Resources
Guides written to be used, not to rank
Each guide answers one concrete question. We add one when a check deserves a page of its own.
- Guide4 minute read
HTTP security headers: what to send and how to check them
A practical guide to CSP, HSTS, cookies and CORS, with ways to check them from outside the code.
Published
- Guide4 minute read
Secrets in Git history: why deleting a key isn't enough
Deleting an API key from your code doesn't remove it from git history. What to do to rotate it and clean the repository.
Published
- Guide11 minute read
A security checklist to work through before you launch
Twenty-two checks across secrets, access control, payments, dependencies and deployment configuration, with what to do about each one when the answer is no.
Published
- Guide9 minute read
How to review the security of an app you built with AI
The five categories of mistake that show up most often in code written quickly with an AI assistant, why they happen, and how to check for each one yourself.
Published
Also useful
Pages that answer a specific question
Not guides, but the places people actually end up looking.
- What happens during a scan, stage by stageIncluding what we do with your repository and when it is deleted.
- How we protect your data, and what we have not built yetThe controls that exist today, separated from the ones that are planned.
- The eight categories of check, in detailWith the tool behind each one named.
Or stop reading and run a scan
A checklist tells you what to look for. A scan tells you what is actually there.