Provelex
Your app is already being scanned

Catch it if you can.
Or a stranger will.

Someone is going to find the holes in your software. The only question is whether it is you, on a Tuesday afternoon, or somebody else at three in the morning. Get your Provelex Score today.

Get your Provelex Score — freeNo account, no card, nothing kept. Free credits when you sign up — enough for a full AI scan.
66Fair11 findings
One number your board understands

The Provelex Score

Out of 100, recalculated on every run, tracked over time. It is deliberately simple to reproduce, because a number an auditor cannot check by hand is a number they will not accept.

100
 − 18 × critical findings
 −  8 × high
 −  3 × medium
 −  1 × low

Each severity is capped, so one noisy accessibility sweep cannot swamp an otherwise sound application. The weights are printed in every report.

Why this matters

These are real findings, from real applications

Every one of these was shipped by a team who believed they had tested. None of them are exotic. All of them are the kind of thing that is obvious in hindsight and invisible beforehand.

critical
An environment file left readable
Database passwords and API keys, downloadable by anyone who asks for /.env.
high
A login with no rate limit
Leaked password lists get run against it automatically. The first sign is a support ticket.
high
Text typed into the address bar rendered into the page
One crafted link runs an attacker’s code in your customer’s browser, on your domain.
medium
A certificate about to expire
Every visitor meets a full-page browser warning. Most of them leave.
medium
Checkout that accepts an impossible quantity
Not a security hole. Just an order you cannot fulfil and a refund you have to process.

A scanner finds the first one. A QA team finds the last one. Provelex finds both, and writes them up so the person approving the fix understands what it costs to leave it.

What it checks

Five kinds of broken

Functionality
An agent writes test cases from your app and drives them in a real browser.
Security
Headers, cookies, TLS, exposed files, and bounded, non-destructive probes.
Performance
Core Web Vitals from the page itself, with drift against your last run.
Accessibility
axe-core, translated out of developer language into plain sentences.
Mobile view
Replayed at phone size: overflow, tap targets, text too small to read.
Guided testing
Or drive it yourself. A blue ring shows you where to click, a red one shows you what is broken, and it adapts when you try your own values.
How it works

No scripts. No selectors. No YAML.

If you can book a flight online, you can run Provelex. The person who needs the report is rarely the person who would write a test script — that is the whole point.

  1. 01
    Add your app
    Paste a URL and pick a profile. A starter test pack comes with it.
  2. 02
    Prove you own it
    A DNS record, a file, or a signed statement for a local address.
  3. 03
    Add a login
    Into a sealed vault. Provelex signs in and shows you the screenshot.
  4. 04
    Tick what to check
    Five toggles. Nothing else to configure.
  5. 05
    Read the report
    A health score, ranked findings, and a branded PDF you can forward.
What it costs

Everything is free except the AI

Adding applications, driving the browser, evidence, reports, PDF export, history — none of it costs credits, because none of it costs us anything. Only a scan spends money, so only a scan spends credits.

Passive scan
2credits
≈ ₹1
Full scan
15credits
≈ ₹7.5
Guided session
10credits
≈ ₹5

You start with 50 credits in India and 70 elsewhere — enough for a full scan either way — and top up with a card or a voucher. The exact price is shown before every run, never discovered afterwards.

Authorisation is not a checkbox

Provelex will not test an address you cannot prove you own

It signs in with real credentials and actively probes for weaknesses, so ownership is proven before any of that runs — a DNS record, a file on the site, or a signed statement for a local address. The grant is stored with the application and reproduced in every report, which is exactly what an enterprise security team asks for. Until a target is verified, only the checks that send no payload will run.

Passwords are sealed with AES-256-GCM under an Argon2id-derived key, masked before every screenshot, and never appear in a report, a log, or an event.

Find your breaking point first.

It takes about three minutes to set up and the first scans are on us. The worst thing you will find today is cheaper than the best thing someone else finds tomorrow.

Provelex — automated QA and security analyst. A DevSapience Technology Solutions product.
OWASP Top 10 · ISO/IEC 25010 · WCAG 2.2 AA© 2026 DevSapience Technology Solutions