Lockpick

How Lockpick checks a site

What Pulse looks at, what it leaves alone, and how to read a result.

Which websites can I assess?

Only sites you own or are authorized to test. Check the exact HTTPS origin before starting. Permission for one site does not include other domains, shared hosting infrastructure or third-party services.

Do I need to understand security?

Start with the plain-language explanation, then open the evidence if you need more detail. Your coding agent can help with a repair, but you should review and test the proposed change.

Does my coding agent run the assessment?

Lockpick runs the assessment on its own infrastructure. Your coding agent can help apply the repair brief in your repository. Customer-facing results show the evidence and next steps; private execution workflows and internal logs are not part of the report.

What does Pulse check?

Pulse inspects the public homepage and its observable security configuration, such as response headers and TLS. It does not sign in, submit forms, access your database or prove that user roles are isolated. Deep (30 pages) is free during the pilot once you verify you own the site.

Does a clean result mean my app is secure?

No. It means the completed checks did not observe a concern in the sampled response. Unknown checks and untested areas remain visible. A public homepage check cannot establish the security of the whole application.

Will Lockpick change my code?

No changes are made automatically. Review the repair prompt with your coding agent, test the proposed fix, and decide whether to deploy it. Copying a prompt does not resolve a finding. Request a separate recheck to compare new evidence.

What happens if the assessment stops early?

The result must distinguish completed observations from checks it could not finish. Timeouts, unavailable pages and scope restrictions can reduce coverage. A partial result is not a clean bill of health.

Can I keep the results forever?

This pilot does not promise permanent report storage. Keep the repair brief you need in your own project records. Do not include passwords, access tokens or private customer data in a target URL or repair brief.

The live vulnerability count on the home page starts from Zero Day Clock, which counted 57,871 CVEs published from January to August 2026. We extend it at the same daily rate.