Managed audits
Choose light, full, or custom coverage and compare results on equal terms.
Choose the smallest useful profile
Audit depth should match the question. A smaller profile is useful for a quick public signal or a focused retest. A broader profile is useful when you need a more complete view of a verified deployment.
Light audits
Light checks the public surface without domain verification. It covers bounded signals such as HTTPS, transport configuration, security headers, public metadata, and selected exposure checks.
It does not prove authenticated behavior, repository quality, private data controls, or complete application security.
Full audits
Full uses the broad managed profile available to the verified domain. It is the default when you want VICE to run the available web, transport, discovery, and stack-specific checks without choosing each module.
Custom audits
Custom lets you select modules for a verified domain. Use it to retest a fix, focus on a known stack, or keep an audit inside a smaller operational window.
- Passive discovery modules remain available to support the selected checks.
- A narrow selection can still produce partial coverage when the target hides a required resource.
- The current custom defaults include passive discovery and Supabase checks.
Follow status and history
When comparing runs, check the selected profile, modules, coverage, engine version, and ruleset before interpreting a score change.
- Queued means the audit is waiting for an isolated worker slot.
- Running means the worker is executing the selected checks.
- Completed means the report and coverage are ready.
- Failed means the final attempt ended without a complete report.
Continue with VICE
Compare light, full, and custom audits on the VICE website.