Trust
The 13 test levels
Avalyz proves what it saw; it promises nothing beyond that. Here is, level by level, what is checked today, how mature it is, and what lets you go further.
What maturity means
- Solid : checked in depth on every test.
- Real, passive : real checks, made by reading the site's answers, with no attack.
- Real with a test account : real as soon as you give a test account.
- Partial : only part of it is checked: the detail says which part.
- Inventory only : what exists is found and counted; nothing is run.
The 13 levels
| Level | What is checked | Maturity | To go further |
|---|---|---|---|
| Code analysis | In your repository's code: forgotten secrets, dependencies with a known vulnerability (public osv.dev database), risky code. | Partial | Give your repository address (Standard and Full modes). Type checking and ESLint are not run yet. |
| Unit tests | Your unit tests are found and counted in your repository. They are not run. | Inventory only | Repository address: inventory. Running your tests is not available yet. |
| Component tests | Your component tests (Storybook, Testing Library) are found and counted. They are not run. | Inventory only | Repository address: inventory. Running your tests is not available yet. |
| API | Your pages' calls to their API: server errors and slowness that reproduce; the OpenAPI description if it is published. | Partial | Publish your API's OpenAPI description: Avalyz reads it. |
| Data security | Your app's data services (Supabase, Firebase) found in the page, and what the page publishes about them. | Partial | Ownership tag: Avalyz reads your database with the page's public key, read-only, to check that it gives nothing to an anonymous visitor. |
| Journeys by role | With a test account: sign-in, then exploration of the signed-in pages. Journeys by role are listed, not played. | Real with a test account | Give a test account: the sign-in is the only form submitted. |
| Business rules | The rules drawn from your app's description (limits, states, amounts), compared with the screens seen during the test. | Partial | Describe your app with “From your idea” (Pro and Team plans). |
| Application security | Security headers, sensitive files left publicly accessible, security.txt file, parameter echoed back as is, open redirect, version leaks. Passive analysis, with no attack. | Real, passive | Nothing to do: checked on every test. It is not a penetration test. |
| Performance | Core Web Vitals (LCP, CLS, TTFB), page weight, phone profile on a slow network, light load. | Solid | Ownership tag: graduated load test (10, 25, 50 simultaneous visits to the home page). |
| Accessibility | Accessibility defects linked to WCAG 2.2 and RGAA 4.1 criteria. | Solid | Nothing to do: checked on every test. It is not an RGAA compliance audit. |
| Visual and languages | Layout on computer and phone, screenshots, comparison with the previous run, languages. | Solid | Nothing to do: checked on every test. |
| Resilience | What your app does offline, on a slow network and when its API fails, in a real browser. | Solid | Nothing to do: checked on every test. |
| Compliance | Privacy policy, legal notice, cookies set before consent, consent banner. | Real, passive | Nothing to do: checked on every test. It is not legal advice. |
What remains out of reach
- Penetration tests and any form of attack: Avalyz does not do them.
- Running your code and your tests: today they are read and counted, not launched.
- Journeys by role played end to end: they are listed, not played.
- An RGAA compliance audit or legal advice.
- What the test did not see: the report says what was not tested.