Early access · built in the UK
Two eyes on your stack. Evidence you can hand over.
Snoopios connects read-only to Supabase, Vercel, Cloudflare, GitHub and Stripe, runs real configuration checks every six hours, and keeps the evidence. When a customer sends a security questionnaire or the ICO asks a question, the answer is already written.
For teams of one to twenty. Flat price by project, never by headcount. No sales call.
- RLS enabled on every public tablePass
- No policy admits anon writesPass
- Preview deployments protectedFail
- DMARC policy is quarantine or rejectFail
- Default branch protectedPass
- Backups or PITR enabledToken expired · reconnect SupabaseUnknown
Compliance tools weren't built for your stack, or your budget.
Vanta and Drata start at five figures a year and are built around AWS and Okta. You're on Supabase and Vercel, you're the DPO and the on-call engineer, and the first enterprise customer just sent a forty-question spreadsheet.
The obligations don't wait
UK GDPR applies from your first user. Since June 2026 every controller needs a complaints procedure. A Stripe review wants a privacy policy that matches the code.
Nobody checks the things that matter
Is RLS on every table? Does any policy let anon write? Is a preview deployment open to the internet? The big platforms sync your user list and call it monitoring.
The documents rot
A privacy policy written once says things the code stopped doing months ago. That gap is a misrepresentation, not a typo.
How it works
- 01
Connect, read-only
Grant Snoopios read access through each provider's own consent screen. No write scope is ever requested. Revoke it from their dashboard any time.
- 02
Checks run every six hours
Each check is code with a recorded fixture. It returns pass, fail or unknown, and a check that can't run says unknown — it never says pass.
- 03
Evidence is kept, unchanged
Every run stores the raw response, a timestamp and a hash. Nothing is edited after the fact. Corrections are new rows.
- 04
Documents write themselves from the facts
The sub-processor register comes from what's connected. Every policy claim links to a live check, so a sentence the code no longer honours is flagged in the document.
What it checks
Thirty-nine read-only checks across five providers, each with a recorded fixture, and each one exists because it caught a real problem on a real app. More as customers ask.
Supabase
- RLS enabled on every public table
- no policy admits anon writes
- private schema closed to session roles
- search_path pinned on definer functions
- email confirmation on
- captcha on
- backups or PITR on
- SSL enforced
- production SMTP configured
- no undeclared public bucket
Vercel
- preview deployment protection on
- git fork protection on
- domains verified and configured
- sensitive-variable policy enforced
- cron routes reject unauthenticated calls
- SAML enforced or members reviewed
GitHub
- default branch protected
- Dependabot alerts on, none critical
- no .env committed
- .gitignore covers .env
- SECURITY.md and CODEOWNERS present
- outside collaborators reviewed
Cloudflare
- DNSSEC active
- TLS mode strict, minimum 1.2
- always HTTPS with HSTS
- no R2 bucket publicly exposed
- WAF managed ruleset deployed
- Bot Fight Mode on
Stripe
- every webhook endpoint enabled and pinned to an API version
- no failed deliveries in 30 days
- live mode with charges enabled
Your domain
- CSP, HSTS, frame-ancestors, nosniff
- HTTP redirects to HTTPS
- HSTS preload status
- SPF, DMARC and CAA present
- TLS 1.2 minimum, certificate not expiring
- security.txt present
- privacy page names a controller and a date
No model decides whether you pass. The full feasibility table, endpoint by endpoint, is published in the documentation.
The pack
The documents a customer, an auditor or the ICO asks for, generated from what's connected and checked against what's running. Every one is a draft for your review, and says so.
- Privacy policy, with a real last-updated date
- Record of processing activities
- Sub-processor register, derived from your connections
- Retention schedule
- Breach notification runbook, pre-filled, with the 72-hour clock
- Data subject request procedure
- Complaints procedure with the 30-day acknowledgement the 2025 Act requires
- Security questionnaire answer bank, grounded in check results
- Cyber Essentials self-assessment preparation
- SOC 2 and ISO 27001 readiness maps: every control, ticked as checked, documented or yours to answer
A trust page you can send instead of a spreadsheet
A public page per project with live check status, your document list and NDA-gated downloads. When a prospect's security reviewer asks, you send a link. Unknown shows as unknown there too.
Flat, published, by project.
No per-seat pricing, no per-framework upsell, no renewal uplift. Annual pays for ten months. Cancel monthly plans any time.
Free
£0Evaluate on one project
- One project
- Weekly checks
- Dashboard and findings
- No document exports
Solo
£29/month
- One project
- Checks every six hours
- Evidence vault, 12 months
- Full document pack
- Public trust page
Studio
£79/month
- Up to five projects
- Everything in Solo
- Questionnaire answer bank
- Agency white-label trust pages
Scale
£199/month
- Unlimited projects
- Everything in Studio
- SOC 2 and ISO 27001 readiness maps
- Auditor export package
- Priority support
For comparison: the cheapest enterprise platform starts around £4,400 a year. Vanta's entry tier for a team your size is about £10,000.
Questions we get asked
- Does Snoopios need write access to anything?
- No. Every connection is a read-only grant through the provider's own consent screen, and a check that would need write access does not get built. You can revoke access from the provider's dashboard at any time.
- What happens when a check can't run?
- It reports unknown, with the reason. Unknown is shown as grey everywhere, including your trust page, and never counts as a pass. An expired token is the usual cause and the fix is a reconnect.
- Is this legal advice, or a certification?
- Neither. Snoopios produces evidence of what was checked and when, and documents drafted from that evidence for your review. It never says a customer is compliant or certified, and it never brokers or bundles an audit.
- Can I get SOC 2 or ISO 27001 with it?
- The Scale tier maps your checks and documents to the SOC 2 common criteria and ISO 27001 controls and exports a package an auditor can read. The audit itself is between you and an audit firm. We can point you at firms that already accept this kind of evidence, as a referral and nothing more.
- Where is my data held?
- In the United Kingdom, with Supabase in the London region, hosted on Vercel. Evidence is stored per organisation with row-level security and is never shared between customers. The full processor list is in the privacy policy.
Built by the kind of company it's for.
Archema Labs runs five products on Supabase and Vercel with one developer. Every check in Snoopios exists because it caught something on one of them. The compliance pack is the one we wrote by hand, five times, before deciding to build the tool.
Connect one project. See what you'd have found out the hard way.
Free for one project, weekly checks, no card. Upgrade when the evidence is worth paying for.