Security audits for AI-built & fast-moving websites

AI built it.
Probe5 checks it.

AI builders, no-code tools, templates, and rapid custom development can put a site online before anyone reviews its security. Probe5 checks what actually shipped for injection indicators, unsafe configuration, exposed software, session weaknesses, and—when you choose a deeper staging audit—broken access or workflow rules.

AI-built or customStart with one free findingEvidence + fix guidanceVerified authorization
PASSIVE PRE-SCANFREE

See what your builder may have missed.

Enter an AI-built, no-code, template-based, or custom website you are authorized to review. The first passive finding is free—no login, attack payloads, or form submissions.

01Built fast ≠ security reviewed02$10 verified surface audit03Evidence your developer can use04One-time purchase · no subscription

Why people use Probe5

Shipping is easy now. Knowing what slipped through is not.

A polished page does not prove the code behind it handles input, cookies, permissions, or business rules safely. Probe5 gives founders and small teams a focused security review without an enterprise contract or a generic wall of scanner noise.

01 / BEFORE LAUNCH

Catch what speed can hide.

Check for missing browser defenses, exposed software signals, and risky input behavior before ads, users, or investors reach the site.

02 / AFTER EVERY BUILD

Test what actually shipped.

Generated code and deployment defaults can change quickly. Probe5 evaluates the live website rather than trusting a prompt, template, or platform badge.

03 / BEYOND THE PAGE

Check access and workflows.

Advanced staging audits test whether roles, sessions, MFA, KYC state, prices, limits, and repeat actions are enforced by the server—not merely hidden in the interface.

04 / FIX THE RIGHT THING

Give your developer a next move.

Get the affected control, evidence, severity, impact, remediation, and retest criteria instead of a vague score or reusable attack recipe.

Coverage

What Probe5 looks for after the builder says “done.”

Probe5 separates confirmed configuration problems from potential application-layer risks. It never calls a suspicion a proven exploit.

01ACTIVE

XSS reflection

Ownership-verified audits use inert canary markers to identify input that is returned without safe encoding.

02ACTIVE

SQL error behavior

Safe GET-only probes look for database error disclosures and abnormal server responses—never data extraction.

03PASSIVE

HTTPS & headers

TLS use, HSTS, CSP, clickjacking protection, MIME sniffing, referrer policy, and permissions policy.

04PASSIVE

Cookies & forms

Secure, HttpOnly, SameSite, mixed-content, password transport, and cross-origin form-action checks.

05PASSIVE

Exposure clues

Server banners, framework disclosures, generator tags, query surfaces, and missing browser defenses.

06REPORT

Fix plan

Every result includes evidence, severity, and a plain-language remediation step your developer can use.

The safe method

Active testing starts only after you prove control.

Buyers place a one-time verification token on the audited domain. Probe5 then limits tests to public, same-origin GET pages and a small number of query parameters. It does not submit forms, log in, brute-force, extract records, or alter data.

See the $10 report
  1. 01

    Enter the website

    Start with a passive, non-invasive check and see one verified issue free.

  2. 02

    Verify ownership

    Add a text file or meta tag containing the unique token shown in the customer report.

  3. 03

    Run the protected probes

    Probe5 checks safe reflection and SQL-error signals, then produces prioritized remediation.

Authenticated applications

KYC, MFA, authz, and logic need a deeper test.

These controls cannot be judged from a public page. Probe5 scopes them separately after website ownership is verified, using a customer-controlled staging environment, synthetic identities, and purpose-built test accounts. Customers can upload OpenAPI, Swagger, or Postman definitions to generate a sanitized, risk-based application map, then define exact synthetic scenarios with expected access, workflow, invariant, and replay outcomes. Every bounded scenario is reviewed by a human operator before execution.

KYCSTAGING

KYC workflow enforcement

Server-side approval, verification-state integrity, provider-result trust, and synthetic identity safeguards.

  • Server-side KYC approval enforcement
  • Verification sequence integrity
  • Signed provider-result authenticity
MFASTAGING

MFA enforcement & recovery

Second-factor enforcement, secure lifecycle changes, recovery equivalence, retry controls, and session revocation.

  • Second-factor enforcement after primary authentication
  • Step-up enforcement on protected actions
  • Enrollment protected by recent reauthentication
AUTHZSTAGING

Authorization boundaries

Cross-role and cross-account access checks using customer-created test users and synthetic records.

  • Anonymous access to protected operations
  • Object and tenant isolation
  • Horizontal access between synthetic accounts
LOGICSTAGING

Business-logic controls

State transitions, replay, duplicate actions, limits, and workflow invariants defined by the customer.

  • Workflow state integrity
  • Out-of-order state-transition rejection
  • Repeat-action, replay, and idempotency controls
RequiredVerified owner · staging/sandbox · synthetic data

No real identity documents, biometric-bypass research, stolen credentials, OTP interception, uncontrolled brute force, or tests against a third-party KYC provider. After verification, synthetic staging test accounts can be placed in a 24-hour encrypted vault inside the customer report.

Buy Surface Audit — $10
Safe disclosure

Reports identify the affected control, observed impact, severity, fix, and retest criteria. They do not publish bypass sequences, payloads, OTP or recovery details, provider secrets, or reusable exploitation steps.

What you are buying

Choose the security depth that matches what you shipped.

Enter your website, prove you own or control it with a one-time verification token, and receive a private report that explains the findings, supporting evidence, severity, and recommended fixes. Every option is a one-time purchase with no subscription.

01 / SURFACEPublic website checks

The $10 Surface Audit runs safe, bounded checks against verified public pages for XSS and SQLi indicators, TLS, headers, cookies, CORS, forms, exposed software, and session-security signals.

02 / AUTHZAccount and role boundaries

The Authz Audit uses customer-supplied staging accounts to compare roles, unauthorized resource access, and session enforcement.

03 / LOGICDefined staging workflows

The Logic Audit evaluates agreed workflows for state-transition, price, quantity, replay, and duplicate-action errors using synthetic data.

60-DAY REFUND PERIOD
Every Probe5 audit purchase includes 60 days to request a refund.

Contact hello@probe5.com within 60 days of purchase and include the order ID from your Digistore24 receipt.

Surface AuditAUTOMATED
$10one time

XSS/SQLi indicators, redirect checks, TLS, DNS posture, CSP, headers, cookies, CORS, forms, secrets, exposed software, error handling, and session-security signals.

  • XSS and SQLi indicators
  • TLS, headers, cookies, and CORS
  • Forms and exposed-software signals
  • Session-security signals
Buy Surface Audit Secure checkout by Digistore24. Applicable tax may be added. Includes the 60-day refund period described above.
Authz AuditSTAGING
$49one time

Customer-supplied test accounts, role-boundary comparisons, unauthorized resource checks, and session enforcement.

  • OpenAPI, Swagger, or Postman application map
  • Customer-supplied test accounts
  • Role-boundary comparisons
  • Unauthorized resource checks
  • Session enforcement
Buy Authz Audit Secure checkout by Digistore24. Applicable tax may be added. Includes the 60-day refund period described above.
Logic AuditSTAGING
$99one time

Defined workflows, state-transition errors, price/quantity invariants, replay, and duplicate-action testing on staging.

  • Schema-driven endpoint and workflow map
  • Defined staging workflows
  • State-transition errors
  • Price and quantity invariants
  • Replay and duplicate-action testing
Buy Logic Audit Secure checkout by Digistore24. Applicable tax may be added. Includes the 60-day refund period described above.
Scope boundary

MFA and session enforcement are assessed under Authz. KYC workflow enforcement failures are assessed under Logic. Findings are evidence-backed but are not a certification or guarantee of security.

Plain limits

This is a focused surface audit—not a penetration test.

What it can find

Missing defenses, unsafe transport, cookie mistakes, risky form behavior, exposed versions, raw input reflection, and database error indicators on public GET surfaces.

What it cannot prove

Complete absence of vulnerabilities, authenticated-area safety, KYC or MFA enforcement weaknesses, authorization or business-logic flaws, or exploitability of every potential XSS or SQLi signal. Those require the separately scoped staging assessment above.

When to hire a professional

Use a qualified penetration tester for regulated data, payment flows, authenticated applications, compliance certification, or confirmation of a high-severity signal.