Security Report

Cross-platform security posture and issue tracking

Overall Security Score

Aggregate of all security checks across 13 platforms

81%

54

Open Issues

0

Being Fixed

10

Critical

26

High

Cross-Platform Matrix

PlatformCSRF ProtectionRate LimitingInput ValidationEncryptionSecurity HeadersAuth / SessionIssues
Nox15
BYND1
Veil2
Veritas3
Heal1
Auth0
TuneNest6
VibeVerse4
ReelRoom4
StreamSpace6
InkWell5
SVRN Economics1
Agent Platform6

Platform Breakdown

Nox83%
High
CSRF ProtectionRate LimitingInput ValidationSecurity HeadersAuth / SessionEncryption

15 open issues

HighNo request size limits on file upload routesOpen
HighAdmin routes lack additional authorization checksOpen
HighNo audit logging for sensitive operationsOpen
+12 more →
BYND100%
CSRF ProtectionRate LimitingInput ValidationEncryptionSecurity HeadersAuth / Session

1 open issue

LowNo rate limiting on WebSocket reconnectionsOpen
Veil100%
CSRF ProtectionRate LimitingInput ValidationEncryptionSecurity HeadersAuth / Session

2 open issues

MediumExport data feature is stub — privacy compliance gapOpen
LowNo key rotation mechanism for encryption keysOpen
CSRF ProtectionRate LimitingInput ValidationSecurity HeadersAuth / SessionEncryption

3 open issues

MediumNo admin dashboard for content moderationOpen
MediumMissing moderation queue for user commentsOpen
LowNo analytics or usage trackingOpen
Heal100%
CSRF ProtectionRate LimitingInput ValidationEncryptionSecurity HeadersAuth / SessionPHI Audit Trail

1 open issue

LowNo automated HIPAA compliance scanningOpen
Auth100%
No issues
CSRF ProtectionRate LimitingInput ValidationSecurity HeadersAuth / SessionCORS
CriticalHigh
CSRF ProtectionRate LimitingInput ValidationSecurity HeadersAuth / SessionEncryption

6 open issues

CriticalNo rate limiting — AI endpoints can be abused (expensive Anthropic calls)Open
HighMissing CSP header — XSS risk on public profilesOpen
HighNo server-side file type verification — relies on extension onlyOpen
+3 more →
CriticalHigh
CSRF ProtectionRate LimitingInput ValidationSecurity HeadersAuth / SessionEncryption

4 open issues

CriticalNo rate limiting on API routesOpen
HighMissing CSP headerOpen
MediumCORS set to * on agent-actions and llms.txtOpen
+1 more →
CriticalHigh
CSRF ProtectionRate LimitingInput ValidationSecurity HeadersAuth / SessionEncryption

4 open issues

CriticalNo rate limiting on API routesOpen
HighMissing CSP and HSTS headersOpen
Highoptimize-image accepts bucket param — potential path traversalOpen
+1 more →
CriticalHigh
CSRF ProtectionRate LimitingInput ValidationSecurity HeadersAuth / SessionEncryption

6 open issues

CriticalNo rate limiting on API routesOpen
HighMissing CSP headerOpen
HighCORS * on agent-actions endpointOpen
+3 more →
CriticalHigh
CSRF ProtectionRate LimitingInput ValidationSecurity HeadersAuth / SessionEncryption

5 open issues

CriticalNo rate limiting — auth, tips, and content endpoints unprotectedOpen
HighMissing CSP headerOpen
HighCORS * on agent-actions endpointOpen
+2 more →
CSRF ProtectionRate LimitingInput ValidationSecurity HeadersAuth / SessionEncryption

1 open issue

LowNo custom security headers configured (relying on Vercel defaults)Open
CSRF ProtectionRate LimitingInput ValidationSecurity HeadersAuth / SessionEncryption

6 open issues

HighCSRF protection unclear — POST endpoints lack documented CSRF mitigationOpen
HighRate limiting thresholds not documentedOpen
HighToken rotation/expiry/revocation not documentedOpen
+3 more →