AI white-hat pen test
See who can really read your users’ data
Most scanners stop at “is a key exposed?” HatTest goes further — it tests whether your access rules actually hold, on the site you own or the API / database backend behind your app: from what the anonymous public can pull, all the way to whether one logged-in user can reach another’s rows. Scanning is free; the full findings, each with its evidence and a fix, are a $50 unlock per report.
🎉 Launch offer — your first report is free. It’s applied automatically at your first unlock (code freescan, nothing to type).
Strictly passive by default · we never run code on your site · full scans run only on domains you verify.
How it works
Create an account, prove you own the domain, and scan it as deeply as your stack allows.
Create an account
Sign up with GitHub or your email — passwordless magic-link works too.
Verify your domain
Add a meta tag or DNS TXT record once. HatTest only ever scans a property you own.
Run the scan
A strictly-passive recon pass — including an anonymous-role check of whether your backend hands out data it shouldn’t. Go deeper any time with an authenticated deep scan.
Read the results
The scoreboard, informational findings and your site profile are free. Unlock the negative findings — evidence and a plain-English fix for each — per scan.
What we find
Deterministic checks with evidence on every confirmed finding. Trust over coverage — we classify by role and sensitivity, so public-by-design things never cry wolf.
A Supabase service_role or secret API key shipped to the browser hands an attacker your whole database. We classify keys by role — public, client-safe keys aren’t findings, so you don’t get false alarms.
Backend tables that answer an anonymous request with data they shouldn’t — the classic Supabase / PostgREST exposure behind many app breaches. Our authenticated RLS-efficacy probe goes further: it proves whether one logged-in user can read another’s rows.
These are the flagships — the full catalog is 156 checks across 18 categories, each with its impact and CWE. See every check we run.
Presence is easy. Efficacy is the point.
A leaked key is a mistake an attacker can read. A broken access rule is the door left unlocked. Most tools check the first. HatTest checks the second — whether your rules actually hold.
Is a secret exposed? A header missing? A library out of date? All worth knowing — and all presence checks: they read what’s there, not whether your data is actually protected.
Whether your access rules hold under a real request. The free scan asks as the anonymous public — can a stranger read your customers table? The deep tier asks as a logged-in user — can Alice reach Bob’s rows? That’s the flaw behind a large share of modern breaches, and the one presence checks can’t see.
A sample report
A real scan of PayFlow — a small billing app we built and deliberately misconfigured — shown unlocked, exactly as an owner sees it after paying: every finding with its evidence and the fix. On your own scans the scoreboard, informational notes and site profile are free; the negative findings are the $50 unlock.
- Add a row-level-security policy that restricts SELECT to the owning/authorized user.
- Revoke the anon role's read grant on the table.
- Verify the fix by querying the endpoint anonymously and confirming zero rows are returned.
- Treat the exposed credential as compromised and rotate/revoke it now in your Supabase project's API settings (rotate the service_role key).
- Remove the secret from all client-visible code, bundles, and source-map/asset files; if it was committed, purge it from git history too.
- Move the call that needs it behind a server-side proxy or serverless function so the secret never reaches the browser.
- Add automated secret scanning (pre-commit + CI) so a privileged key can't ship to the client again.
- Add a row-level-security policy that restricts SELECT to the owning/authorized user.
- Revoke the anon role's read grant on the table.
- Verify the fix by querying the endpoint anonymously and confirming zero rows are returned.
- Fetched and rendered the homepage and its bundles
- Probed the Supabase PostgREST API — 2 tables answered anonymous reads
- Classified every key in the bundle by role (public anon vs privileged service_role)
- Checked response-security headers, object storage and email-spoofing records
Strictly passive — no data was modified. Evidence is redacted to prove each finding without exposing the live secret.
What we’re built to scan
HatTest is sharpest on apps that reach a database or API straight from the browser or a mobile client — the setups where one backend misconfiguration leaks in public. It runs on any website; the depth just depends on the stack.
- Apps on a backend-as-a-service — Supabase, Firebase, PocketBase, Appwrite, AWS AppSync, Nhost
- Apps built with AI tools like Lovable, Bolt, v0 or Cursor — what we check
- Single-page apps (React, Vue, Angular, Svelte) calling a public REST or GraphQL API
- Mobile or desktop app backends — add the API base as a property, no web page needed
- WordPress & CMS sites — known-CVE version and plugin checks
- Any site — leaked keys in JS, exposed files (.env, .git), and open S3 / GCS / Azure buckets
- Static & JAMstack front ends built against a hosted backend
Sites fully behind a login wall or an aggressive bot-wall may come back as an honest “scan incomplete” — we never guess a verdict we couldn’t measure.
Every confirmed finding shows the exact artifact an attacker would see.
Public-by-design keys and endpoints are never flagged — only real, privileged exposure.
No repo, no agent, no access. We never run your code — or anyone’s.
Pricing
Create an account, verify your domain, and scan for free — pay only to reveal the negative findings, and only when a scan has some. Scale up to bulk reports, weekly monitoring, or authenticated deep testing when you’re ready.
- Scan any domain you own — up to 5 free scans a day
- Passive recon + an anonymous-role backend check
- Full severity scoreboard on every scan
- Informational findings + full site profile
- Every High / Medium / Low finding, with evidence
- A plain-English fix for each
- Pay only when a scan has findings — verified owner only
- Buy in bulk: 5 for $200, 10 for $350 (to $35 each)
- Launch offer: your first report is free — applied automatically at your first unlock (code freescan)
- Re-scanned automatically every week (4 scans a month)
- Every report included free — nothing to unlock
- See what changed since the last scan — catch a new High after a deploy
- ≈ $25 per scan — the cheapest way to scan
- Authenticated, per-user access testing (BOLA)
- Signs in as two test accounts you create in your own app
- Proves whether one logged-in user can reach another’s data
- Pay only when there’s a finding — a clean result is free