Start here
Quickstart — from scan to verified fix
The whole loop in five steps: scan, audit, read results, fix, verify.
1 · Scan your domain
Start free on the homepage: enter a domain and get a scored pre-check in about ten seconds. Every failing check comes with a fix written to stand alone — most teams clear several grades of issues in an afternoon. Working against localhost? Tunnel it (e.g. cloudflared) and scan the tunnel URL; the fix loop works pre-deploy.
2 · Run an audit
From the audit page, tell us what to evaluate — an MCP server URL, an npm/PyPI package, or a CLI — and we generate an evaluation plan: a scenario pack for your target type plus scenarios derived from your documentation. You see the full plan (every scenario, everything it proves) for free, then request the audit in one click — we reply within a business day to agree scope and price, and the plan you previewed is hash-pinned to the plan that runs.
If your target needs credentials, you submit them once the audit is set up — sealed in your browser to the audit worker's key, unreadable by us, and verified by a pre-flight gate before any agent run is spent (details).
3 · Watch, then read the results
Runs stream live to your results page. When they finish you get the verdict, the scenario × agent matrix with confidence intervals, AI-drafted findings (human-reviewed before you see them), per-run timelines, and downloadable evidence for every claim (what each layer means).
4 · Fix — with your own coding agent, if you like
The results page has a Fix with your coding agent card. Connect Claude Code or Cursor and your agent pulls each finding with its evidence, repro steps, and acceptance criteria over MCP — no copy-pasting from reports:
claude mcp add --transport http vorza-audit \ https://www.vorza.dev/api/mcp/audit \ --header "Authorization: Bearer <credential from your results page>"
In Claude Code, /fix_finding f-001 pulls a complete fix brief (the Fix Loop, in full).
5 · Verify, then keep it green
Deploy the fix and re-run exactly the failing scenarios — one free re-run is included, from the results page button or your agent's request_fix_verification call. Then put the plan on a schedule with monitoring, so the next agent-client release can't quietly break what just passed.