CloakCheck fetches publicly reachable pages you provide and runs a fixed set of mechanical checks for invisible unicode, CSS-hidden text, and instruction-shaped language in places a human reader would not normally see. It is a diagnostic tool, not a security audit, not legal advice, and not a guarantee your site has no other vulnerabilities or manipulated content. A clean report means the specific patterns checked were not detected on the pages you submitted — it does not certify the absence of every possible prompt-injection technique, and it cannot check pages you did not submit (a fresh review posted after your scan runs is not covered until you scan again).
You must only submit URLs you are authorized to have scanned. CloakCheck makes ordinary HTTP GET requests only; it does not authenticate, does not submit forms, and does not attempt to modify anything on the pages it fetches.
The $29 charge is one-time, billed via Stripe, for a single 5-page report. It is non-refundable once the report has been generated, since the report is the deliverable. If payment succeeded but no report was generated due to a fault on our end, contact us with your Stripe session ID for a refund.
The service is provided as-is with no warranty. We are not liable for decisions made based on its output.