Introducing Trust Twin
Alice can.
Bob can't.
Prove it.
Most scanners test whether someone can log in. Trust Twin tests whether the wrong logged-in user can read Alice's data—the authorization failure behind IDOR and tenant leaks.
Free first run. No account. Use a staging origin and two low-privilege test accounts you control.
GET /api/projects/:idvalue redactedAlice
owns this project
Bob
different tenant
Anonymous
no session
Clear in tested scope
DAST_AUTHZ_2A · local integrity seal
Interactive simulation on a disclosed first-party fixture—not a customer result or blanket security claim.
The counterfactual proof loop
One object.
Three identities.
One useful answer.
A normal happy-path test asks “can Alice see her project?” Trust Twin asks the question that creates trust: “what happens when Bob presents Alice's exact object reference?”
- 01
Record Alice
In an isolated browser, Alice signs in and opens the read-only resources that matter.
- 02
Capture Bob
A second isolated browser records Bob’s low-privilege test session on the same origin.
- 03
Replay safely
Only Alice’s observed GET/HEAD reads are replayed with Bob and anonymous credentials.
- 04
Seal exact scope
The report retains redacted templates and status facts—not credentials, bodies, or raw IDs.
Run it in about five minutes
Your credentials stay in two temporary browser contexts. The proof does not.
npx --yes github:paulchum/vibeaudit twin https://staging.your-app.comWhat the free local report proves
- Whether Bob or an anonymous caller received Alice’s tested resource
- The exact redacted route templates and HTTP status facts observed
- Whether the report changed after its local Ed25519 integrity seal
It does not prove app-wide security or independent VibeAudit observation. A shareable Launch Pass is server-backed, freshness-bound, and independently verifiable.
Fix → replay → prove
Turn “trust us” into a test your first customers can understand.
Run the Twin free. If it catches a leak, fix the exact route and replay the same evidence. When it clears, add a Launch Pass for server-backed proof your buyer can verify.
