// Trust isn't given. It's scanned.
FIND LEAKSBEFOREATTACKERSDO._
> Catch the leak before it leaks you.
VibeLeak scans the publicly observable surface of your website for trust gaps, misconfigurations, and exposure signals you can act on.
VIBELEAK_SURFACE_SCAN
Scan pipeline
Elapsed: 00:00:09Active probe
Read browser policy
CSP, HSTS, framing, MIME posture
Public surface findings
66/100
Trust score
C
Grade
07
Findings
+8 pts
Fastest lift
Overall progress
43%> trustscan :: CSP, HSTS, framing, MIME posture
> node 52.8,18.3 locked for public-surface review
> 4 header gaps queued into priority model
> rescan proof will attach after deploy
// Trust surface map
Map the public surface that shapes your grade
VibeLeak works best when it stays honest about the public surface: the stuff a browser, crawler, client, or attacker can already inspect without deep access.
External perspective
See your assets the outside world sees - no logins, no access needed.
Real-world signals
We validate misconfigurations, exposures, and outdated tech in the wild.
Actionable output
You get a prioritized list, severity map, and a clear trust grade.
One public request. Layers of insight.
35
score
Surface digest
DOne critical public exposure caps this sample at D. Fix that first; a second critical would push the report to F.
Trust score
35/100
Trust grade
D
Critical
1
High
1
Active layer readout
TLS / Certificate
HTTPS enabled, redirect posture healthy, cert expires in 23 days
Signal
72/100
Meaning
Holding steady
Layer queue
9 signals// Priority loop
Turn surface findings into shipped fixes
VibeLeak turns public-surface findings into a fix sequence: what to patch first, why it matters, and what the live recheck should prove.
Impact weighted
Severity, exposure, and lift decide what should ship before anything else.
Action shaped
Each finding becomes a concrete patch target instead of a vague warning.
Proof loop
Recheck the live response and confirm the grade moved before calling it done.
Priority engine
Queue updated: 2 min agoFix lift preview
A after policy80
Now
96
After policy fix
Lift
+16 pts
First pass
14 min
Proof
rescan
Next patch
Ship browser policy
Add a baseline CSP and enforce HSTS after HTTPS is verified.
Why first
A single high finding keeps this sample in B until the policy is present.
Done when
CSP and HSTS headers present
Ship browser policy
HighCSP and HSTS missing - A single high finding keeps this sample in B until the policy is present.
Publish security.txt
LowDisclosure route missing - Low-severity trust cue that cleans up the handoff after the blocker is gone.
Reduce stack fingerprint
InfoFramework fingerprint visible - Informational cleanup after the material findings are handled.
>_ Patch in order. Recheck the live URL after deploy.
Open fix queue// Markdown export
export_handoff.mdExport findings. Hand off to your AI agent.
Signed-in owners can export a structured Markdown report - one file with grade, evidence, and exact remediation steps. Free accounts get this full handoff during the launch window; public links stay redacted.
01
Executive summary
Grade, target, severity mix, and the fastest lift to move the score.
02
Findings by module
Evidence, why it matters, and plain remediation for every surfaced issue.
03
AI visibility next steps
A clean markdown structure you can paste into your team stack or straight into an AI workflow.
> export surface_scan --markdown --agent-ready_
target=https://your-site.com scan_id=VLK-24A7FC1
Grade
D
Score
39 / 100
Blockers
2
Fastest lift
+45 pts
## Top Findings
## Remediation
- Revoke exposed production keys and move sensitive calls server-side.
- Ship CSP and HSTS after the key exposure is contained.
modules
8
checks
189
proof
rescan
> handoff_ready=true next=apply_fixes_
Handoff pipeline
Works with your AI agent
Claude Code
Codex
OpenCode
Kilo Code
BlackBox AI
OpenClaw
Hermes Agent
Cursor
Windsurf
Qwen CLI
Antigravity
Factory
VibeSignal AI readiness grade
Grade the public signals AI systems rely on.
This illustrative V2 fixture shows a core-strong AI readiness profile: the grade leads, the weighted score follows, and raw bucket points stay visible only as supporting detail.
Raw fixture: 20 / 20, 20 / 20, 20 / 20, 4 / 20, 4 / 20. Weighted by the shared V2 rubric to 92 / 100 and grade A.
Observed against
ChatGPT
Perplexity
Claude
Grok
Gemini
> vibesignal scan https://yoursite.com_
Opening passive AI signal probe...
AI Readiness Grade: A - Strong Signal
Weighted score: 92/100 from shared V2 weights
Raw buckets: 20 / 20, 20 / 20, 20 / 20, 4 / 20, 4 / 20
-> Grade-first V2 fixture. Export .md for your agent.
Weighted contribution breakdown
Shared V2 weights: 35 / 35 / 20 / 7 / 3. Raw /20 values are supporting detail only.
Grade A
92 / 100 weighted • Strong Signal
Markdown fix lists you can hand straight to an AI agent or a developer.
Rescan after you deploy changes and watch category scores move.
Observed against
ChatGPT
OpenAI
Perplexity
Perplexity
Claude
Anthropic
Grok
xAI
Gemini
// Plans
Start free. Scale when the signal demands it.
Run the public scanner with no card. Sign in during launch to save history, see full findings, and export Markdown handoffs. Pro and Agency use live checkout to unlock unlimited scans, VibeRank, API/MCP access, paid Score Watch, durable full-report access, and higher account limits.
Free
LiveFree scans. Limited-time full report access.
- 5 full trust scans / day
- VibeSignal included
- Grade + public summary
- Limited-time export when signed in
- Dashboard recents while signed in
Pro
FoundingHigher limits + VibeRank for builders shipping fixes often. Founding price is locked for the life of your subscription.
- Unlimited scans when billing is active
- Same VibeLeak + VibeSignal engine
- VibeRank AI answer visibility scan (Pro extension)
- Saved history + score watch
- Markdown + AI handoff export
- API keys for API v1 + MCP
- CI/CD hooksRoadmap
Agency
FoundingFor teams managing trust across client sites, with VibeRank included. Founding price is locked for the life of your subscription.
- Unlimited scans when active
- VibeRank AI answer visibility scan (Pro extension)
- Client-fleet workflowsRoadmap
- Bulk scanningRoadmap
- Team seatsRoadmap
- White-label reportsRoadmap
