Signoffly

Know if your app is ready to ship.

Paste a GitHub link for one plain-language report on security, testing, code quality and legal risk. Or paste your website address for a quick look from the outside.

See a sample report

Three steps, nothing to install.

  1. Paste

    Drop in a public GitHub link or your website address. There is nothing to install and nothing to configure.

  2. Scan

    Proven open-source scanners read your code and dependencies. Your app is never run.

  3. Sign off

    Get one report ranked by what could hurt you first, with a fix prompt for every issue.

Four areas, one report.

Most scanners stop at security. Signoffly also looks at the parts that sink launches quietly: missing tests, messy code and privacy rules.

Legal and privacy

Region-aware checks for wherever you launch, including Indonesia and Southeast Asia.

  • UU PDP
  • GDPR
  • CCPA
  • PDPA

Findings to review with a professional. Not legal advice.

Security

The mistakes AI assistants repeat, found before a stranger finds them.

  • Secret keys committed to the repo
  • Packages with known vulnerabilities
  • Database tables anyone can read

Testing

Does the code that matters have tests? Payments, sign-in and anything that changes data are checked first.

Code quality

Copied code, very long files and loose typing, explained without jargon.

Sample report

Plain words. Ranked fixes.

lumen-notes/web

Scanned 4 Oct 2026

Legal checks forIndonesiaEU

Fix three things before you launch.

3 high3 medium2 low
  1. High

    A Stripe secret key is committed to the repo

    Blocks sign-off

    Anyone who can see this repo can charge and refund on your account. Rotate the key now, then remove it from git history.

    .env.example:4

    Fix prompt for Cursor or Claude Code
    Remove the Stripe secret key from .env.example and replace it with a placeholder. Read it from process.env.STRIPE_SECRET_KEY instead, add .env to .gitignore, and list the exact steps to rotate the key in the Stripe dashboard and clean it out of git history.
  2. High

    You collect emails and phone numbers but have no privacy policy

    The signup form stores personal data. Privacy laws in several regions expect a clear notice before you collect it.

    app/signup/page.tsx

    Applies under: UU PDP (Indonesia) and GDPR (EU). A finding to review, not legal advice.

    Fix prompt for Cursor or Claude Code
    Add a /privacy page that explains what personal data this app collects (email, phone number), why, how long it is kept, and how a user can ask for deletion. Link it from the signup form and add an unchecked consent checkbox before submit. Keep the wording plain and mark anything that needs a lawyer to review.
  3. High

    Anyone can read the profiles table

    Blocks sign-off

    The profiles table has no row level security, so anyone holding your public key can read every user's email.

    supabase/migrations/002_profiles.sql:1

    Fix prompt for Cursor or Claude Code
    Enable row level security on the profiles table and add policies so a signed-in user can only select and update their own row (auth.uid() = id). Show me the migration SQL and a test that proves another user cannot read it.
  4. Medium

    A package you use has a known security problem

    One of your dependencies has a published vulnerability. A newer version fixes it.

    package-lock.json

    Fix prompt for Cursor or Claude Code
    List the dependencies with known vulnerabilities in this project, upgrade each to the lowest version that fixes it, run the tests, and tell me about any breaking change.
  5. Medium

    Tracking tools load and there is no consent banner

    Google Analytics can follow visitors from page to page. Some laws expect people to agree first, for example visitors from Europe.

    app/layout.tsx:14

    Applies under: GDPR (EU). A finding to review, not legal advice.

    Fix prompt for Cursor or Claude Code
    Add a consent banner so Google Analytics only loads after a visitor agrees, with accept and reject buttons of equal weight and a way to change the choice later. Mark anything that needs a lawyer to review.
  6. Medium

    We found no test that mentions your payments code

    Your app handles payments, and none of its tests mention payments, checkout or webhooks. A silent bug here costs you customers or money. This is judged from file names and what the tests mention, not from measured coverage.

    app/api/checkout/route.ts

    Fix prompt for Cursor or Claude Code
    Write tests for the payment code: a successful payment, a declined card, a duplicate submit, a webhook that arrives twice, and a request from a signed-out visitor. Use the test runner already in this project and mock the payment provider.
  7. Low

    The same code is copied in several places

    About 86 lines across 3 files look copied from each other. A fix in one place does not reach the others, and the copies slowly drift apart.

    lib/orders.ts:6

    Fix prompt for Cursor or Claude Code
    Move the shared logic in lib/orders.ts, lib/invoices.ts and app/cart/page.tsx into one function, make each place use it, and delete the copies. Do not change behavior.
  8. Low

    We could not find a way for users to delete their account

    This can be fine if you handle requests by email. If so, say so in your privacy policy and make sure someone answers.

    Applies under: UU PDP (Indonesia) and GDPR (EU). A finding to review, not legal advice.

    Fix prompt for Cursor or Claude Code
    Add a way for signed-in users to delete their account and download their data, or describe in the privacy policy how to ask for it by email. Make deletion remove the user's rows in every table.
Automated findings. Review anything legal with a professional.Sample data

Pay once for the repo you are fixing.

No subscription to forget about. Scan a few times a day for free, and unlock everything for one repository when you need the full picture.

Free

$0

  • 3 scans a day
  • Score and verdict
  • Every finding with its title and location
  • Full detail on the two most important findings

Project pass

One repository for 14 days

  • Unlimited rescans of that repository
  • Every explanation and fix prompt unlocked
  • Legal checks for the regions you pick

Fair questions.

Is this legal advice?

No. Legal findings are automated flags for you to review, ideally with a lawyer. They tell you where to look, not what the law requires of you.

Does Signoffly run my code?

No. It reads your repository as text and never starts your app, so nothing of yours executes on our side. For a website it only opens the page the way a browser does, and never tries to get in.

What can I check?

Public GitHub repositories get the full check. You can also paste the address of a live website for a quick look at what a visitor's browser sees: the secure connection, protective headers, cookies, keys visible in the page and privacy basics. A website check cannot see your code, so it can never be signed off. Private repos come later.

How is this different from a security scanner?

Security scanners stop at security. Signoffly also checks privacy rules by region, explains everything in plain language, and writes a fix prompt for every finding.

Ship it when it is signed off.