Tools you can run yourself

Our services are people doing the work. Our products are tools you run on your own, in minutes, with no sales call. Two tools, each answering one question.

Audit note: 1.3.1Passes Each product is its own section under its own heading, so a screen reader user can jump between them by heading.

Accessibility

CodexMotive Audit

Paste a URL and get an automated check of the page against WCAG 2.1 AA and AODA. Every failure comes with what it is, who it blocks, and how to fix it, ranked by severity.

What it checks
A live, rendered web page, against WCAG 2.1 AA and AODA
What it doesn't
It's automated, so it finds what a scanner can. A person testing with a screen reader finds more; that's our manual audit.
Price
Free, no account needed
What a finding looks like in Audit

Serious

Form fields have no labels.

The email and phone inputs rely on placeholder text. A screen reader announces "edit text" with no name, and the hint disappears as soon as someone starts typing.

Fix
Add a visible <label for> to each field.
WCAG
1.3.1 Info and Relationships

Security

CodexMotive Shield

It works. That's not the same as safe.

For apps built with an AI coding assistant. Connect the repository and Shield checks what was actually written: exposed credentials, vulnerable dependencies and flaws in the code. Then it tells you, in plain language, which findings are launch blockers and which aren't.

What it checks
Three scans on every check: a code scan (injection, broken access control, weak cryptography and nine more kinds of flaw), a credential scan, and a dependency scan of your lockfiles
AI Review
Paid checks include AI Review by Anthropic's Claude. It gets the findings, never your source code, and explains the real risk, what to fix first, and a fix you can hand to your coding assistant.
Your code
Read, never built, installed or run. Credentials are masked before anything leaves. Delete your account and the projects, history and tokens go with it.
Price
One free check per repository, no card. Paid plans are in USD: compare Shield plans.
What a finding looks like in Shield (from its demo report)

Critical

Anyone signed in can read every user's data.

The row-level security policy on profiles uses USING (true), so any logged-in account can select every row.

Where
supabase/migrations/0002_profiles.sql
Verdict
Launch blocker

Why two tools, not one

Checking accessibility honestly means looking at the rendered page, which means running your site. Audit does exactly that.

Checking code safely means never running it. Shield only reads your files, so nothing in your repository ever executes on our machines.

Two boundaries, so two products. If you're shipping a web app, you likely want both.

Need a person, not a tool?

A scanner tells you what it found. Our team tests the way your users do, fixes it, and stands behind the result.