vibe'nscanFrom vibe to verifiedBeta
How it worksReportsPricingWall of LoveBlogBillingDashboard

How It Works

What actually happens to your repo after you click scan.

The Deep Scan runs deterministic SAST first, layers multi-provider LLM reasoning on top, then fact-grounds every claim against your real files — all streamed live to your browser.

View GitHub App Permissions

Free Recon

Public URL · deterministic only

Deep Scan

Full repo · SAST + LLM + grounding

Three-Layer Engine

Three phases. One report. Zero guesswork.

Each phase builds on the last, so you get deterministic precision first, then AI-powered insight, then real-world visibility checks.

Phase A

Deterministic SAST

Instant. Zero hallucination. 100% reproducible.

Regex and AST-based detectors run over your codebase in seconds. No LLM involved. Finds hardcoded secrets, exposed .git directories, debug endpoints, missing auth checks, and 30+ other patterns with 100% reproducibility.

Phase B

LLM Reasoning

Finds business-logic flaws no regex can catch.

Context-aware analysis over your actual files. Identifies Stripe logic flaws, missing balance checks, improper error handling, and fragile state management. Every claim is fact-grounded with file paths and line numbers.

Phase C

Performance & SEO

Client-side rendering detection, Lighthouse checks.

Detects whether Google and AI search engines can see your content. Checks metadata, canonical tags, structured data, heading hierarchy, and sitemap signals. Flags client-side rendering that makes your app invisible to search.

The Pipeline

Seven stages between click and confidence.

Each stage is observable in the live progress feed. This is the exact path every Deep Scan follows — from read-only clone to a scorecard your stakeholders can actually read.

Stage 01

Read-only clone, ephemeral sandbox

The GitHub App pulls a shallow clone into a throwaway sandbox that is wiped the moment the scan ends. We read your code; we never mutate it.

Never mutates your repo · destroyed in a finally block

Stage 02

Deterministic SAST, under 30 seconds

Bearer and an AST engine run 30+ detectors — secrets, RBAC, IDOR, SEO, Core Web Vitals, dead code — with framework-aware false-positive suppression.

100% reproducible · deterministic · zero hallucination

Stage 03

Your whole codebase, tokenized

A tiktoken bundler prioritises the files that matter and fits them into a real context budget — up to 1M tokens and 250 files — so the model reasons over your actual code.

Critical files · API routes · config · call graph

Stage 04

Multi-provider LLM reasoning, streamed live

A reasoning pass over your real files finds business-logic flaws no regex can catch — Stripe logic, missing balance checks, fragile state — while a second call assesses your architecture.

DeepSeek → z.ai → Chutes → OpenRouter · automatic failover

Stage 05

Every claim checked against real files

Each candidate finding is verified against the sandbox: does the file exist, does the snippet match, is the line relevant? If the model invents a problem, it dies here.

Zero hallucinations reach your report

Stage 06

An independent verifier kills false positives

A second model runs a 3-pass semantic check, so findings that pass grounding but are semantically wrong never ship. Two stages of defence, not one.

Grounding + verification = two layers of defence

Stage 07

A 14-factor score, not a wall of warnings

Findings fold into a Production Readiness score out of 100 and an executive launch-risk summary. An integrity check refuses to ship an incomplete report.

Stored to Postgres · delivered via WebSocket + email

System Architecture

One pipeline. Every layer observable.

From the read-only clone to the integrity-checked report, every stage is deterministic where it can be and AI-augmented where it must be — with fact-grounding and verification guarding the boundary.

Deep Scan · end-to-end

Why You Can Trust It

Every claim, checked against your actual code.

Most AI auditors ship whatever the model says. We don't ship hallucinations — three guardrails make sure of it.

Fact-grounding

Every LLM candidate is checked against your real files before it can become a finding. No file, no match, no finding.

Two-stage verification

Grounding catches fabricated evidence; an independent 3-pass verifier catches findings that are technically present but semantically wrong.

Graceful degradation

If a provider goes down mid-scan, we fail over to the next. If the whole AI layer fails, we ship deterministic-only partial results instead of crashing your scan.

Under The Hood

Battle-tested infrastructure.

No magic, no black boxes. The Deep Scan is assembled from proven, observable components.

Hono

API edge layer

BullMQ + Redis

Job queue + event replay

PostgreSQL · Supabase

Reports & accounts

GitHub App

Read-only repo access

Bearer CLI + js-x-ray

SAST engines

js-tiktoken

Real token budgeting

Multi-provider LLM

DeepSeek · z.ai · Chutes · OpenRouter

WebSocket + SSE

Live scan streaming

Cloudflare R2

Asset storage

Stripe

Billing & credits

Brevo

Scan-complete email

Railway

Orchestrator hosting

FAQ

What happens before we scan your app?

Does the free scan use LLMs?+

No. Free Recon is a deterministic public URL audit. It checks exposed .git folders, debug endpoints, headers, crawlability, visible SEO signals, and obvious deployment risks without using LLMs.

Why do you need GitHub access for the full scan?+

A URL can only reveal public symptoms. The full production audit needs to inspect the repository to find file-level problems, 14-Factor violations, hardcoded secrets, fragile auth logic, unsafe payment flows, and bad code patterns.

What GitHub permissions are required?+

The GitHub App is designed for read-only repository analysis. Users can inspect the permission screen before installation and select only the repositories they want audited.

Can I paste the report back into Lovable, Cursor, bolt.new, or v0?+

Yes. Paid audits include safe prompt packs: structured remediation briefs that explain what to inspect, where to inspect it, how to validate the change, and which fixes need developer review.

Is vibe'nscan a replacement for a human security audit?+

No. It is a production-readiness layer for AI-built apps. It catches obvious and common failure modes before launch, but high-risk systems should still receive specialist security review.

See it run on your repo.

Install the read-only GitHub App and watch the Deep Scan move through every stage — live.

Audit Your App NowView GitHub App Permissions
vibe'nscan

vibe'nscan — The Grown-Up Version of AI Development.

Built for the 36 million vibe-coded apps. One scan, one saved business at a time.

How It WorksManifestoTermsPrivacy PolicyCookie PolicyRefund PolicySecurityWall of Love

Celebrating human endeavour. Building something damn good — and production-ready.

Operated by - gradient3 tech OÜ

All rights reserved.