English
Seges Trust

For founders shipping AI-built web apps

See what the open web sees before you launch.

Paste one public page. In about a minute, see what a new visitor sees first, where they may hesitate or leave, and what to fix first. The report also includes page load timing (LCP) and first server response timing (TTFB). No repository or password. If the report finds something that looks like a key, details go only to the signed-in account recorded as the owner of that domain after domain verification (DNS).

No card. Google sign-in required. Your first report is free. Suspected-key details reach only the signed-in account that verified the domain and never appear on the shareable link.

Need a review of screens behind sign-in? Signed-in Audit is USD 350: agree the scope first, receive the payment step next, then get an owner-only report.

See the USD 350 scope and payment steps

Three questions before you share the link

Know what a visitor will meet before your launch does.

Start with the situation you recognise. The report turns what is visible on one public page into a short, evidence-backed fix list.

Public safety

Situation
You are about to send a link to a customer and worry that the public page may show more than it should.
What we look at
We look only at what a stranger can open and flag visible signs that deserve attention first.
What you get
A ranked fix list, so you can deal with the most worrying public issue before sharing the link.
Clear boundary
Each item shows its page evidence and what was not checked. This is not a penetration test or a security guarantee.
Run my free pre-launch check

Friction before conversion

Situation
You are about to run ads or ask friends to share the site, but a visitor may not understand the offer or find the next step.
What we look at
We check whether the main message, action, and search preview are easy for a first-time visitor to find.
What you get
Clear fix prompts you can hand to the person or AI making the site, before paid traffic meets the page.
Clear boundary
The report separates what it saw, measured, inferred, and did not assess. It does not promise sales or sign-ups.
Run my free pre-launch check

Claim and policy risk

Situation
Your privacy, terms, and refund pages exist, but you do not know whether a customer or partner can find them or question a claim.
What we look at
We check that important pages and contact paths are findable, then flag wording that needs a person to review.
What you get
A page-backed to-do list for launch decisions, instead of relying on a last-minute guess.
Clear boundary
This is not legal advice or a compliance certificate. Places needing professional judgment are labelled clearly.
Run my free pre-launch check

What you receive

One report. Three things you can act on.

About a minute after you paste the link.

The first issues to address

Ranked, with the evidence under each one: measured by a tool, seen on the page, an educated guess, or not checked at all. Never a single score to hide behind.

A fix prompt you can paste back

One button turns the whole report into a prompt for the AI that wrote the code. Anything that looks like a secret is stripped out before it reaches your clipboard.

A dated link, and the limits on its face

Shareable with the first customer who asks about security, and explicit about where the check stopped. It is evidence, not a certificate, and it says so.

How it works

Four steps, one sign-in.

  1. Sign in and paste one link

    A public page you control, which you confirm you control, and a Google sign-in so the report has an owner. Nothing else is asked for, and no card is involved.

  2. Read the result

    About a minute later. Every line says where it came from, and the report states what it could not check as plainly as what it found.

  3. Copy the fix prompt

    Paste it straight back into the AI that wrote the code. Secrets are removed first, and anything needing a human decision is marked do-not-auto-edit.

  4. If a suspected key is flagged, verify the host

    Suspected-key details stay hidden until the signed-in account proves control of that host with a DNS TXT record. The rest of the report does not require this step.

What it will not do

  • Public-surface evidence, not a pentest, certification, legal opinion, or guarantee of security.
  • The instant page check reads one public HTTPS page you submit and attest you control; receiving the report requires a free Google sign-in.
  • The public-page check never asks for credentials or private-page content, and it does not sign in, submit forms, pay, book, or bypass access controls.
  • Technical artifacts and page observations stay separate from conversion hypotheses, so a plausible idea is never presented as a fact.

Scope and limits

Four kinds of problem that ship without breaking anything.

None of these break your site. It works, the tests pass, and the problem sits there in public until somebody else finds it first.

Things that were never meant to be public

If a secret was accidentally left in the live page, anyone can copy it. Trust checks the public page for clues like exposed keys or unsafe settings, then tells you what to fix first. It never signs in or looks inside your database.

Legal pages and claims that invite trouble

Whether privacy, terms, refunds, accessibility and a route for data requests are actually there and findable. It reads what you claim as well, and flags wording that usually needs evidence first. For Taiwan it matches food, cosmetic and pet-food rules and suggests wording the regulation itself permits.

Reasons a visitor leaves before buying

Whether a first-time visitor is offered a clear next step without scrolling, whether your search result still shows the placeholder your template shipped with, and how long the main content really takes to appear.

Barriers that shut people out

Every page checked runs through the same automated accessibility engine professional auditors start with, pointing at the exact elements that fail. It catches part of the problem, not all of it, and says so.

Run my free pre-launch check

Common questions

Fair questions, answered before you paste anything.

What does the free check ask me for?

One public HTTPS page you control and a Google sign-in so the report has an owner. It does not log into the target, submit a form, ask for customer data, or request a repository or password.

Will it dig around inside my app?

No. The free check reads pages the way a visitor's browser does, and stops there. The instant page check performs a small, bounded same-origin crawl: the page you submit, plus up to four same-origin pages it links to directly (five pages total). It is not a full site crawl, penetration test, legal opinion, compliance certification, or private-review workflow.

Does a clean result mean my site is safe?

No. A clean free-check result means only that these checks found nothing, which is not the same as the site being safe. It does not provide a penetration test, legal opinion, medical opinion, compliance certification, or conversion guarantee.

What does the free check deliberately not probe?

It does not request unpublished file paths, fabricate a cross-origin request, submit a GraphQL query, query a database, scan ports, log into the target, or submit forms. Those are not clean results; they are not-assessed areas. The separate active scan goes further only after current DNS ownership and explicit authorization, and payment never starts it.

Before you send the link

Run it once yourself.

One link and a Google sign-in. No card, no sales call. About a minute from now you will know, instead of hoping.

Run my free pre-launch check