Sample report

An example report for a deliberately-vulnerable demo app — every issue in plain language, with the exact fix to paste back into your builder.

https://my-saas.lovable.app

Checked 6 September 2026assaysecurity.com
Action required

Issues found — fix before publishing.

A point-in-time check for the specific issues below — not a comprehensive audit or a guarantee of security.

2Critical
1Risky
1Minor
0/ 100
HELD

What Assay kept from this scan

  • 1 exposed secret seen — 0 stored. We record where a key leaked, never the key itself.
  • A few rows read, 0 stored. To prove your database is readable we pulled a small sample, masked every value before it reached this page, and wrote none of it down.
  • We kept the 4 findings above and nothing else — no page content, no source code, no secrets.

Read-only, ownership-gated, SSRF-guarded. We scan only what a browser can already see.

In a real report, every finding has a re-check.

Paste the fix into your builder, then press it. Assay runs that one check against your live app again and tells you whether the issue is actually gone — usually a single request, fast enough to use as a loop while you work. It can’t run here, because this report describes a demo app that was never deployed.

You can’t confirm your own fix any more than you can clear your own app. “I applied the change” and “the hole is closed” are different claims.