Early access · built in the UK

Two eyes on your stack. Evidence you can hand over.

Snoopios connects read-only to Supabase, Vercel, Cloudflare, GitHub and Stripe, runs real configuration checks every six hours, and keeps the evidence. When a customer sends a security questionnaire or the ICO asks a question, the answer is already written.

For teams of one to twenty. Flat price by project, never by headcount. No sales call.

acme-app
17 pass · 2 fail · 1 unknown
  • RLS enabled on every public tablePass
  • No policy admits anon writesPass
  • Preview deployments protectedFail
  • DMARC policy is quarantine or rejectFail
  • Default branch protectedPass
  • Backups or PITR enabledToken expired · reconnect SupabaseUnknown
Last run 14 minutes ago · next in 5h 46mEvidence stored · sha256 3f9a…c21e

Compliance tools weren't built for your stack, or your budget.

Vanta and Drata start at five figures a year and are built around AWS and Okta. You're on Supabase and Vercel, you're the DPO and the on-call engineer, and the first enterprise customer just sent a forty-question spreadsheet.

The obligations don't wait

UK GDPR applies from your first user. Since June 2026 every controller needs a complaints procedure. A Stripe review wants a privacy policy that matches the code.

Nobody checks the things that matter

Is RLS on every table? Does any policy let anon write? Is a preview deployment open to the internet? The big platforms sync your user list and call it monitoring.

The documents rot

A privacy policy written once says things the code stopped doing months ago. That gap is a misrepresentation, not a typo.

How it works

  1. 01

    Connect, read-only

    Grant Snoopios read access through each provider's own consent screen. No write scope is ever requested. Revoke it from their dashboard any time.

  2. 02

    Checks run every six hours

    Each check is code with a recorded fixture. It returns pass, fail or unknown, and a check that can't run says unknown — it never says pass.

  3. 03

    Evidence is kept, unchanged

    Every run stores the raw response, a timestamp and a hash. Nothing is edited after the fact. Corrections are new rows.

  4. 04

    Documents write themselves from the facts

    The sub-processor register comes from what's connected. Every policy claim links to a live check, so a sentence the code no longer honours is flagged in the document.

What it checks

Thirty-nine read-only checks across five providers, each with a recorded fixture, and each one exists because it caught a real problem on a real app. More as customers ask.

Supabase

  • RLS enabled on every public table
  • no policy admits anon writes
  • private schema closed to session roles
  • search_path pinned on definer functions
  • email confirmation on
  • captcha on
  • backups or PITR on
  • SSL enforced
  • production SMTP configured
  • no undeclared public bucket

Vercel

  • preview deployment protection on
  • git fork protection on
  • domains verified and configured
  • sensitive-variable policy enforced
  • cron routes reject unauthenticated calls
  • SAML enforced or members reviewed

GitHub

  • default branch protected
  • Dependabot alerts on, none critical
  • no .env committed
  • .gitignore covers .env
  • SECURITY.md and CODEOWNERS present
  • outside collaborators reviewed

Cloudflare

  • DNSSEC active
  • TLS mode strict, minimum 1.2
  • always HTTPS with HSTS
  • no R2 bucket publicly exposed
  • WAF managed ruleset deployed
  • Bot Fight Mode on

Stripe

  • every webhook endpoint enabled and pinned to an API version
  • no failed deliveries in 30 days
  • live mode with charges enabled

Your domain

  • CSP, HSTS, frame-ancestors, nosniff
  • HTTP redirects to HTTPS
  • HSTS preload status
  • SPF, DMARC and CAA present
  • TLS 1.2 minimum, certificate not expiring
  • security.txt present
  • privacy page names a controller and a date

No model decides whether you pass. The full feasibility table, endpoint by endpoint, is published in the documentation.

The pack

The documents a customer, an auditor or the ICO asks for, generated from what's connected and checked against what's running. Every one is a draft for your review, and says so.

  • Privacy policy, with a real last-updated date
  • Record of processing activities
  • Sub-processor register, derived from your connections
  • Retention schedule
  • Breach notification runbook, pre-filled, with the 72-hour clock
  • Data subject request procedure
  • Complaints procedure with the 30-day acknowledgement the 2025 Act requires
  • Security questionnaire answer bank, grounded in check results
  • Cyber Essentials self-assessment preparation
  • SOC 2 and ISO 27001 readiness maps: every control, ticked as checked, documented or yours to answer

A trust page you can send instead of a spreadsheet

A public page per project with live check status, your document list and NDA-gated downloads. When a prospect's security reviewer asks, you send a link. Unknown shows as unknown there too.

snoopios.com/t/acme-app
17
Pass
2
Fail
1
Unknown

Flat, published, by project.

No per-seat pricing, no per-framework upsell, no renewal uplift. Annual pays for ten months. Cancel monthly plans any time.

Free

£0Evaluate on one project

  • One project
  • Weekly checks
  • Dashboard and findings
  • No document exports
Start free

Solo

£29/month

  • One project
  • Checks every six hours
  • Evidence vault, 12 months
  • Full document pack
  • Public trust page
Start Solo
Most teams

Studio

£79/month

  • Up to five projects
  • Everything in Solo
  • Questionnaire answer bank
  • Agency white-label trust pages
Start Studio

Scale

£199/month

  • Unlimited projects
  • Everything in Studio
  • SOC 2 and ISO 27001 readiness maps
  • Auditor export package
  • Priority support
Start Scale

For comparison: the cheapest enterprise platform starts around £4,400 a year. Vanta's entry tier for a team your size is about £10,000.

Questions we get asked

Does Snoopios need write access to anything?
No. Every connection is a read-only grant through the provider's own consent screen, and a check that would need write access does not get built. You can revoke access from the provider's dashboard at any time.
What happens when a check can't run?
It reports unknown, with the reason. Unknown is shown as grey everywhere, including your trust page, and never counts as a pass. An expired token is the usual cause and the fix is a reconnect.
Is this legal advice, or a certification?
Neither. Snoopios produces evidence of what was checked and when, and documents drafted from that evidence for your review. It never says a customer is compliant or certified, and it never brokers or bundles an audit.
Can I get SOC 2 or ISO 27001 with it?
The Scale tier maps your checks and documents to the SOC 2 common criteria and ISO 27001 controls and exports a package an auditor can read. The audit itself is between you and an audit firm. We can point you at firms that already accept this kind of evidence, as a referral and nothing more.
Where is my data held?
In the United Kingdom, with Supabase in the London region, hosted on Vercel. Evidence is stored per organisation with row-level security and is never shared between customers. The full processor list is in the privacy policy.

Built by the kind of company it's for.

Archema Labs runs five products on Supabase and Vercel with one developer. Every check in Snoopios exists because it caught something on one of them. The compliance pack is the one we wrote by hand, five times, before deciding to build the tool.

Connect one project. See what you'd have found out the hard way.

Free for one project, weekly checks, no card. Upgrade when the evidence is worth paying for.

Start free