Interview with Stephen Gray of Decloak

Stephen Gray Decloak Interview

Meet Stephen

My name is Stephen Gray. I’ve been a developer my entire life, with 20+ years of commercial experience. I’ve spent many years working in digital agencies, with significant time focused on e-commerce and digital payments for highstreet retail. I helped run and eventually start my own digital agencies, serving as CTO for several of those years. Mostly around London in the UK.

During that time I learnt the programming trade across all areas of the stack, before the term “full stack” even existed!

I’ve worked with many clients and businesses whose leaders aren’t technical. In recent years, I’ve focused on helping those businesses better understand their code and security without that technical barrier.

Now in the age of AI, some industries (like cybersecurity) are RIPE for disruption!


What inspired you to build Decloak?

At other companies we’ve used services like Qualys and AppCheck for security audits, automated pentesting and similar services. These services are large, complex and come with a very high price tag.

They can charge that much because the services they provide are inherently complicated yet extremely necessary. So they got away with charging that much for so long.

But now with AI we believe this should change, so we built Decloak. It’s already being used as an alternative to those tools for some companies, so we checked that box very quickly.

And it evolved from there!

What makes Decloak fundamentally different from traditional web security tools?

The main features in Decloak revolve around an agentic approach to security scans. It’s not just a hardcoded script that ticks off a list of security checks.

It’s an actual agentic approach where our AI agent takes a starting point (an IP address or domain) and decides what to check next, what URL to navigate to and so on.

Each URL it finds passes through numerous checks so nothing is missed, but the agent ultimately decides where to go next and what threads to follow.

On top of this, the platform is growing at an impressive rate. We passed 60 features a short while ago when we released AI-powered penetration testing, and we’ve already released more features since then!

What’s the biggest mistake website owners make when they see a security warning?

Even before AI it was very common for web security to be prioritized lower than everything else. And this caused all sorts of issues that are well known now.

It can always seem more important to tackle the next bug fix or get the next new feature live, but security flaws don’t simply go away if ignored.

Every attack surface and vulnerability is a way someone could potentially get access to data they shouldn’t have or access to a system you really don’t want them to access.

What does a typical Decloak workflow look like from diagnosis to resolution?

We’ve engineered Decloak to be as simple to use as possible right from the start. All our system needs is a domain name or an IP address, everything from there is automated.

Once you see the scan results you can take action from here. You start with a security score and grade, then you can export the results as PDF reports or you can use the AI-generated remediation tips to start resolving the issues. You can also use our API and MCP server to automate workflows with your own AI systems to fix the findings.

You can also ask our own AI assistant on the page about any of the findings to discuss them further.

Active Testing (DAST) and AI-powered Pentesting, which are Enterprise features, have their own dedicated scores, PDF report exports and results areas.

Why did you believe the rise of AI coding tools required a new approach to web security?

The two core reasons are that AI is now generating an insane amount of code volume across everyone’s projects. Most projects by now will be 60% AI-generated, with most even higher than that.

With AI generating that much code, more security flaws and vulnerabilities are finding their way into production code on live websites.

This affects vibe coders as well as professional programmers and we even see stories of this affecting global software companies around the world; you only have to do a Google search or see the stories on X!

On the other side, AI systems are now looking for and finding vulnerabilities in people’s websites and apps. So it’s not only just hackers and botfarms, but actual intelligent AI systems that are targeting people.

All this together means that we all need to be better at keeping on top of our own security!

What does it mean for the agent to “investigate a whole site” rather than follow a fixed checklist?

After scanning the first page, our AI agent examines the source code, included scripts, links and so on. From there it will decide which pages need to be investigated next.

We’re applying a level of intelligence to the security scans, similar to how a human would approach a security audit (but much faster!)

What security practices should every startup adopt before launching its first SaaS product?

At the very least, run a free scan on decloak.dev which covers the basics – vibe-coded app security checks, exposed keys and so on.

But really, as companies start to take on real live users and grow, security is not a one-off activity. It’s something that needs to be checked regularly, as code changes and new vulnerabilities are discovered all the time.

What advice would you give founders building in the SaaS industry?

Stay strong, be vigilant! As we all know, writing the code and building the app is easier than ever and no longer the hard bit. The hard bit is marketing, getting those first users, and importantly making sure that your user’s data is safe and won’t be compromised if they use your app!

Did you enjoy our interview? Do you have anything to say to our community?

This has been a bit of fun, thank you. But it’s a very serious topic. I’m happy to answer any questions around security, vibe coding, and how we can all do better about our security 🙂

Who we are interviewing today? Stephen Gray

Which product are you part of? Decloak

What is the focus of the interview? Web security and his role in Decloak

Latest Interviews

Ace Bailey GSC Resolver Engine Interview

Interview with Ace Bailey of GSC Resolver Engine

What is the focus of the interview? Search console warnings and his role in GSC Resolver Engine

David Patrykowski Backona Interview

Interview with David Patrykowski of Backona

What is the focus of the interview? AI marketing analytics and his role in Backona company

Carmen Tune Expert Interview

Interview with Carmen Tune

What is the focus of the interview? Software deals and her role in Carmen Tune website

Eshwar Lifetime QR Codes Interview

Interview with Eshwar Deshmukh of Lifetime QR Codes

What is the focus of the interview? Permanent QR codes and his role in Lifetime QR Codes company

Leave a Comment