A review that shows its evidence and states what it could not check.
Small teams and solo builders shipping a web app, a bot or an AI feature without a security team of their own. You want an independent check before real users arrive, and you want to know exactly what that check covered.
Squall only reviews targets you own. Before anything runs, you prove control of the domain or repository and sign a written scope that names every target and what may be done to it.
Add a DNS TXT record we give you to the domain, or grant read access to the repository. Nothing runs until one of these is in place.
A short written scope lists every hostname and repository, the checks permitted, and the dates. Anything outside it is refused before a tool starts.
Squall runs the checks inside the scope, read-only and at human pace. Every step keeps its raw output so each finding can point at the line, header or host that proves it.
A person reads everything flagged and decides: confirmed, or cleared with a written reason. Scanner output never goes to you unread.
The report is delivered to you privately. It is never published, and findings are never shared with anyone outside the engagement.
The review re-runs each night on new commits. You hear from us only when the findings change.
Every finding with its evidence, why it matters and how to fix it. A finding without proof is labelled unverified and says what proof is missing.
Available now
Each check that passed, stated. Each thing the review could not reach, named, with the reason.
Available now
Findings in severity order, each with the specific change that closes it.
Available now
Ship, ship with fixes, or hold, with the three findings that decided it. Written for the person who signs off.
Partial: a short summary opens the report today; the standalone page is being built.
On the next run: what was fixed, what is new, what is still open.
Partial: each run records whether findings changed since the last; the item-by-item comparison is being built.
Live means it runs on real targets now. Partial means part of it runs; the gap is stated. Planned means designed and not yet in service. Planned checks are not sold as part of a review.
| Capability | Status | What that means | Aligns to |
|---|---|---|---|
| Application security review | Live | Secrets in git history, dependency CVEs, static analysis, response headers and content security policy, the hosts your shipped bundle can talk to, what the app leaves in the browser. Runs per release and nightly. | OWASP ASVS, OWASP Top 10 |
| Vulnerability intelligence | Partial | A daily feed of new CVEs, known exploited vulnerabilities and exploit likelihood is live. Matching that feed against your own dependency list is planned; today dependency CVEs come from the application review. | OWASP Top 10 |
| Account and cloud posture | Partial | Read-only checks on the accounts that can publish your app: deploy-token expiry, repository visibility, branch protection. A full cloud account and host configuration review is planned. | NIST SP 800-115 |
| Reporting and evidence | Partial | Technical report with evidence per finding and the passed and not-covered lists are live. The one-page verdict and a downloadable evidence bundle are planned. | NIST SP 800-115 |
| External attack surface | Planned | What the internet can see of your domain: subdomains, open ports, exposed services. Method written, not yet run on any target. | NIST SP 800-115 |
| AI and LLM testing | Planned | Whether a bot or AI feature can be steered by planted instructions, made to leak data or pushed past its limits. Method written, tools not yet in service. | OWASP Top 10 for LLM Applications |
| Standards and regulatory mapping | Planned | Findings carry CWE and OWASP identifiers today. Mapping each finding to the regulatory clauses it touches is planned. | OWASP ASVS |
| Detection validation | Planned | Whether your monitoring would notice an attack in progress. Not built. | NIST SP 800-115 |
Read how the application review runs, step by step, in the published method.
Squall is read-only. It recommends; it changes nothing in your code, your deployment or your accounts. Findings stay private to you and are never published.
Tell us what you are shipping, the domain or repository, and when you plan to release. We reply with the ownership step and a draft scope.