Illuminate the internet supply chain
operating within every application

Provider discovery, runtime behavior profiling, resource baselining, and entity resolution for the applications you depend on — read from a capture of what actually loaded, analyzed as evidence, never inferred from claims.
A band across the top of the SCVue supply chain graph, showing the source domain fanning out into the third-party domains and hosts a single application loads.

The foundational question SCVue™ answers: “Can I trust this website and its contents to be consistent with what the creator intended, or is it susceptible to manipulation or influence?”

Distinctive

What Makes SCVue Different

Conventional review asks an application what it contains. SCVue watches what it actually does.
Evidence, not claims
Reports what code and traffic are observed to do, never what a manifest declares.
The whole chain, not the first hop
A page loads a tag, the tag loads a script, that script calls a service nobody put on the vendor list. SCVue follows all of it.
Three independent axes
Compare any report across time, capture context, and page.
Risk & Influence Factors
Is the code risky? Are the parties behind it flagged? Two questions, answered together.
Method

How SCVue Works

Five steps from a capture file to a full picture.

01

Import
Export a HAR from your browser's developer tools and import it. No agent, no proxy, no capture infrastructure to stand up.

02

Parse & Normalize
Capture each unique resource and network call to identify every provider and the data flowing to and from them.

03

Analyze & Enrich
Ten engines profile code, traffic, payloads, and media, while providers are enriched with entity, ownership, and infrastructure intelligence.

04

Report & Compare
Eight report sections over the same capture, every finding deep-linked to the evidence it was derived from.

05

Re-import & Diff
Import a later capture of the same application. The change report is generated for you and shows exactly what moved between the two.
Analyst Toolkit

Eight Report Sections

One workspace, eight views of the same capture — every finding deep-linked to the evidence it came from.
Overview
Risk factors, supply chain graph, change.
Traffic & Requests
Calls, payloads, endpoints, redirects, cookies, storage.
Assets
Documents, code, styles, media, data.
Infrastructure
Domains, hosts, IPs, ISPs, cloud, CDNs, SSL.
Data Flow & Jurisdiction
Flow-downs, hosting, governing law.
Security & Behavior
Runtime scripting, CSP, SRI, vulnerabilities.
Entities & Vendors
Influence factors, companies, software, sanctions.
References & Exposure
Referenced domains, URLs, emails, phones.
In Action

See What Actually Runs

Every screen below is analysis of a real capture, not a mockup.

Risk Factor Analysis on Every HTTP Request

  • One scale: ten analysis engines roll up to High, Warning, and Info, each finding deep-linked to its report.
  • Evidence only: every finding derived from captured code and traffic, never from build manifests.
  • Code risks: CSP and SRI weaknesses, HTTPS downgrades, runtime code generation, fetch-to-execute patterns.
SCVue risk factors report, showing findings graded High, Warning and Info with category, detail, originating host and URL for each.
Ten analysis engines roll up to a single High / Warning / Info scale.

X-Ray Every Request, Map Every Data Flow

  • Every payload: inspect what the application transmits out, decoded call by call.
  • Automatic flags: fingerprinting, personal information, cross-site tracking, behavior logging.
  • Data flow mapping: see exactly which service providers receive data about your application and your users.
SCVue HTTP POST report listing every call that transmitted a payload, with a detail panel decoding one payload and flagging device fingerprinting and tracking behaviour.
Every HTTP POST that transmitted a payload, decoded call by call and flagged for fingerprinting and tracking behavior.

Revealing Who Is Behind Every Resource

  • Real entities: enrichment resolves observed domains to companies, software products, and individuals.
  • Influence factors: flags on the parties themselves: ownership, control, sanctions, jurisdiction.
  • Nothing sampled: every domain observed in the capture is resolved, not a selection of the recognisable ones.
SCVue entities report resolving observed domains to the companies that operate them, with country, category and role for each.
Observed domains resolved to the companies that operate them, with country, category, and role.

What SCVue Does

SCVue turns a browser capture into a resolved, comparable report. All of it runs on a free community account:
  • HAR import: web applications, in your browser, from a capture file you export yourself.
  • Full analysis: all ten engines and all eight report sections run on every import.
  • Entity resolution: observed domains resolved to the companies operating them.
  • Report comparison: import a later capture and the difference against the earlier one is computed automatically.
SCVue supply chain graph: one source domain connected outward to every third-party domain and host loaded by a single application.
One application, one imported capture — and every third-party domain and host it reached.

SCVue discovers your digital vendors

Revealing and documenting all of the providers and services utilized in your applications. Identify every jurisdiction and governing law with authority over the processing and storage of your application data, proven with captured evidence.
One application, and the vendor web behind it: its domains and hosting each open into tiers of vendors that multiply and fade past the edges of the frame, while a clear path remains from its data flow down to jurisdiction and governing law.