-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathBuildSecure.html
More file actions
452 lines (410 loc) · 23.4 KB
/
Copy pathBuildSecure.html
File metadata and controls
452 lines (410 loc) · 23.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
<!DOCTYPE html>
<html lang="en" itemscope itemtype="https://schema.org/WebPage">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no">
<title>BuildSecure — web editor & AI security scans</title>
<meta name="description"
content="BuildSecure: Monaco editor in the browser with AI-assisted security scans—secrets, vulns, crypto, SEO, HTTPS URL checks, OSV deps. Groq, Ollama Cloud, or Google Gemini. Sign-in (Supabase); optional Stripe credits for scan tools.">
<meta name="author" content="OffCrypt">
<meta name="last-modified" content="2026-03-21">
<meta name="keywords"
content="buildsecure, code editor, online editor, security scan, OSV, groq, ollama cloud, gemini, github, supabase, stripe, website scan">
<meta name="robots" content="index, follow">
<meta property="og:type" content="website">
<meta property="og:locale" content="en_US">
<meta property="og:url" content="https://www.dev-offcode.com/BuildSecure.html">
<meta property="og:title" content="BuildSecure — web editor & AI security scans">
<meta property="og:description"
content="Browser editor plus AI scans for secrets, vulns, crypto, SEO, and HTTPS URLs. Groq, Ollama Cloud, or Gemini. GitHub proxy, optional server tools, Supabase auth, optional Stripe scan credits.">
<meta property="og:image" content="https://www.dev-offcode.com/BuildSecureLogo.png">
<meta property="og:image:width" content="1200">
<meta property="og:image:height" content="630">
<meta property="og:image:alt" content="BuildSecure Logo">
<meta name="twitter:card" content="summary_large_image">
<meta name="twitter:site" content="@OffCryptAndroid">
<meta name="twitter:creator" content="@OffCryptAndroid">
<meta name="twitter:url" content="https://www.dev-offcode.com/BuildSecure.html">
<meta name="twitter:title" content="BuildSecure — web editor & AI security scans">
<meta name="twitter:description"
content="Monaco editor + AI security scans (Groq, Ollama Cloud, or Gemini). Secrets, crypto, SEO, website scan, OSV. GitHub proxy; optional premium scan credits.">
<meta name="twitter:image" content="https://www.dev-offcode.com/BuildSecureLogo.png">
<!-- Social Media Links -->
<meta property="og:see_also" content="https://www.instagram.com/off.crypt86/">
<meta property="og:see_also" content="https://www.youtube.com/@OffCrypt">
<meta name="instagram:site" content="@off.crypt86">
<meta name="youtube:channel" content="@OffCrypt">
<link rel="canonical" href="https://www.dev-offcode.com/BuildSecure.html">
<link rel="alternate" hreflang="en" href="https://www.dev-offcode.com/BuildSecure.html">
<link rel="alternate" hreflang="x-default" href="https://www.dev-offcode.com/BuildSecure.html">
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" sizes="180x180" href="/apple-touch-icon.png">
<link rel="icon" type="image/png" sizes="32x32" href="/favicon-32x32.png">
<link rel="icon" type="image/png" sizes="16x16" href="/favicon-16x16.png">
<link rel="manifest" href="/manifest.json">
<!-- Preload critical resources -->
<link rel="preload" href="styles.css?v=2.8.0" as="style">
<link rel="preload" href="gallery-simple.css?v=2.8.0" as="style">
<!-- Core Web Vitals optimization -->
<meta name="theme-color" content="#00ff88">
<meta name="msapplication-TileColor" content="#00ff88">
<link rel="stylesheet" href="styles.css?v=2.8.0">
<link rel="stylesheet" href="gallery-simple.css?v=2.8.0">
<style>
.buildsecure-hero-shot {
margin: 1.25rem auto 2rem;
max-width: min(100%, 920px);
border-radius: 12px;
overflow: hidden;
border: 1px solid rgba(0, 255, 136, 0.22);
box-shadow:
0 0 0 1px rgba(0, 0, 0, 0.35),
0 12px 48px rgba(0, 255, 136, 0.08),
0 24px 80px rgba(0, 102, 255, 0.06);
}
.buildsecure-youtube-wrap {
position: relative;
width: 100%;
padding-bottom: 56.25%;
height: 0;
overflow: hidden;
background: #0d1117;
}
.buildsecure-youtube-wrap iframe {
position: absolute;
top: 0;
left: 0;
width: 100%;
height: 100%;
border: 0;
}
.buildsecure-hero-hint {
display: block;
text-align: center;
font-size: 0.8rem;
color: rgba(200, 220, 210, 0.65);
margin: 0.5rem 0 0;
letter-spacing: 0.02em;
}
.buildsecure-coming-soon {
text-align: center;
padding: 2.25rem 1rem 2.75rem;
margin-top: 0;
border-top: 1px solid rgba(0, 255, 136, 0.1);
}
.buildsecure-coming-soon p {
margin: 0;
font-size: 0.95rem;
color: rgba(200, 220, 210, 0.45);
letter-spacing: 0.12em;
}
</style>
</head>
<body>
<!-- Sidebar Navigation -->
<aside class="sidebar">
<div class="sidebar-header">
<div class="sidebar-title">OffCode</div>
</div>
<nav class="sidebar-nav">
<ul class="sidebar-menu">
<li class="menu-item">
<a href="index.html" class="menu-link">
<span class="menu-icon">📱</span>
<span class="menu-text">Android App</span>
</a>
</li>
<li class="menu-item">
<a href="OffCryptDesktop.html" class="menu-link">
<span class="menu-icon">💻</span>
<span class="menu-text">Desktop App</span>
</a>
</li>
<li class="menu-item">
<a href="ScreenLockBuilder.html" class="menu-link">
<span class="menu-icon">🔒</span>
<span class="menu-text">Screen Lock Builder</span>
</a>
</li>
<li class="menu-item">
<a href="ScreenLockBuilderPremium.html" class="menu-link">
<span class="menu-icon">⭐</span>
<span class="menu-text">Premium Builder</span>
</a>
</li>
<li class="menu-item">
<a href="AutomationTool.html" class="menu-link">
<span class="menu-icon">🤖</span>
<span class="menu-text">Automation Tool</span>
</a>
</li>
<li class="menu-item active">
<a href="BuildSecure.html" class="menu-link">
<span class="menu-icon">🛡️</span>
<span class="menu-text">BuildSecure</span>
</a>
</li>
<li class="menu-item">
<a href="RemoteControl.html" class="menu-link">
<span class="menu-icon">🌐</span>
<span class="menu-text">Web Remote Control</span>
</a>
</li>
<li class="menu-item">
<a href="https://ko-fi.com/emptyc0de" class="menu-link" target="_blank" rel="noopener noreferrer">
<span class="menu-icon">💝</span>
<span class="menu-text">Donate</span>
</a>
</li>
<li class="menu-item">
<a href="PrivacyPolicy.html" class="menu-link">
<span class="menu-icon">🔐</span>
<span class="menu-text">Privacy Policy</span>
</a>
</li>
</ul>
</nav>
<div class="sidebar-footer">
<p class="footer-text">Social media</p>
<div class="sidebar-social-divider"></div>
<div class="sidebar-social">
<a href="https://x.com/OffCryptAndroid" target="_blank" rel="noopener noreferrer"
aria-label="Follow OffCrypt on X">
<span class="sidebar-social-icon">🐦</span>
<span class="sidebar-social-label">X</span>
</a>
<a href="https://www.instagram.com/off.crypt86/" target="_blank" rel="noopener noreferrer"
aria-label="Follow OffCrypt on Instagram">
<span class="sidebar-social-icon">📸</span>
<span class="sidebar-social-label">Instagram</span>
</a>
<a href="https://www.tiktok.com/@offcrypt0" target="_blank" rel="noopener noreferrer"
aria-label="Follow OffCrypt on TikTok">
<span class="sidebar-social-icon">🎵</span>
<span class="sidebar-social-label">TikTok</span>
</a>
<a href="https://www.youtube.com/@OffCrypt" target="_blank" rel="noopener noreferrer"
aria-label="Follow OffCrypt on YouTube">
<span class="sidebar-social-icon">▶️</span>
<span class="sidebar-social-label">YouTube</span>
</a>
<a href="https://bsky.app/profile/off-crypt86.bsky.social" target="_blank" rel="noopener noreferrer"
aria-label="Follow OffCrypt on Bluesky">
<span class="sidebar-social-icon">🦋</span>
<span class="sidebar-social-label">Bluesky</span>
</a>
<a href="https://www.linkedin.com/in/off-crypt-b94175382/" target="_blank" rel="noopener noreferrer"
aria-label="Follow OffCrypt on LinkedIn">
<span class="sidebar-social-icon">💼</span>
<span class="sidebar-social-label">LinkedIn</span>
</a>
</div>
</div>
</aside>
<!-- Mobile Menu Toggle -->
<button class="mobile-menu-toggle" aria-label="Toggle Menu">
<span class="hamburger"></span>
</button>
<!-- Main Content Wrapper -->
<div class="main-wrapper">
<main>
<!-- App Description Section -->
<section class="intro-section">
<div class="intro-container">
<div class="intro-content">
<!-- Hero Header -->
<h1 class="hero-title">🛡️ BuildSecure</h1>
<p class="hero-subtitle">Web editor, AI-assisted scans, and finding follow-ups in one workflow
</p>
<div class="hero-glow-divider"></div>
<figure class="buildsecure-hero-shot">
<div class="buildsecure-youtube-wrap">
<iframe src="https://www.youtube.com/embed/bq3DuH-b9DI?rel=0"
title="BuildSecure — walkthrough of AI-assisted security scanning"
allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share"
allowfullscreen loading="eager"
referrerpolicy="strict-origin-when-cross-origin"></iframe>
</div>
<figcaption class="buildsecure-hero-hint">See how scanning works — embedded from YouTube;
press play to watch</figcaption>
</figure>
<p class="intro-description lead-text">Shipping features quickly—whether using AI tools, working
in a small team, or operating under tight deadlines—often leaves limited time for formal
security reviews. As a result, issues such as exposed API keys, weak cryptographic
implementations,
and vulnerable dependencies still appear in real-world codebases.</p>
<p class="intro-description"><strong>BuildSecure</strong> is designed to support this gap. It
does
not replace a full penetration test, but it enables developers to run structured security
checks directly within the same working session before deployment. This includes scanning
for secrets,
common vulnerabilities, cryptographic issues, dependency-related risks, and SEO
audits—without switching
to
a separate toolchain.</p>
<div class="intro-highlights">
<div class="highlight-item">
<span class="highlight-icon">💻</span>
<span class="highlight-text">Code Editor</span>
</div>
<div class="highlight-item">
<span class="highlight-icon">🤖</span>
<span class="highlight-text">AI scans (LLM)</span>
</div>
<div class="highlight-item">
<span class="highlight-icon">🔒</span>
<span class="highlight-text">Security Scans</span>
</div>
<div class="highlight-item">
<span class="highlight-icon">🐙</span>
<span class="highlight-text">GitHub Proxy</span>
</div>
<div class="highlight-item">
<span class="highlight-icon">🌐</span>
<span class="highlight-text">HTTPS site check</span>
</div>
</div>
</div>
</div>
</section>
<!-- Modern Section Divider -->
<div class="section-divider"></div>
<!-- Features Section -->
<section id="features" class="features-section">
<div class="features-container">
<h2 class="features-title">Features</h2>
<div class="features-grid">
<!-- Premium Code Editor -->
<div class="feature-card">
<div class="feature-icon">💻</div>
<h3>Code editor</h3>
<p>Monaco in the browser—same family of editing tools as VS Code. Read and edit code in one
place, then attach the same files to scans in the side panel without switching apps.</p>
<ul class="feature-list">
<li>Syntax highlighting, minimap, folding, bracket pair colorization</li>
<li>Built-in suggestions where Monaco ships a language worker (ordinary IntelliSense—not
the AI filling your buffer)</li>
<li>Open a local folder via the File System API, or load a GitHub repo through the proxy
(see below)</li>
<li>Multiple files open; tab strip for quick switching while you review or refactor</li>
</ul>
</div>
<!-- AI scans -->
<div class="feature-card">
<div class="feature-icon">🤖</div>
<h3>AI scans & sessions</h3>
<p>Scan-first side panel: choose provider, model, and reasoning level, then run repo-side
scans or open the website URL flow—everything stays in one layout next to the editor.
</p>
<ul class="feature-list">
<li>Pick <strong>Groq</strong>, <strong>Ollama Cloud</strong>, or <strong>Google
Gemini</strong> and a model in the panel</li>
<li>No free-text chat field: start scans from the panel buttons (with confirmation);
follow-ups come from finding-card actions in the same thread. Toggle context
options—current file, open tabs, project tree—so each run only sees what you
intend</li>
<li>After a security or SEO scan, findings appear as cards. <strong>Give fix
code</strong> (security) or <strong>Ask for implementation details</strong>
(SEO) sends one follow-up with that finding baked in; the reply stays in the thread
for you to copy or paste into the editor yourself. There is no agentic mode and no
automatic file writes—the assistant does not change your project on its own</li>
<li>Session tabs and saved scan history sync to your account on the API</li>
</ul>
</div>
<!-- Security & DevOps Scanning -->
<div class="feature-card">
<div class="feature-icon">🔍</div>
<h3>Source Code Scanning</h3>
<p>Analyze files or entire projects to identify potential security and quality issues.</p>
</div>
<div class="feature-card">
<div class="feature-icon">🔑</div>
<h3>Secrets Detection</h3>
<p>Detect exposed API keys, tokens, and other sensitive data.</p>
</div>
<div class="feature-card">
<div class="feature-icon">🔐</div>
<h3>Encryption Checks</h3>
<p>Review cryptographic usage (e.g., AES-GCM) to identify incorrect or unsafe
implementations.</p>
</div>
<div class="feature-card">
<div class="feature-icon">🛡️</div>
<h3>Vulnerability Scanning</h3>
<p>Identify common security risks such as injection vectors, misconfigurations, and unsafe
patterns.</p>
</div>
<div class="feature-card">
<div class="feature-icon">📦</div>
<h3>Dependency Signals</h3>
<p>Surface potential risks in dependencies by analyzing manifest content (via OSV when
available).</p>
</div>
<div class="feature-card">
<div class="feature-icon">📈</div>
<h3>SEO Review</h3>
<p>Evaluate web-related code for basic search engine optimization issues.</p>
</div>
<!-- Website scan -->
<div class="feature-card">
<div class="feature-icon">🌐</div>
<h3>Website scan (HTTPS)</h3>
<p>Separate from repo analysis: a quick read on <strong>one public page</strong>—useful for
a marketing site or docs front page, not a substitute for testing a logged-in app.</p>
<ul class="feature-list">
<li>Choose <strong>Website-scan</strong> in the panel; paste a URL. Only
<strong>HTTPS</strong> is accepted (HTTP is rejected in the UI)
</li>
<li>The API fetches that response once (SSRF protections; redirects may land on a final
URL). Pattern checks plus an LLM summary with your chosen <strong>Groq</strong>,
<strong>Ollama Cloud</strong>, or <strong>Gemini</strong> model
</li>
<li><strong>Not</strong> a crawl, login flow, or authenticated API test—you only see
what that URL returns publicly</li>
</ul>
</div>
<!-- Seamless GitHub Integration -->
<div class="feature-card">
<div class="feature-icon">🐙</div>
<h3>GitHub</h3>
<p>Browse a repository without leaving BuildSecure: tree and file contents go through your
backend proxy, so the browser never calls GitHub directly—CORS stays clean and
credentials never ship to the client.</p>
<ul class="feature-list">
<li>Enter <strong>owner</strong> and <strong>repository</strong>; the UI builds a folder
tree from <code>HEAD</code> and opens files on demand</li>
<li>Proxy endpoints require a <strong>signed-in</strong> BuildSecure user (JWT), so
anonymous visitors cannot burn your GitHub rate limit</li>
<li>Which repositories open depends on the <strong>server-side</strong> GitHub setup
(public repos; private only if the deployer configured a PAT with access—shared for
the deployment, not per viewer’s own GitHub account)</li>
</ul>
</div>
</div>
</div>
</section>
<div class="buildsecure-coming-soon" role="status" aria-live="polite">
<p>Coming soon...</p>
</div>
</main>
</div>
<!-- External JS Libraries -->
<script src="https://cdnjs.cloudflare.com/ajax/libs/Swiper/11.0.5/swiper-bundle.min.js"
integrity="sha384-T6qkM4ANslBL/pKcwNUeB0bpsiI6pkXXzwrl7Avc6FXEC/UZaXAeBpZZ2zQ3Zbez" crossorigin="anonymous"
data-cfasync="false"></script>
<!-- Application JavaScript -->
<script src="script.js" defer></script>
<script src="gallery.js" defer></script>
<!-- Semantic Footer for SEO -->
<footer role="contentinfo" style="display: none;">
<p>© 2025-2026 OffCrypt. All rights reserved.</p>
<nav aria-label="Footer navigation">
<a href="PrivacyPolicy.html">Privacy Policy</a>
<a href="disclaimer.html">Disclaimer</a>
</nav>
</footer>
<!-- Cookie Consent Banner -->
<link rel="stylesheet" href="cookie-consent.css">
<script src="cookie-consent.js" defer></script>
</body>
</html>