Decloak - Web security intelligence Reviews

5.0

5.00 stars
5.00 stars
3

Taco ratings

3
0
0
0
0
Showing 1 - 3 of 3 reviews
jeremy8939

Verified purchaser

Deals bought: 10Member since: Aug 2026
5 stars
5 stars
Sep 30, 2026

As a Former White Hat Hacker, This Is One of the Most Impressive Security Tools I’ve Seen on AppSumo!

I’m coming at Decloak from a somewhat different perspective than the average user. I’m a technology industry professional and former white hat hacker, so I’ve spent enough time around security testing to know the difference between a scanner that spits out a pile of generic warnings and something that actually gives you useful intelligence.
After putting Decloak through its paces across several of my own production sites and applications, I’m extremely impressed.

First, an important qualification: Decloak does not replace a skilled professional penetration tester, nor should any automated platform claim to. Security findings can be contextual, false positives exist, and a human tester who understands an application’s architecture, business logic and threat model can investigate things automation cannot. But professional penetration testing can also cost thousands or tens of thousands of dollars. For the price point here, the breadth and depth of what Decloak provides is frankly remarkable. Its AI-directed crawler actually determines where to investigate rather than simply walking a static sitemap. One of my scans crawled 76 pages and analyzed hundreds of network requests.

The reporting is excellent. You get an immediately understandable A-F score and severity breakdown, but you can drill into individual findings, affected locations, evidence and remediation guidance. Reports also include CVE/CWE/OWASP references and compliance mapping. The exported PDFs are genuinely useful documents rather than an afterthought. My reports included mappings for SOC2, ISO, NIS2, DORA, LGPD and PCI, along with DNS/TLS analysis, platform security and other appendices.

DAST/Active Testing is where things get considerably more interesting. Instead of only analyzing what the application exposes passively, Decloak performs non-destructive probes for things such as forced browsing, CORS configuration, HTTP methods, reflected input, postMessage behavior, Subresource Integrity and sensitive-data patterns. That distinction matters because there is a huge difference between saying “this configuration might be risky” and actually investigating the behavior.

AI Pentesting takes it another step further. Decloak can perform exploitation-confirmation testing using sandboxed security tools including sqlmap, dalfox, ffuf, nuclei and jwt_tool. It also performs API discovery/testing for REST, GraphQL and SOAP endpoints. AppSumo’s listing correctly distinguishes this from DAST: active testing looks for plausible security signals, while AI Pentesting attempts sandboxed exploitation against confirmed findings, with independent scoring.

I also really like the third-party and supply-chain visibility. Modern applications make requests all over the place, and Decloak inventories those domains, analyzes dynamically loaded scripts and checks external domains for reputation signals. This is increasingly important with modern SaaS and AI-built applications.

Another standout is the platform-specific analysis. Decloak is looking for common problems involving platforms not merely applying a generic checklist to every website.

Before writing this review, I also went back through the other AppSumo feedback and the founder’s updates. What impressed me almost as much as the product is the development velocity. Issues and shortcomings users raised appear to have been systematically addressed: reporting was rebuilt, findings were consolidated to reduce duplicate noise, confidence levels were added, coverage became more explicit, and the reporting now distinguishes Detected, Potential and Confirmed findings. The founder is also incredibly responsive, which matters enormously to me when buying an early-stage lifetime deal.

If I could request one improvement, it would be context-aware feedback on findings. I’d love to click a potential finding and explain why it is intentional or not applicable in my architecture, then have Decloak retain that context for subsequent scans and AI analysis. Security is inherently contextual, so allowing the human operator to teach the system why a particular finding is a non-issue would make an already impressive platform even better.

Overall, this feels less like another automated website scanner and more like a growing security workbench. Between agentic crawling, DAST, AI pentesting, API discovery, third-party analysis, remediation guidance, compliance mapping and genuinely professional reports, there is an extraordinary amount here.

For developers, agencies, SaaS operators and technology companies that cannot justify having a professional pentester continuously testing every release, Decloak fills an extremely valuable gap at a fraction of the cost.

Easy 5 tacos from me. 🌮🌮🌮🌮🌮

Founder Team
StephenGray_Decloak

StephenGray_Decloak

Sep 30, 2026

Hi Jeremy, thank you.

As a founder I couldn't ask for better feedback. We're a small team working hard on the product and this review means a lot.

We will continue to be quick to respond to feedback and stay on top of any issues!

Stephen.

Helpful?
0
Share
user901

Verified purchaser

Deals bought: 193Member since: Sep 2021
5 stars
5 stars
Sep 6, 2026

I’ve started testing the product and have been very impressed so far!

I’ll share a more detailed review soon, but I wanted to offer my first impression: I really love this tool! Thank you for shipping it to us!

Founder Team
StephenGray_Decloak

StephenGray_Decloak

Sep 6, 2026

Hello!

Thank you for the feedback!

We have a long list of features and improvements, we want to keep improving Decloak to provide as much value as possible.

These are now all viewable on the members-only feature roadmap you can see and make suggestions on.

Thanks again,
Stephen.

Helpful?
1
Share
AgnidhraC

Verified purchaser

Deals bought: 5Member since: Apr 2025
5 stars
5 stars
Aug 29, 2026

Great potential, but it needs more control and polish. They are working hard on the improvements I mentioned below. Changed my rating cause they are awesome.

I bought Decloak today, specifically the Enterprise deal, because I genuinely like what you're building and want this product to succeed.

For context, I work in penetration testing and digital forensics, so I'm probably looking at Decloak differently from the average AppSumo user. I'm not expecting automation to replace a manual pentest, but I want this to become useful professionally.

The idea is great: putting reconnaissance, attack-surface discovery, DAST and tools like Nuclei, sqlmap, ffuf, Dalfox and jwt_tool behind one platform has a lot of potential.

My main request is more control over what happens underneath. Right now Decloak sometimes feels like a front-end around open-source tools running in the background. Good foundation, but professional pentesting can't be a black box.

I'd like granular control over requests/sec, concurrency, crawl depth, maximum URLs, timeouts, retries/backoff, User-Agent, custom headers, cookies/authentication, HTTP methods, URL/regex exclusions, passive vs active testing and which checks/tools run.

Requests/sec is especially important. If I'm testing behind Cloudflare/WAF or aggressive rate limiting, I need to be able to slow the scan down. I'd rather run at 2–5 requests/sec and get a complete assessment than have the scanner get blocked halfway through. Safe/Balanced/Aggressive/Custom scan profiles would be great.

I'd also like live visibility: current phase/tool, requests/sec, URLs tested, errors, 429/403 responses and skipped checks.

There is also a potential Enterprise plan issue I ran into today. The AppSumo Enterprise deal says 15 scans per domain per day, but when I started a second scan against the same domain with a different URL/path, I was told I could only AI scan that domain once per day. If the actual restriction is one scan per root domain/day, the offer should make that clear. If not, this needs fixing.

Finding quality is another area I'd improve. My scan crawled 76 pages and produced 1,706 findings across 103 groups. Good coverage, but better deduplication would make results more useful. If HSTS affects 83 pages, I'd rather see one HSTS finding affecting 83 URLs than essentially the same finding repeated 83 times. Same for CSP, cookies, TLS, DNS, etc.

Please distinguish detected, potential and confirmed vulnerabilities. Detecting a software version isn't the same as proving exploitation. Decloak already does this in places, such as reporting when sqlmap/Dalfox had nothing to test, and I'd like that approach used consistently.

For each finding, show evidence: HTTP request/response, payload, parameter, relevant headers, response difference, validation result, reproduction steps and screenshots where useful. Pentest-Tools is a good benchmark.

I'd also like authenticated testing: login forms, cookies, Bearer/JWT, custom headers, recorded browser sessions, session refresh/CSRF and different user roles.

Reporting needs serious improvement.

**The report is the deliverable.**

Right now the PDF feels like a screenshot/render of the webpage exported to PDF, rather than a professional pentest report. I want a client-ready report: executive summary, scope, methodology, scan configuration, risk summary, detailed findings, evidence, request/response, screenshots, reproduction steps, remediation, CVE/CWE/OWASP references and affected assets.

Please fix raw Markdown and cut-off text. The AI itself isn't necessarily the problem; the final UI and report look AI-generated. Use a proper reporting/document-generation system rather than printing the web UI. Pentest-Tools is a useful benchmark for this.

The UI needs a rethink. It feels like an AI generated front-end around open-source tools rather than a mature security workbench.

I'd prefer:
Target → Scope → Scan Profile → Configuration → Execution → Findings → Validation → Report

Keep it simple, but make it feel precise and professional, not like an AI SaaS dashboard.

Longer term, I'd love to see finding lifecycle/false positives, retesting, scan comparison, finding history, comments/evidence, manual findings, severity overrides, projects/workspaces, scheduled/regression scans, custom Nuclei templates/wordlists/payloads/checks, API/webhooks, JSON/CSV/XLSX/DOCX/SARIF exports, Jira/GitHub/GitLab/DefectDojo/CI/CD integrations and internal/private-network scanning agents.

Please also publish a public roadmap with feature voting.

I don't expect Decloak to become Pentest-Tools overnight or copy them. But Pentest-Tools is a useful benchmark for the level of scan control, authenticated testing, validation, evidence and professional reporting that serious users eventually expect.

Overall, I think the foundation is genuinely promising. I'm pointing these things out because I bought Enterprise today because I want this product to succeed, and I'd love to see Decloak grow from an automated scanner into something professional pentesters can actually rely on.

Founder Team
StephenGray_Decloak

StephenGray_Decloak

Aug 29, 2026

Hello,

Thank you for such detailed feedback. This is the exact reason why we wanted to launch on AppSump - to get feedback from experts in their areas.

You are right that Decloak is aimed at providing advanced tools and data for non-technical or non-expert users and business owners. That's one of the barriers we want to break down, allowing access to this sort of data without needing to be an...

Helpful?
6
Share