I'm Kyle, co-founder of TripleKey.
When we launched TripleKey, our goal was to help anyone understand their software by analyzing software risk, licensing, and contributors. Our focus has been daily software composition analysis (SCA).
We decided to build a simple external scan that anyone can use. The tool is FreeDAST. You enter a URL and get an external security grade in seconds. It's the same outside view an attacker or buyer sees of your public surface. There is no code access required and nothing to install.
Why did we launch a free tool?
We've gone through SOC2 compliance, cyber insurance applications, renewals, and security reviews with large enterprises and those processes always involve external scans (Dynamic Application Security Testing). Many enterprise companies sell these scans but also create risk profiles that are hard to change without upgrading to their paid services. We wanted to provide a more transparent alternative.
We've also run this on several vibe coded websites/applications and there is always something to improve.
What I'd genuinely love is to hear if you find it useful (or not) for your company. You can run a scan anytime at freedast.com.