Know your enemy. Know yourself.
Point Tzu at any address — a rival, a tool you're weighing up, or your own
app. It reads what that app already tells the world — the stack, the
hosting, the keys shipped in the JavaScript, the controls nobody switched
on — and hands you back a teardown.
敵 Know your enemy
Point Tzu at any app. It fingerprints the stack, maps what's exposed, and
tells you how solid that app actually is. Most apps built in a weekend
look like it from the outside — and now you can tell which ones.
Free. No account. Any target.
己 Know yourself
Then prove you own your own app, and Tzu stops observing and starts
testing. AI writes code that trusts the browser: row-level security never
switched on, auth missing from an endpoint, keys left in the bundle,
storage rules wide open. Tzu finds those, proves they're real, and gives
you a fix to paste straight into your coding agent.
Verified assets only.
Where the line is
Actively scanning infrastructure you don't control is unauthorized access,
so Tzu is built so it can't. The active engine takes no target parameter at
all — it reads the target out of a verified-ownership record, which means
there's no request you could craft to aim it somewhere else.
For a target nobody has verified, the output is characterizing, not
exploitable: enough to make a business decision, never enough to
launch an attack.
What you see from outside is the tip
Everything Tzu reads passively is what the app publishes to anyone who
loads it. That's a real signal, and it's a small slice of what's actually
there. The keys in a bundle say a door might be unlocked; only testing your
own app says whether it opens.
Being built now
The engine behind this has been running against real client work for months.
Tzu is the self-serve half, and it isn't live yet. Put an address in and
you'll be among the first to point it at anything.