Ship it. Then just say “check it.”
Opviva is a security agent you talk to. Tell it what you shipped — it scans your live app and code, proves each exploit is real, and opens the fix as a pull request you approve in one click. Then it keeps watching. No live site yet? Connect your repo and it grades your code — no domain needed.
Free · no signup for the URL scan · 1 free code scan every day · we never store your source code
You shipped your app in a weekend.
- Security headersExposed
- Exposed Supabase keyExposed
- Public .env fileExposed
- Detected
- Analyzing
- Writing the patch
- Pull request opened
Sources: Escape.tech mass scan & vibe-coding security studies, 2026.
How Opviva works
Four steps, one agent. You stay in control — it does the security work end to end.
- 1
You tell it what you shipped
In plain language, or just paste your app's URL. No scanners to configure, no dashboards to learn.
- 2
It proves the exploit
Opviva scans your live app and code, then reproduces each real vulnerability — so you see the impact, not a maybe.
- 3
It opens the fix
The agent writes the fix and opens a pull request. Small ones auto-merge; risky ones wait for your one-click approval.
- 4
It keeps watching
After launch it monitors your app and attack surface, and comes back the moment something new shows up.
A scanner hands you a list. Opviva does the work.
Most tools stop at “here are some maybe-issues.” Opviva proves each one, ships the fix, and keeps watching.
Typical security scanner
- Hands you a list of maybe-issues
- You triage and verify every finding
- You write and ship every fix yourself
- Drowns you in false positives
- One-time scan, then you're on your own
- Configure the tool, read the docs
Opviva
- Proves each exploit is real — reproduced, not guessed
- It does the triage — you see only confirmed issues
- Writes the fix and opens a pull request you approve in one click
- No noise — only real, reproduced findings
- Keeps watching your app and attack surface 24/7
- Just talk to it in plain language
What the free scan checks
A URL-only shallow scan — no code access — surfaces the exact issues AI builders ship. No live URL? Connect a repo instead: the agent scans your code, dependencies, and secrets with no domain needed — 1 code scan free every day.
Security headers
Missing CSP, HSTS, clickjacking and MIME-sniff protection.
Exposed secrets
API keys and an exposed Supabase service_role key in your bundle.
Sensitive files
Publicly downloadable .env and .git directories.
HTTPS & cookies
Insecure cookies, weak transport, and stack disclosure.
Not another dashboard. An agent that does the work.
Security tools hand you findings and leave the hard part — proving they're real and fixing them — to you. Opviva is the opposite: you talk to one agent, it proves each exploit, ships the fix as a pull request you approve, and keeps watching. You stay in control; it does the work.
Your code stays yours
We never store your source. Scans run, then drop it.
Read-only by default
Least-privilege GitHub access. You approve risky fixes.
Every fix is reviewable
Changes ship as pull requests you can read before merging.
Watch it prove the exploit
The agent doesn't just flag an issue — it reproduces it on a live Evidence Canvas. An AI agent logs in as itself, with valid credentials, so a bad decision hides inside a chain of tool calls. Opviva records every step, append-only and sealed, so you can prove exactly what happened and that the record was never touched.
One agent's session, replayed newest first. It handled a refund normally — then quietly overstepped. Opviva caught it and sealed an unforgeable record.
Opviva flagged the action and sealed the sessionCaught & sealed
2026-06-20T14:02:56Z
checkout-agent ran DELETE FROM users — outside its allowed scopeThe violation
2026-06-20T14:02:55Z
checkout-agent issued a ₹4,200 refund to the original method
2026-06-20T14:02:44Z
checkout-agent queried the orders table for order #80421
2026-06-20T14:02:43Z
checkout-agent received a refund request from a customer
2026-06-20T14:02:41Z
Every step is sealed and linked to the one before it — edit or delete any of them and the record visibly breaks, so it can't be forged. Illustrative reconstruction.
No surprises. You stay in control.
Our promise: nothing merges without your one-click approval, we never store your source, and you can cancel anytime.
Will it break my app?
No. Every fix ships as a pull request you review and approve — nothing merges without your one-click OK. Read-only by default.
Do you keep my source code?
Never. Scans run and the code is dropped — we never store it. GitHub access is least-privilege and you stay in control.
Is the scan really free?
Yes — the scan and letter grade are free forever, no card. You only pay if you want the agent fixing and watching for you.
What if I'm not technical?
You don't need to be. Paste a URL or talk to the agent in plain language — it does the security work and explains every finding.
Simple, honest pricing
Start free — 1 code scan every day, no card. Plans are credit bundles, not feature locks — and 24/7 monitoring is a per-app add-on funded by credits. Cancel anytime.
Free
See where you stand — free.
- 1 free code scan every day
- Credits power everything else — top up anytime
- Plain-English proof of what it finds
- Security score (0–100)
Starter
The agent watches your app.
No GST · billed in USD
24/7 monitoring
Weekly · 200 cr/app
Daily · 1,300 cr/app
- ≈ 40 code scans or 8 fix PRs / mo
- Alerts the moment something regresses
- Proof on every finding, on the Evidence Canvas
- Credits roll over one month
Growth
It watches — and opens the fixes.
No GST · billed in USD
4,500 + 500 bonus
24/7 monitoring
Weekly · 200 cr/app
Daily · 400 cr/app · up to 3 apps
- ≈ 100 code scans or 20 fix PRs / mo
- Agent-opened fix PRs, ready to review
- One-click approval; small fixes auto-merge
- Credits roll over one month
Scale
Hands-off. The agent runs security.
No GST · billed in USD
9,900 + 1,000 bonus
24/7 monitoring
Weekly · 200 cr/app
Daily · 200 cr/app · up to 10 apps
- ≈ 218 code scans or 43 fix PRs / mo
- Everything in Growth, priority queue
- Dependency upgrades handled for you
- Priority incident response
Frequently asked questions
What is Opviva?
Opviva is an AI security agent for AI-built apps that you talk to. You describe what you shipped in plain language; it scans your live app and code, proves each vulnerability is real by reproducing the exploit, opens the fix as a pull request you approve in one click, and keeps watching after launch — all on a live Evidence Canvas.
Is Opviva the same as Opvia?
No — they're unrelated. Opviva (opviva.com) is an AI application-security agent for apps built with Lovable, Bolt, Cursor, and v0. It is not affiliated with Opvia, the offshore-talent and business-consulting firm, or any other similarly named company. If you searched for 'opviva' and were shown 'opvia', you're in the right place now.
How is Opviva different from a normal security scanner?
A scanner hands you a list of maybe-issues and leaves the work to you. Opviva is an agent: it proves each finding is real by reproducing it, then writes the fix and opens it as a reviewable pull request that merges on your one-click approval — and it keeps monitoring after launch. You talk to it in plain language instead of configuring tools.
Is my AI-built app secure?
Often not by default. In a 2026 mass scan, 91.5% of AI-generated apps had a vulnerability — commonly exposed API or Supabase keys, missing access control, a public .env, or no security headers. Opviva's free scan grades your live app in seconds so you know.
How does the free security scan work?
Paste your app's URL, or just tell the agent to check your app. Opviva inspects the live response headers and front-end bundle for exposed secrets, sensitive files, and missing protections, then gives a 0–100 score and a letter grade with a plain-English report. No signup, no source-code access. Every account also gets 1 free code scan a day — connect your repo and the agent scans your code, dependencies, and secrets, no domain needed.
What does it mean that Opviva 'proves the exploit'?
Instead of a theoretical warning, Opviva reproduces the vulnerability — for example reading another user's data through a missing Row-Level Security policy, or pulling an exposed service_role key from your bundle — and records every step on a tamper-evident Evidence Canvas. You see the real impact, not a maybe.
Can Opviva fix the issues automatically?
Yes. The agent writes the fix and opens it as a pull request. Small, safe fixes can auto-merge; higher-risk changes wait for your one-click approval so you always stay in control. It keeps monitoring after the fix ships.
Which platforms does Opviva support?
Any live web app, including those built with Lovable, Bolt, v0, Replit, Cursor, Claude Code, and Emergent. Non-developers just talk to the agent or paste a URL; developers can use the API, CLI, and CI.
Do I need a live domain to use Opviva?
No — connect your GitHub repo and the agent scans your code, dependencies, and secrets, then grades you with no domain at all. Perfect for half-finished apps, side projects, and student work. A verified domain unlocks the live side: 24/7 monitoring and attack-surface testing against your running app.
Do you store my source code?
No. Scans run and the code is dropped — we never store your source. GitHub access is least-privilege and you approve risky fixes before they merge.
How much does Opviva cost?
Everything runs on one credit balance — a code scan is 50 credits, a fix PR is 250, and 24/7 monitoring is a per-app, opt-in add-on funded by credits. You get 1 free code scan every day — see where you stand, free, no card. Plans (Starter, Growth, Scale) are credit bundles with bonus credits and a cheaper monitoring rate, not feature locks; any credits — plan, top-up, bonus, or referral — spend the same. See the pricing page for current rates in your currency.
How do I add Row Level Security to my Supabase app?
Enable RLS on every table in the Supabase dashboard and write per-user policies, then make sure the service_role key is only used server-side. Or just ask Opviva — the agent proves the gap, then opens a reviewed pull request that adds RLS and moves the key off the client for you.
