Avalyz

Method

How Avalyz works.

Paste your address. Avalyz understands your app, plays its journeys, checks thirteen levels and tells you whether you can ship.

The 13 levels · Test from your tool · Documentation

Trust

The 13 test levels

Avalyz proves what it saw; it promises nothing beyond that. Here is, level by level, what is checked today, how mature it is, and what lets you go further.

What maturity means

  • Solid : checked in depth on every test.
  • Real, passive : real checks, made by reading the site's answers, with no attack.
  • Real with a test account : real as soon as you give a test account.
  • Partial : only part of it is checked: the detail says which part.
  • Inventory only : what exists is found and counted; nothing is run.

The 13 levels

LevelWhat is checkedMaturityTo go further
Code analysisIn your repository's code: forgotten secrets, dependencies with a known vulnerability (public osv.dev database), risky code.PartialGive your repository address (Standard and Full modes). Type checking and ESLint are not run yet.
Unit testsYour unit tests are found and counted in your repository. They are not run.Inventory onlyRepository address: inventory. Running your tests is not available yet.
Component testsYour component tests (Storybook, Testing Library) are found and counted. They are not run.Inventory onlyRepository address: inventory. Running your tests is not available yet.
APIYour pages' calls to their API: server errors and slowness that reproduce; the OpenAPI description if it is published.PartialPublish your API's OpenAPI description: Avalyz reads it.
Data securityYour app's data services (Supabase, Firebase) found in the page, and what the page publishes about them.PartialOwnership tag: Avalyz reads your database with the page's public key, read-only, to check that it gives nothing to an anonymous visitor.
Journeys by roleWith a test account: sign-in, then exploration of the signed-in pages. Journeys by role are listed, not played.Real with a test accountGive a test account: the sign-in is the only form submitted.
Business rulesThe rules drawn from your app's description (limits, states, amounts), compared with the screens seen during the test.PartialDescribe your app with “From your idea” (Pro and Team plans).
Application securitySecurity headers, sensitive files left publicly accessible, security.txt file, parameter echoed back as is, open redirect, version leaks. Passive analysis, with no attack.Real, passiveNothing to do: checked on every test. It is not a penetration test.
PerformanceCore Web Vitals (LCP, CLS, TTFB), page weight, phone profile on a slow network, light load.SolidOwnership tag: graduated load test (10, 25, 50 simultaneous visits to the home page).
AccessibilityAccessibility defects linked to WCAG 2.2 and RGAA 4.1 criteria.SolidNothing to do: checked on every test. It is not an RGAA compliance audit.
Visual and languagesLayout on computer and phone, screenshots, comparison with the previous run, languages.SolidNothing to do: checked on every test.
ResilienceWhat your app does offline, on a slow network and when its API fails, in a real browser.SolidNothing to do: checked on every test.
CompliancePrivacy policy, legal notice, cookies set before consent, consent banner.Real, passiveNothing to do: checked on every test. It is not legal advice.

Measured against the market: the comparative benchmark will be published soon, with its method.

What remains out of reach

  • Penetration tests and any form of attack: Avalyz does not do them.
  • Running your code and your tests: today they are read and counted, not launched.
  • Journeys by role played end to end: they are listed, not played.
  • An RGAA compliance audit or legal advice.
  • What the test did not see: the report says what was not tested.

Test my app for free

Security and data · Documentation

Integrations

Test with Avalyz from your tool

Wherever you build your app, one gesture is enough. By default, every test is read-only: it changes nothing on your site, and signing in with your test account is the only form submitted.

One link, zero clicks

This link fills in the address and starts the test by itself: paste it anywhere (3 free tests per day per visitor).

https://avalyz.com/essai?url=TON_URL

Lovable, Bolt, v0, Replit

Add this badge to your README or your page: one click on it runs a test of your app.

Tested with Avalyz

Markdown

[![Tested with Avalyz](https://avalyz.com/av/badge.svg)](https://avalyz.com/essai?url=TON_URL)

HTML

<a href="https://avalyz.com/essai?url=TON_URL"><img src="https://avalyz.com/av/badge.svg" alt="Tested with Avalyz"></a>

Claude Code, Cursor

Paste this block into CLAUDE.md (Claude Code) or .cursorrules (Cursor): your assistant tests the app after every deployment and reads the report.

## Avalyz acceptance test
After every deployment, test the app with Avalyz (read-only by default) and read the report.
1. Run the command below.
curl -sS --max-time 150 -X POST https://avalyz.com/api/v1/tests -H "Authorization: Bearer $AVALYZ_API_KEY" -H "Content-Type: application/json" -d '{"url":"TON_URL","attendre":true}'
2. Read the JSON that comes back: "verdict" (GO, GO SOUS CONDITIONS, NO-GO, INCONCLUSIF), "pourquoi" (why), "constats" (findings: severite S1 to S4, titre) and "rapport_url" (a path to append to https://avalyz.com).
3. If the verdict is not GO, fix the S1 and S2 findings, redeploy, then run it again.
If "etat" is "en_cours" (still running), read https://avalyz.com/api/v1/tests/<id> again with the same key.
TA_CLE is your Avalyz API key: keep it in the AVALYZ_API_KEY environment variable and never write it into the repository.

Claude Desktop, Cowork (MCP)

Download the MCP server and add this block to your configuration: Claude runs the tests and reads the reports itself.

1. Download the file (once)

curl -O https://avalyz.com/av/integrations/avalyz_mcp.py

2. Add this block to the MCP configuration, then restart the app

{
  "mcpServers": {
    "avalyz": {
      "command": "python3",
      "args": ["/CHEMIN/VERS/avalyz_mcp.py"],
      "env": { "AVALYZ_API_KEY": "TA_CLE" }
    }
  }
}

In Claude Code, one command replaces step 2:

claude mcp add avalyz -e AVALYZ_API_KEY=TA_CLE -- python3 /CHEMIN/VERS/avalyz_mcp.py

GitHub Actions

Paste this file into .github/workflows/avalyz.yml: the test runs after every deployment and the CI fails if the verdict is NO-GO.

on:
  deployment_status:
jobs:
  avalyz:
    if: github.event.deployment_status.state == 'success'
    runs-on: ubuntu-latest
    steps:
      - name: Avalyz
        run: curl -fsS https://avalyz.com/api/av/outils/recette_ci.py -o recette_ci.py && python3 recette_ci.py
        env:
          AVALYZ_URL: TON_URL
          AVALYZ_SERVEUR: https://avalyz.com
          AVALYZ_CLE: ${{ secrets.AVALYZ_API_KEY }}  # TA_CLE: your API key, stored in the repository secrets (AVALYZ_API_KEY).

Before you copy

Replace TON_URL with your app's address and TA_CLE with your API key (the "API keys" page of your account, 14-day trial with no card). Never write it into a repository: keep it in an environment variable or a secret.

The link and the badge need no key. Without a test account, the test stops where access stops; with a test account (single page, panel), signing in is the only form submitted and the signed-in pages are explored read-only by default.

Create my account

Documentation

Getting started with Avalyz

Everything you need to run a test, prove your site is yours and connect Avalyz to your tools.

Get started in 3 steps

  1. Paste your app's address on the trial page: the free test starts without signing up.
  2. Read the report: the verdict, each finding with its screenshot and address, and what was not tested.
  3. Create your account to go further: Full mode, test account, scheduled monitoring, API.

Run a test Create my account

The ownership tag

It proves the site is yours and unlocks the deeper checks: read-only reading of your database, graduated load test.

Your personal token is shown at the first step of the guided trial, once signed in. Paste it into your site's home page:

<meta name="avalyz-verification" content="TON_JETON">

Or put it in the file /.well-known/avalyz-verification.txt. If your account's e-mail address is on the site's domain, there is nothing to do.

Open the guided trial

Integrations

  • Lovable, Bolt, v0, Replit: a “Tested with Avalyz” badge to paste, which runs the test of your app.
  • Claude Code, Cursor: a block of instructions that calls the Avalyz API after each deployment.
  • Claude Desktop, Cowork, Claude Code: the Avalyz MCP server, three tools: avalyz_test_url, avalyz_get_report, avalyz_list_tests.
  • Continuous integration: a script for GitHub Actions, GitLab and Bitbucket; GitHub pull request comment.
  • Alerts and follow-up: e-mail, signed webhook, Slack, Teams; Jira export.
  • API described in OpenAPI, with API keys per account.

All integrations, ready to copy · Download the MCP server

Frequently asked questions

Does Avalyz change my app?

By default, no: read-only, nothing is created or changed, and with a test account, the sign-in is the only form submitted. Write mode, only at your request, fills in and submits forms with test data: it requires proof that the site is yours (production) or your attestation that you have the right to test it (test environment), and never makes a real payment or deletes anything.

Does a report with no findings mean my app has no defects?

No. Avalyz proves what it saw; what was not tested is not covered, and the report says so.

Where is my data?

At Scaleway, in Paris (France), in the European Union. Retention periods and deletion: Security and data page.

Can I test a site that is not mine?

Only with its owner's permission. The deeper checks also require the ownership tag.

The 13 levels · Security and data