The gap
Small sites often ship through modern hosting platforms, client frameworks, third-party APIs, and fast deployment pipelines. The platform may be secure while the deployed output still exposes a source map, secret-looking value, backup, weak browser policy, or risky public route.
The approach
SiteGuardrail starts with what an unauthenticated visitor can observe. It keeps requests bounded, records an affected URL, redacts sensitive-looking evidence, distinguishes confidence from severity, and says when coverage is partial.
The promise
SiteGuardrail will not label a public client identifier as a confirmed secret, count failed checks as vulnerabilities, or claim that a passive scan proves a website is secure. The aim is a short, defensible engineering queue—not a dramatic score.