TrueTag

Pre-launch trust infrastructure for AI-built software

Find what could go wrong before your users do.

Connect a repository or a live URL and get an evidence-backed review of security, privacy, accessibility, AI risk, and legal readiness — explained in plain English, with exact fixes.

TrueTag identifies common launch risks. It does not certify that an application is secure or legally compliant, and it is not a substitute for penetration testing or legal advice.

Repository scan

Exposed secrets, vulnerable dependencies, missing auth checks, unsafe Supabase/Firebase/Stripe configuration — with file and line evidence.

Live application scan

TLS, security headers, cookies, trackers, exposed files, legal pages, and automated WCAG 2.2 AA accessibility checks. Always non-destructive.

AI security review

Prompt-injection exposure, unsafe model-output handling, excessive agent permissions, and secrets in prompts, aligned with the OWASP LLM Top 10.

Privacy & legal readiness

A data-practice map built from what your app actually does, gap analysis, and draft Privacy Policy, Terms, and disclosures generated from verified facts.

Remediation that fits your workflow

Every finding ships plain-English steps plus copy-paste prompts for Cursor, Claude Code, Lovable, Bolt, Replit, and Windsurf. Rescan to verify fixes.

A verdict you can defend

A scoped launch score with visible limitations: what was scanned, what wasn't, and how confident each finding is. Never a fake 'certified secure' badge.