is signed as a statement that the read happened and that these were its results, which is a thing that can be true. Nobody can sign that software is secure.
What this does not do
- A URL alone reaches two or three of the seven surfaces. Login, payments, customer data and code execution cannot be seen from outside at all, and the ones a URL does reach, it reaches only in part. Connect the repository for the rest.
- No score. A number is honest only if it is calibrated against real loss data, and we have none.
- It reads and reasons. It does not attack. This complements a penetration test rather than replacing one.
- Authorization still needs a human. Whether a route belongs to the person calling it is the review, not the monitor.
- Not a compliance certificate. That comes from a licensed auditor. What you get is the evidence underneath one: a dated record of what was read and what it found, signed as a read performed on your behalf, with a public reference the person you hand it to can check without an account.
Getting in early
Setup is one field: connect a domain and we find the rest. Early access is free, so the only thing a key costs you is the email asking for one. Tell us the domain you want watched and we will send one back. If you think the price is wrong, that is worth writing too.
Get an early access key