
SteelSuit
Scan your site for exposed secrets, bad TLS & weak headers
The numbersIs it still shipping, is it overpriced, where did it land — and what the price is built from.
Security. Launched 1d ago on PeerPush, where it placed #417. Today, it's live, but nothing on the site has changed since we started watching.
Moving right now. The clock only starts when a launch goes quiet.
We check this site every day, ourselves. A founder can post “still working on it” — a claim like that doesn't price. What we price is what we can verify from the outside: evidence, not announcements. The real question isn't “will this be huge?” — it's “will they still be moving in four weeks?”
How the launch is moving on its own board, day by day — the crowd's attention.
A flat line is normal: votes stop within a day or two of launch, on every board. What's unusual — and what actually counts — is a launch that keeps pulling votes long after its day is over.
About
SteelSuit is an external web security scanner built for the people shipping sites without a security team — indie founders, freelancers, agencies, and developers building on AI tools like Cursor, Lovable, Bolt and v0. Point it at a domain you own and it looks at your site the way an attacker would, from the outside: no code access, no installed agent, no repo — just the domain. Under one scan it runs a professional toolchain — port and service detection, Nuclei's 4000+ CVE/misconfig templates, testssl.sh for TLS, subdomain enumeration with takeover detection, content discovery, and JavaScript-bundle secret detection — then aggregates and de-duplicates everything into a single A–F report instead of a wall of raw tool output. What you get: - An A–F security grade with an executive summary and the top issues up front - TLS/SSL, security-header and CSP analysis, with exact misconfigurations called out - Exposed-secret detection in JS bundles (we detect patterns — we never test your keys against the provider) - Subdomain enumeration + takeover detection, content discovery, and Wayback exposure (what the archive leaked: old .git, dev domains, backups) - Email posture — SPF, DKIM, DMARC, BIMI — RFC-correct - Stack-specific fix snippets: not "your CSP is weak" but the exact block to paste into next.config.js, your Cloudflare rules, or nginx - Compliance mapping to PCI DSS 4.0, ISO 27001:2022 and GDPR on every finding - A PDF deliverable, JSON/LLM-ready export (each finding ships a fix_prompt for Cursor/Claude/ChatGPT), continuous monitoring with diff alerts (webhook/email/Slack/Telegram), and a REST API for your CI/CD - Free single-purpose tools: email (SPF/DKIM/DMARC), SSL, headers, CORS, subdomain, port, DNS, WHOIS How it's different: deeper than the cheap single-purpose scanners (it's not just an SSL test or a header checker — it's all of them plus CVEs, subdomains and secrets in one report), and a fraction of the price and friction of the enterprise platforms (Detectify, Probely, Intruder). It is external and read-only — browser-equivalent traffic, no exploitation, no DoS, no credential testing. The more thorough deep scan is gated behind a DNS ownership check, so you can only run it against domains you control. Free tier with no credit card; paid plans from $9.99/mo. You only scan domains you own or are authorized to assess.
Where it launched
1 platform| Platform | Votes | Link |
|---|---|---|
| PeerPush | 1 | ↗ |
The board it did best on sets the price. Every other board only adds to it if the launch also placed high on that board too — because just showing up somewhere isn't an achievement. Listing on twelve directories is free; placing well on them isn't.
Discussion (0)
No thesis posted yet. Be the first.