How it works
Afterprompt looks at your site the way a visitor's browser does, then tells you what an attacker could find there, and how to fix it.
What we check
- Leaked API keys. Stripe, OpenAI, Anthropic, AWS, GitHub, Supabase service keys and more, in your page and its JavaScript.
- Source maps. Files that let anyone rebuild your original source code.
- Private files. .env, .git, backups and database dumps left in public folders.
- Security headers. Content-Security-Policy, HSTS, clickjacking protection and the other standard headers.
- HTTPS. Redirects, certificate validity and expiry.
- Cookies & CORS. Session cookies without protection, APIs readable by any website.
- Email spoofing. SPF, DMARC and DKIM records that stop others sending email as you.
What the bot does
Only ordinary GET requests, only to the exact address you entered, about 80 at most, three at a time. The same address is scanned at most once per hour.
Besides your page and its scripts, it checks a short, fixed list of well-known paths: /.env, /.git/HEAD, /.DS_Store, /config.json, /backup.zip, /backup.sql, /backup.tar.gz, /dump.sql, /db.sql, /database.sql, /site.zip, /www.zip.
It identifies itself as AfterpromptBot/0.1.0.
What it never does
It doesn’t guess hidden pages, try to log in, submit forms or change any data. It never uses a key it finds, never follows a redirect to another site, and never connects to private networks.
Your data
We never store your HTML or JavaScript. They are read in memory and discarded when the scan ends.
We keep the results only. Any secret is masked before it is saved, like sk_live_****a3f9.
We don't store the IP addresses of people who run scans. Reports are deleted after 90 days.
To see what works, we count page views, scans and sign-ups per day, without cookies, IP addresses or identifiers.
With an account, you can download everything we hold about you, or delete your account and all its data immediately, from your dashboard.
Opt out
Own a site and want it excluded from scans? Contact us from an address on that domain.