← Back to scanner

Terms of Use & Privacy

Broid Business Solutions — AI App Security Audit · Last updated 15 August 2026
Authorization required. Only scan websites and applications that you own or are explicitly authorized to test. Scanning systems without permission may be illegal in your jurisdiction. By using this tool you confirm you have that authorization.

1. What the tool does

The Broid Business Solutions — AI App Security Audit performs an automated, external security assessment of a web address you provide — reading publicly observable security headers, checking for exposed files, cookies, transport security, and known dependency vulnerabilities. It is a first-line screening aid, not a penetration test, code review, or guarantee of security.

Broid also performs bounded active checks, and we describe them here so you know exactly what you are consenting to. It extracts the public database key already present in your page and issues read-only, count-only requests to your Supabase or Firebase project to test whether anonymous access is possible; and it sends a single harmless message to up to three AI or chat endpoints on your own domain to test whether they are unauthenticated or unthrottled. It performs no writes, no deletions and no authentication attempts.

2. Acceptable use

3. No warranty

The service is provided "as is." A passing grade does not guarantee an application is secure; automated external scanning cannot see backend logic or authenticated areas. Broid is not liable for decisions made based on results. For production systems handling real data, obtain a professional security audit.

4. Privacy & data

5. Service providers

To operate Broid we rely on trusted third-party processors, each handling only what their function requires: Vercel (hosting), Upstash (database), Clerk (sign-in/identity), Stripe (payments — we never see or store your card details), Resend (transactional email), Anthropic (the AI assistant and code-audit features), OSV.dev (open-source vulnerability lookup — receives the names and versions of libraries detected on your site), and Google Public DNS (DNS-over-HTTPS — receives the domain being scanned, to check its SPF, DMARC, DNSSEC and CAA records). Your use of Broid is also subject to these providers' terms where applicable.

6. Credits, payment & refunds

7. Cookies & local storage

We use your browser's local storage and cookies for three things, all of them functional:

We do not use third-party advertising or tracking cookies, and we do not run cross-site analytics. You can clear this data at any time in your browser settings; clearing it removes any guest credits held only in that browser.

8. Contact

Questions, authorization queries, refund requests, or data requests: broid@broid.net.