Avalyz

Documentation

Getting started with Avalyz

Everything you need to run a test, prove your site is yours and connect Avalyz to your tools.

Get started in 3 steps

  1. Paste your app's address on the trial page: the free test starts without signing up.
  2. Read the report: the verdict, each finding with its screenshot and address, and what was not tested.
  3. Create your account to go further: Full mode, test account, scheduled monitoring, API.

Run a test Create my account

The ownership tag

It proves the site is yours and unlocks the deeper checks: read-only reading of your database, graduated load test.

Your personal token is shown at the first step of the guided trial, once signed in. Paste it into your site's home page:

<meta name="avalyz-verification" content="TON_JETON">

Or put it in the file /.well-known/avalyz-verification.txt. If your account's e-mail address is on the site's domain, there is nothing to do.

Open the guided trial

Integrations

All integrations, ready to copy · Download the MCP server

Frequently asked questions

Does Avalyz change my app?

By default, no: read-only, nothing is created or changed, and with a test account, the sign-in is the only form submitted. Write mode, only at your request, fills in and submits forms with test data: it requires proof that the site is yours (production) or your attestation that you have the right to test it (test environment), and never makes a real payment or deletes anything.

Does a report with no findings mean my app has no defects?

No. Avalyz proves what it saw; what was not tested is not covered, and the report says so.

Where is my data?

At Scaleway, in Paris (France), in the European Union. Retention periods and deletion: Security and data page.

Can I test a site that is not mine?

Only with its owner's permission. The deeper checks also require the ownership tag.

The 13 levels · Security and data