Skip to content

The public assessment costs $0 AUD, and the PDF arrives within 24 hours.

Start free assessment

Free public app launch and security assessment

Built an app with AI? Get a free launch and security assessment within 24 hours

A senior engineer manually checks the public app with external tools across visual quality, accessibility, performance, SEO, AEO and GEO, public security controls and visible architecture. You get a plain English PDF with evidence, priorities and next actions, plus an optional 15 minute walkthrough.

Public staging or live pages only. No login, source code or payment details needed. Made with Cursor, Lovable, Replit, Bolt, v0, Base44, Claude Code or similar.

Paid prelaunch review after the free assessment
“…a written report so precise that our own independent verification confirmed every finding, line for line.
Stacey BlackwellDirector, BuildScore

SMB1001 Silver

Level 2, CyberCert certified.

About the certifier

Some businesses that trust VibeZero

Before the public app becomes business critical

Use the assessment before launch, after a run of fast changes or before customers, staff or investors begin relying on the app.

  • Preparing a public staging build for launch
  • Checking a live app after rapid feature work
  • Reviewing the public surface before collecting data or payments

In Veracode's 2025 benchmark of more than 100 language models, 45% of the tested code generation tasks introduced a known security flaw. That does not mean your app is unsafe. It is a reason to check what was shipped before other people rely on it. Read the Veracode report.

A PDF your developer can act on

We put the important findings first, show the evidence and recommend the next check or fix. Anything the public view cannot establish stays marked as unknown. You can act on the PDF yourself or ask us to scope a separate paid review if deeper access would be useful.

Illustrative example

See how we present the work

These four pages come from a synthetic full technical audit and show how we present priorities, evidence and actions. The free assessment is narrower and covers the public, unauthenticated app only.

Preview 1 of 4

This is a synthetic full audit format sample, not a client report or certification. The free assessment does not include source code, logged in areas or private infrastructure. The full PDF is not published for download.

One security example from the PDF

Evidence checked before delivery

Verified public finding

Production source map is publicly reachable

Priority
Review before launch
Evidence state
Verified from the public URL
Why it matters
The file can reveal application structure and client side code that is harder to inspect in the bundled build.
Next action
Disable public production source maps or restrict access. Deploy again, then verify that the path no longer resolves.
Boundary
This finding does not establish anything about database permissions, server side secrets or access after login.

External tools gather the evidence. We check the context, remove false positives and state where the public view stops. The delivery email includes the optional 15 minute walkthrough link.

From public URL to assessment within 24 hours

External tools collect repeatable evidence. VibeZero reviews the app, checks the context and writes the assessment before it reaches you.

  1. Request

    Send the public URL

    Use a public staging or live URL that opens without a login. Tell us what concerns you most if you want to.

  2. Review

    A senior engineer checks the public app

    We work through the six public facing areas with external tools, then check the context and remove noise.

  3. Delivery

    The assessment arrives within 24 hours

    You receive the findings, evidence, limits and next actions, plus a link to book the optional 15 minute walkthrough.

What the manual review covers

We inspect the pages and states that an ordinary visitor can reach without signing in. Every finding stays within that public view.

Six public facing areasNo credentials or private access
Experience

Visual clarity and responsive behaviour

We work through the public pages at desktop and mobile widths, checking hierarchy, consistency, content clarity, layout breaks and the interaction states a visitor can reach.

Accessibility

Accessibility and form behaviour

We check keyboard use, focus order, labels, contrast, semantic structure and public form and error states that do not require us to send data.

Performance

Loading and page performance

We inspect page weight, loading behaviour, image delivery, render delays and other public signals that can make the app feel slow or unstable.

Findability

Search and answer visibility

We inspect titles, metadata, indexing directives, headings and structured data. This covers the public evidence behind SEO, AEO and GEO.

Security

Public security controls

We check HTTPS and TLS, browser headers, framing controls, public cookie settings, exposed files, source maps and credential patterns visible in public assets.

Architecture

Public architecture signals

We review public routes, client side JavaScript, dependency clues, platform exposure, diagnostics and error behaviour that reveal how the public app is assembled.

We do not guess at private systems

The assessment stops where public access stops. We do not sign in, accept test credentials, enter a repository or inspect private hosting, cloud, database or application settings.

  • The codebase, repository history and private dependencies
  • Logged in screens, account roles and authenticated workflows
  • Authenticated APIs, hosting and cloud infrastructure
  • Database, storage and server side permissions
  • Secrets, environment variables and private configuration
  • Business logic, payments and private data flows

The assessment stands on its own. If a public finding raises a question that needs private access, we state the limit rather than guessing. If you want us to go further, we can scope that work separately after delivery. An area outside scope is not evidence that it is safe or unsafe.

What to know before you send the URL

The assessment is useful because its scope is clear. You will know what we checked, what we could not reach and where the evidence stops.

Why is the assessment free?

The scope is limited to public, unauthenticated evidence. That keeps the work bounded while still giving you a useful first view across the public app. If a finding needs deeper access, we explain why. The PDF stands on its own, and any later work is a separate decision.

What happens to the details I submit?

We use your name and company to manage the request, the URL to review the public app and your email to send the result and one possible follow up about the findings. We do not send these details or your concern text to analytics or advertising platforms. If Google supplied an advertising click identifier, we may store it with the request so we can measure the campaign. We do not add you to a marketing list.

Is it safe for a live application?

We make read only, non destructive requests to public pages and files. We do not sign in, enter data, submit forms, change data or attempt to exploit a finding.

Can you review pages behind a login?

Not as part of this assessment. The codebase, logged in workflows, authenticated APIs and private infrastructure stay outside scope. We do not ask for credentials or treat those areas as checked.

Do I need to buy anything after the assessment?

No. The free PDF stands on its own. If you want us to inspect code, authenticated workflows or private infrastructure, we can scope a separate paid review after delivery. You decide whether that work happens.

Who performs the review?

A senior VibeZero engineer runs the external tools, reviews the public app at desktop and mobile widths, checks the evidence and writes the PDF. The result is not an unreviewed scanner export.

Does the app need to have been built with AI?

No. The same public checks are useful for conventionally built apps. The offer is aimed at teams shipping quickly with tools such as Cursor, Lovable, Replit, Bolt, v0, Base44 or Claude Code, but the build method does not determine eligibility.

What if the URL cannot be reached?

We will email you and ask for a working public URL. The 24 hour delivery period starts once the page opens without a login, password or private preview token.

Can I go straight to a paid app audit?

Yes. If you already need codebase, logged in workflow or private infrastructure testing, you can ask for a paid app audit without completing the free assessment first.

Does 24 hours mean calendar hours?

Yes. The PDF is due within 24 hours of a successful request with a working public URL. If we cannot honour that window, we will pause new requests rather than promise a delivery time we cannot meet.

Is this a penetration test or certification?

No. It is an external readiness assessment of the unauthenticated public surface. It does not certify the app, codebase, logged in workflows or private infrastructure.

Know what deserves attention before launch

A public staging or live URL is enough. No credentials, codebase access or payment details are needed.

Send the public URL now. The free PDF arrives within 24 hours.

Get my $0 assessmentThe assessment costs $0 AUD and covers public, unauthenticated pages only. It arrives within 24 hours, with no obligation to continue.