English
Seges TrustCheck my public page

For independent builders shipping with AI

Catch public launch gaps before your first real visitor does.

Submit one public page you control. In under a minute, get a plain-language check for exposed secrets, missing security headers, CORS, SEO, accessibility, and Core Web Vitals. No signup.

One public page you control. No account required.

Sign in with Google (optional) to find your verified domains and reports here again later.

One clear launch check

Find the public gaps that scattered tools leave you to piece together.

Use specialist tools when you need them. Seges Trust turns the public signals from one page into a readable launch check, with boundaries and limitations stated beside each result.

Why the boundary matters

Public trust friction can appear before a visitor reaches your product.

A vague promise, unclear next step, unsupported-looking claim, or unexplained data posture can leave buyers unsure what to believe. Trust is designed to make a proposed review legible before anyone shares a URL or company information.

Lens 01

Visible trust & technical signals

What can be observed on an approved public page, with a stated method and limitation—not an assurance that the surface is secure.

Lens 02

Visitor-path clarity

Where a visitor may lack context, confidence, or a clear next step. These are hypotheses to validate, not invented conversion results.

Lens 03

Claim-evidence & disclosure triggers

Public statements or journey patterns that may need a product, legal, clinical, privacy, or security owner—not an automated approval.

Common AI-assisted shipping mistakes

What tends to slip through when you ship fast.

These are the kinds of gaps the instant check is built to catch — easy to miss when an AI scaffold got you to production quickly.

Leaked secrets

API keys, tokens, and connection strings can end up baked into the JavaScript bundle a scaffold ships to the browser — visible to anyone who opens dev tools.

Wide-open CORS

A permissive Access-Control-Allow-Origin left over from local development can let any other site read responses straight off yours.

Missing security headers

No CSP, no HSTS, no X-Frame-Options — headers most frameworks don't set by default, and most launch checklists skip entirely.

Broken SEO on day one

A placeholder page title, a missing meta description, or a missing canonical tag — easy to miss before your first real visitor shows up.

Check my public page

A fixed scope, not a black box

What a future human-led review is designed to produce.

The deliverable stays bounded to the approved public surface and states what was not assessed. It is not a certification, a legal finding, or an automated decision.

Try the free instant check (live now)
  • Scoped observations from approved public pages only
  • Visitor-path clarity hypotheses kept separate from facts
  • Visible trust and technical signals with stated limitations
  • Claim-evidence, disclosure, privacy, and owner-review triggers
  • A prioritized remediation brief with explicit out-of-scope items

First-release boundary

Public pages. Explicit authority. Read-only evidence.

  • Exact customer-approved HTTPS hosts and paths
  • No login, form submit, appointment, payment, OAuth, or CAPTCHA
  • No session replay, raw analytics, patient portals, or credentials
  • Future protected features exclude EU/EEA/UK request locations; this local build accepts no client data, and non-EU routing is not service availability or customer eligibility
  • Health and regulated claims route to a named human owner
  • The instant page check reads one public HTTPS page you submit and attest you control; no account is required.
  • The public-page check never asks for credentials or private-page content, and it does not sign in, submit forms, pay, book, or bypass access controls.
  • The instant page check is limited to the one public page you submit; it is not a crawl, penetration test, legal opinion, compliance certification, or private-review workflow.
  • It does not provide a penetration test, legal opinion, medical opinion, compliance certification, or conversion guarantee.

Trust before tooling

A useful review should not require blind trust in the reviewer.

Trust is designed for teams who need a clear answer to one question first: what will be observed, what will not, and who still owns the decision?

01 · Scope

You approve what is observed.

Every review begins with an exact host, path, action, time, and data-mode boundary. Nothing outside it becomes in scope by implication.

02 · Evidence

Findings link to what was seen.

Technical artifacts and page observations stay separate from conversion hypotheses, so a plausible idea is never presented as a fact.

03 · Human release

Sensitive claims stay human-owned.

Health, clinical, legal, privacy, and security language becomes a review trigger—not an automated approval or certificate.

How scope stays accountable

Eligibility, evidence, and judgment are different jobs.

  1. Decide eligibility

    A no-data readiness path separates excluded, unselected, and proposed-review scenarios before any URL is requested.

  2. Freeze authority

    A future real review needs written authorization, domain-control proof, a named owner, and an immutable approved scope.

  3. Observe read-only

    A future isolated browser lane for an authorized private review will be restricted to the approved scope and will not log in, submit, pay, book, or collect credentials. This is separate from the live instant page check at /critique, which already runs today against a single public page a visitor submits and attests they control.

  4. Release with context

    A human reviews evidence, limitations, and regulated-claim triggers before any private report can be released.

The report language

No black-box score. No fabricated certainty.

MeasuredA deterministic tool signal with a stated method, timestamp, and limitation.
ObservedVisible behavior inside the approved scope.
InferredA bounded hypothesis that still needs validation.
Needs human reviewA legal, clinical, privacy, security, or owner decision is required.
Not assessedThe review did not have the authority or evidence to decide.

Before a review can open

Questions that should have clear answers first.

What could a future fixed-scope review examine?

Only approved public pages: bounded observations, visible technical signals, visitor-path hypotheses, and claim-evidence or disclosure triggers with explicit limitations.

What is needed before a real review can open?

A future review requires written authorization, domain-control proof, an exact scope, private controls, and human approvals. This local walkthrough cannot open that workflow.

Do I have to provide credentials or customer data?

No. P0 excludes credentials, portals, forms, raw analytics, session replay, patient data, and free-text client context.

How are sensitive claim and privacy questions handled?

They become named owner-review triggers. Trust does not make a legal, clinical, privacy, or security decision for your team.

Will this scan my production app?

No. The instant page check is limited to the one public page you submit; it is not a crawl, penetration test, legal opinion, compliance certification, or private-review workflow.

Does a clean result certify security or compliance?

No. Trust reports scoped observations, tool signals, hypotheses, and owner review triggers. It does not provide a penetration test, legal opinion, medical opinion, compliance certification, or conversion guarantee.

Does it check if I left Supabase Row Level Security (RLS) off?

Partially. /critique classifies a discovered Supabase key as a public anon key or a more sensitive service_role key, and flags service_role exposure as critical. It does not yet directly query your database to test individual table RLS policies.

Before you share it

Check the public page you are about to put in front of people.

One URL. No signup. A clear page-level result in about a minute — not a sales call.

Check my public page