Skip to content

AI-generated video

CodeGuard Cloud

Checking tools through one interface: Lighthouse, security headers, known vulnerabilities in your packages. Your source code stays on your machine.

In development. We test every feature daily for at least a week before it goes live.

Your code stays with you

The cloud never sees your source code. It checks what is public anyway, and otherwise works only with what you choose to send.

Addresses, not files
Performance, security headers and certificate are measured on your live website, exactly as any visitor sees it. All the cloud needs is the address.
A package list, not your project
For the vulnerability check, a script on your machine reads the lockfiles and sends only package names and versions. No file, not a single line of code.
No path for source code
Features that transfer source code are not part of the concept. What the cloud never receives cannot get lost there either.

Tools through one interface

Your AI assistant calls the tools directly (through the MCP protocol). For scripts and pipelines there is a web interface (REST), first for Lighthouse and the package check. What comes back is data a program can work with.

  • Lighthouse for up to 20 addresses per job, on mobile and desktop
  • DNS, encryption and security headers
  • Known vulnerabilities in your package versions, from public databases
  • Lifecycle of PHP, Node and Laravel: which version will soon stop getting updates
  • Crawler, SEO, HTML and structured data
  • Accessibility, checked in a real browser
  • Continuous monitoring with notifications

The tools are built one after another. How far each one is shows in the progress below.

Right away or as a job: you decide how you wait

One address takes about a minute, because the cloud measures every page three times. Twenty addresses on two devices take considerably longer. So every request has two paths, and both lead to the same result.

RequestInstantJobResult
Synchronous: the result in the same response
Your tool waits for the result: up to five minutes through the web interface, up to one minute for your AI assistant. If the result is not there by then, you get a job number instead of an error: the measurement keeps running, nothing is lost. Intended for the moment you are in your editor or just before a commit.
Asynchronous: a job number at once
The cloud accepts the job and answers immediately with a number. Your pipeline keeps working and checks the status later: waiting, running, done or failed. Intended for long lists of addresses, nightly runs and CI.
Partial results as soon as they are done
When you check, you see every finished measurement while the others are still running. Every value comes with a comparison to the last run. The same request within ten minutes is answered from the cache, without measuring again.

An example: our own website

Measured at www.provimedia.de on October 7, 2026, mobile view, with Lighthouse on our own machine, not yet through the cloud. The example shows why a score alone is not enough: only the cause tells you what to do.

Mobile performance
55 and 56 out of 100
The three largest files (JavaScript and CSS)

1,197 KB uncompressed, as delivered

328 KB compressed

Cause
The web server compressed only the HTML. JavaScript and CSS went over the wire uncompressed.
Fix
One web server setting. These three files are then transferred about 73% smaller. The fix is in progress; we will add the measurement taken after it here.

What you save

Machine time
One Lighthouse measurement kept our development machine busy for about 20 to 25 seconds. Twenty addresses on mobile and desktop, each measured three times, are 120 measurements: 40 to 50 minutes in which the machine does nothing else. With the cloud they run on our machines, and yours stays available for your work.
Numbers you can trust
Lighthouse fluctuates: the same page scored 53 and 63 for us on the same day. The cloud measures every page three times and takes the middle of the three values for performance. A single outlier does not decide the result.
Findings, not just a score
Every measurement comes with up to ten findings from performance, accessibility, best practices and SEO, ordered by their weight in Lighthouse. You see which values pull the score down.
Nothing to run yourself
No test environment to set up, no browser to maintain on the build server, no vulnerability database to keep current. You call a tool and get a result.

How far we are

The status comes straight from our development and updates itself. We count the core build, weighted by effort. Every item can be expanded.

3% built

2 of 66 weight points, core build P0 Status as of 7 October 2026, 13:02

34 items in the core build

Currently working on

  • Lighthouse measurement for URL lists
  • Score per project

Foundation

  • Automated testing and delivery with monitoring (open)Effort M
  • Maintenance of large data sets (open)Effort S
  • Accounts, organisations and roles (in progress)Effort M
  • Sign-in with the CodeGuard licence key (done)Effort M
  • Projects, domains and domain verification (in progress)Effort M
  • Bookable plans and billing (open)Effort M
  • Usage and quotas (in progress)Effort S
  • Registry of check services (open)Effort M
  • Orchestration of check runs (in progress)Effort L
  • Merging and tracking findings (in progress)Effort M
  • Score per project (in progress)Effort S
  • Cache for public results (open)Effort S
  • Checks for DNS, encryption and security headers (in progress)Effort M
  • Crawler and SEO checks (in progress)Effort L
  • Browser checks for performance and accessibility (open)Effort M
  • HTML and structured data (in progress)Effort L
  • Detection of software in use (open)Effort M
  • Lighthouse measurement for URL lists (in progress)Effort L
  • Framework for security knowledge (open)Effort L
  • Known vulnerabilities from public databases (in progress)Effort M
  • Lifecycle of PHP, Node and Laravel (open)Effort S
  • Matching of installed package versions (in progress)Effort M
  • Web interface for projects and findings (in progress)Effort L
  • Documented programming interface (in progress)Effort M
  • Continuous monitoring with notifications (in progress)Effort M
  • Pilot operation and cost measurement (in progress)Effort S

Security foundation

Before the cloud opens, its foundation has to stand. These items are part of it:

  • Separate environment for checks (in progress)Effort M
  • Backup and restore (open)Effort S
  • Protection against access to internal networks (in progress)Effort L
  • Only permitted check targets (in progress)Effort M
  • Isolated check processes (in progress)Effort M
  • Strict separation of customer data (in progress)Effort M
  • Access keys and multi-factor sign-in (in progress)Effort S
  • Traceable log of all changes (open)Effort S

Milestones

  • Use in our own operations (in progress)
  • Legal review (open)