Skip to main content
VibeAudit
runs locally read-only two real users

Introducing Trust Twin

Alice can.
Bob can't.
Prove it.

Most scanners test whether someone can log in. Trust Twin tests whether the wrong logged-in user can read Alice's data—the authorization failure behind IDOR and tenant leaks.

See the proof loop

Free first run. No account. Use a staging origin and two low-privilege test accounts you control.

TRUST TWIN / OWNED FIXTURE
local session
GET /api/projects/:idvalue redacted

Alice

owns this project

200
own resource allowed

Bob

different tenant

403
cross-actor denied

Anonymous

no session

401
unauthenticated denied

Clear in tested scope

DAST_AUTHZ_2A · local integrity seal

Interactive simulation on a disclosed first-party fixture—not a customer result or blanket security claim.

The counterfactual proof loop

One object.
Three identities.
One useful answer.

A normal happy-path test asks “can Alice see her project?” Trust Twin asks the question that creates trust: “what happens when Bob presents Alice's exact object reference?”

  1. 01

    Record Alice

    In an isolated browser, Alice signs in and opens the read-only resources that matter.

  2. 02

    Capture Bob

    A second isolated browser records Bob’s low-privilege test session on the same origin.

  3. 03

    Replay safely

    Only Alice’s observed GET/HEAD reads are replayed with Bob and anonymous credentials.

  4. 04

    Seal exact scope

    The report retains redacted templates and status facts—not credentials, bodies, or raw IDs.

Run it in about five minutes

Your credentials stay in two temporary browser contexts. The proof does not.

npx --yes github:paulchum/vibeaudit twin https://staging.your-app.com

What the free local report proves

  • Whether Bob or an anonymous caller received Alice’s tested resource
  • The exact redacted route templates and HTTP status facts observed
  • Whether the report changed after its local Ed25519 integrity seal

It does not prove app-wide security or independent VibeAudit observation. A shareable Launch Pass is server-backed, freshness-bound, and independently verifiable.

Fix → replay → prove

Turn “trust us” into a test your first customers can understand.

Run the Twin free. If it catches a leak, fix the exact route and replay the same evidence. When it clears, add a Launch Pass for server-backed proof your buyer can verify.

See Launch Pass pricing