Lens 01
Visible trust & technical signals
What can be observed on an approved public page, with a stated method and limitation—not an assurance that the surface is secure.
For independent builders shipping with AI
Submit one public page you control. In under a minute, get a plain-language check for exposed secrets, missing security headers, CORS, SEO, accessibility, and Core Web Vitals. No signup.
One public page you control. No account required.
Sign in with Google (optional) to find your verified domains and reports here again later.
One clear launch check
Use specialist tools when you need them. Seges Trust turns the public signals from one page into a readable launch check, with boundaries and limitations stated beside each result.
Why the boundary matters
A vague promise, unclear next step, unsupported-looking claim, or unexplained data posture can leave buyers unsure what to believe. Trust is designed to make a proposed review legible before anyone shares a URL or company information.
Lens 01
What can be observed on an approved public page, with a stated method and limitation—not an assurance that the surface is secure.
Lens 02
Where a visitor may lack context, confidence, or a clear next step. These are hypotheses to validate, not invented conversion results.
Lens 03
Public statements or journey patterns that may need a product, legal, clinical, privacy, or security owner—not an automated approval.
These are the kinds of gaps the instant check is built to catch — easy to miss when an AI scaffold got you to production quickly.
API keys, tokens, and connection strings can end up baked into the JavaScript bundle a scaffold ships to the browser — visible to anyone who opens dev tools.
A permissive Access-Control-Allow-Origin left over from local development can let any other site read responses straight off yours.
No CSP, no HSTS, no X-Frame-Options — headers most frameworks don't set by default, and most launch checklists skip entirely.
A placeholder page title, a missing meta description, or a missing canonical tag — easy to miss before your first real visitor shows up.
A fixed scope, not a black box
The deliverable stays bounded to the approved public surface and states what was not assessed. It is not a certification, a legal finding, or an automated decision.
Try the free instant check (live now)First-release boundary
Trust before tooling
Trust is designed for teams who need a clear answer to one question first: what will be observed, what will not, and who still owns the decision?
01 · Scope
Every review begins with an exact host, path, action, time, and data-mode boundary. Nothing outside it becomes in scope by implication.
02 · Evidence
Technical artifacts and page observations stay separate from conversion hypotheses, so a plausible idea is never presented as a fact.
03 · Human release
Health, clinical, legal, privacy, and security language becomes a review trigger—not an automated approval or certificate.
How scope stays accountable
A no-data readiness path separates excluded, unselected, and proposed-review scenarios before any URL is requested.
A future real review needs written authorization, domain-control proof, a named owner, and an immutable approved scope.
A future isolated browser lane for an authorized private review will be restricted to the approved scope and will not log in, submit, pay, book, or collect credentials. This is separate from the live instant page check at /critique, which already runs today against a single public page a visitor submits and attests they control.
A human reviews evidence, limitations, and regulated-claim triggers before any private report can be released.
The report language
Before a review can open
Only approved public pages: bounded observations, visible technical signals, visitor-path hypotheses, and claim-evidence or disclosure triggers with explicit limitations.
A future review requires written authorization, domain-control proof, an exact scope, private controls, and human approvals. This local walkthrough cannot open that workflow.
No. P0 excludes credentials, portals, forms, raw analytics, session replay, patient data, and free-text client context.
They become named owner-review triggers. Trust does not make a legal, clinical, privacy, or security decision for your team.
No. The instant page check is limited to the one public page you submit; it is not a crawl, penetration test, legal opinion, compliance certification, or private-review workflow.
No. Trust reports scoped observations, tool signals, hypotheses, and owner review triggers. It does not provide a penetration test, legal opinion, medical opinion, compliance certification, or conversion guarantee.
Partially. /critique classifies a discovered Supabase key as a public anon key or a more sensitive service_role key, and flags service_role exposure as critical. It does not yet directly query your database to test individual table RLS policies.
Before you share it
One URL. No signup. A clear page-level result in about a minute — not a sales call.
Check my public page