Decloak - Web security intelligence

Product details
AgnidhraC

Verified purchaser

Deals bought: 5Member since: Apr 2025
5 stars
5 stars
Aug 29, 2026

Great potential, but it needs more control and polish. They are working hard on the improvements I mentioned below. Changed my rating cause they are awesome.

I bought Decloak today, specifically the Enterprise deal, because I genuinely like what you're building and want this product to succeed.

For context, I work in penetration testing and digital forensics, so I'm probably looking at Decloak differently from the average AppSumo user. I'm not expecting automation to replace a manual pentest, but I want this to become useful professionally.

The idea is great: putting reconnaissance, attack-surface discovery, DAST and tools like Nuclei, sqlmap, ffuf, Dalfox and jwt_tool behind one platform has a lot of potential.

My main request is more control over what happens underneath. Right now Decloak sometimes feels like a front-end around open-source tools running in the background. Good foundation, but professional pentesting can't be a black box.

I'd like granular control over requests/sec, concurrency, crawl depth, maximum URLs, timeouts, retries/backoff, User-Agent, custom headers, cookies/authentication, HTTP methods, URL/regex exclusions, passive vs active testing and which checks/tools run.

Requests/sec is especially important. If I'm testing behind Cloudflare/WAF or aggressive rate limiting, I need to be able to slow the scan down. I'd rather run at 2–5 requests/sec and get a complete assessment than have the scanner get blocked halfway through. Safe/Balanced/Aggressive/Custom scan profiles would be great.

I'd also like live visibility: current phase/tool, requests/sec, URLs tested, errors, 429/403 responses and skipped checks.

There is also a potential Enterprise plan issue I ran into today. The AppSumo Enterprise deal says 15 scans per domain per day, but when I started a second scan against the same domain with a different URL/path, I was told I could only AI scan that domain once per day. If the actual restriction is one scan per root domain/day, the offer should make that clear. If not, this needs fixing.

Finding quality is another area I'd improve. My scan crawled 76 pages and produced 1,706 findings across 103 groups. Good coverage, but better deduplication would make results more useful. If HSTS affects 83 pages, I'd rather see one HSTS finding affecting 83 URLs than essentially the same finding repeated 83 times. Same for CSP, cookies, TLS, DNS, etc.

Please distinguish detected, potential and confirmed vulnerabilities. Detecting a software version isn't the same as proving exploitation. Decloak already does this in places, such as reporting when sqlmap/Dalfox had nothing to test, and I'd like that approach used consistently.

For each finding, show evidence: HTTP request/response, payload, parameter, relevant headers, response difference, validation result, reproduction steps and screenshots where useful. Pentest-Tools is a good benchmark.

I'd also like authenticated testing: login forms, cookies, Bearer/JWT, custom headers, recorded browser sessions, session refresh/CSRF and different user roles.

Reporting needs serious improvement.

**The report is the deliverable.**

Right now the PDF feels like a screenshot/render of the webpage exported to PDF, rather than a professional pentest report. I want a client-ready report: executive summary, scope, methodology, scan configuration, risk summary, detailed findings, evidence, request/response, screenshots, reproduction steps, remediation, CVE/CWE/OWASP references and affected assets.

Please fix raw Markdown and cut-off text. The AI itself isn't necessarily the problem; the final UI and report look AI-generated. Use a proper reporting/document-generation system rather than printing the web UI. Pentest-Tools is a useful benchmark for this.

The UI needs a rethink. It feels like an AI generated front-end around open-source tools rather than a mature security workbench.

I'd prefer:
Target → Scope → Scan Profile → Configuration → Execution → Findings → Validation → Report

Keep it simple, but make it feel precise and professional, not like an AI SaaS dashboard.

Longer term, I'd love to see finding lifecycle/false positives, retesting, scan comparison, finding history, comments/evidence, manual findings, severity overrides, projects/workspaces, scheduled/regression scans, custom Nuclei templates/wordlists/payloads/checks, API/webhooks, JSON/CSV/XLSX/DOCX/SARIF exports, Jira/GitHub/GitLab/DefectDojo/CI/CD integrations and internal/private-network scanning agents.

Please also publish a public roadmap with feature voting.

I don't expect Decloak to become Pentest-Tools overnight or copy them. But Pentest-Tools is a useful benchmark for the level of scan control, authenticated testing, validation, evidence and professional reporting that serious users eventually expect.

Overall, I think the foundation is genuinely promising. I'm pointing these things out because I bought Enterprise today because I want this product to succeed, and I'd love to see Decloak grow from an automated scanner into something professional pentesters can actually rely on.

Founder Team
StephenGray_Decloak

StephenGray_Decloak

Aug 29, 2026

Hello,

Thank you for such detailed feedback. This is the exact reason why we wanted to launch on AppSump - to get feedback from experts in their areas.

You are right that Decloak is aimed at providing advanced tools and data for non-technical or non-expert users and business owners. That's one of the barriers we want to break down, allowing access to this sort of data without needing to be an expert (or have the huge enterprise budgets some of those tools demand!)

But I really like some of the ideas you have presented here. I've identified a few that we will review as a team and try to work on, then I'd love to contact you to give them a go, as you are coming from that more technical / industry perspective.

The first one we'll work on is an "Expert Mode" toggle when you onboard, which will surface more controls when you setup a scan, and potentially surface more information DURING a scan too.

There are also a few things that we already do from your feedback like being able to triage items as false positives, re-scanning the same domain, comparing the findings of two scans, scheduled scans.

And yes, we do have a list of features on our roadmap that we're constantly reviewing, we'll see if we can add this to the logged in area for voting and potential comments.

On the issue of rate limiting, I can explain this. There are a few limits based on what the activity actually does to the target, and how expensive/risky it is. Regular scans are 15/day on enterprise, active testing is 3/day and AI pentesting is 1/day per domain. This is scaled this way due to potential consequences on the target, and also because AI pentesting has the potential to spin up dozens of secure sandboxes per target that can ramp up our costs quickly! We have however improved the messaging to make this clearer now thanks to your feedback.

We think of the limits as "reading" (cheap, generous) > "poking, non-destructively" (moderate) > "actually attacking, with real infra cost" (deliberately scarce)"

But definitely open to feedback here too if you feel this is too restrictive.

Thanks!

Helpful?
6
Share
Ratings