AppSite Cyber Check
AI
ai.appsite.caThis app is in beta: it’s live and ready to use, and some of its services are still being completed. Below is every claim on its Home and where it stands — and if something doesn’t work the way its Home says, tell the developers below.
What the Home says, checked against the app — 2 backed · 14 partly · 1 not yet · 1 not verified
- On the wayA platform egress guard blocks private values or replaces them with placeholders before a prompt is sent to the AI provider.Why: No egress guard appears anywhere in the shown proxy, gateway or client code; prompts are forwarded as sent.
- Partly liveEvery module calls one platform AI proxy, which uses either AppSite's provider keys or the tenant's own keys, decided per call.Why: The per-call key choice is real, but it covers a user's Anthropic key only. The UI can only store Gemini/OpenAI keys, which this proxy ignores, and not every module goes through the one proxy.
- Partly liveThe AI model is chosen per use.Why: Per-call model choice exists in the proxy and for images, but the text page's model picker has no effect on which model runs.
- Partly liveAI tokens are assigned per module and per tenant, are zero by default, and are never unlimited by default.Why: Per-tenant zero-default quotas exist on the client, but there is no per-module allocation, and the server proxy treats unconfigured tenants as unmetered rather than zero.
- Partly liveEvery AI call is metered to the module that made it, and usage by module can be viewed.Why: Proxy calls are metered per module and a server endpoint exposes the per-module totals, but the module's Usage page lists no per-module view, and direct callers like docChatAI bypass this meter.
- Backed by the appAI usage is attributed to the division and the job that incurred it.
- Partly liveThe assistant is embedded in every AppSite module and reads the record on the current page (customer, job, numbers on screen).Why: The assistant is embeddable everywhere, but no shown code reads the record currently open on the page into the prompt.
- Partly liveAssistant drafts are not saved until the user chooses to save, and can be edited first.Why: Drafts are mostly not saved without action, but the output is not editable in place and Analyze results auto-save.
- Partly liveAI work is grounded in the tenant's own documents, records and chosen connections.Why: User-written context blocks and memory ground prompts, but no shown code pulls tenant records or documents or connections into a prompt.
- Partly liveYouTube and document content can be pulled in as source context for AI.Why: Document upload as AI input works, but YouTube context is unbuilt.
- Backed by the appThe module provides text and image generation.
- Partly liveFlows chain multiple AI steps into repeatable runs.Why: AI writes a flow definition and a runner executes flows, but nothing chains AI steps into repeatable runs, and the generated steps use 'type' while the runner switches on 'action'.
- Partly liveUsers can configure connections to the AI providers they choose.Why: Users can file their own key, but there is no provider connection setup, and the stored keys are not used by the text proxy.
- Partly liveAI agents registered in the Agents module run through the same AI proxy and metering.Why: The shared gateway exists for server-side callers, but the shown code does not show that Agents-module agents use it.
- Partly liveEvery plan includes AI tokens for the assistant and agents, while Enterprise and Creator plans can use their own keys and quotas.Why: Plan allowances come from configuration, which is content, and own-key use is not restricted to Enterprise/Creator as claimed.
- Partly liveThe module shares tenant identity, permissions, shared records, automation events and reporting with the rest of AppSite.Why: Tenant identity and shared usage events are shown; permissions, shared records and automation events are not evidenced.
- Partly liveA Cyber Check record reports the build number, check date and live-feature count, and lets visitors report an issue.Why: The check date and issue reporting are backed, but the files shown never display the build number or a live-feature count, and the specific figures are content, not code.
- Not checked yetThe AI module appears in the recommended module set for 2 of 19 industries.Why: An industry recommendation count is content, not code.
The open tickets on this module’s own repository — what is being worked on right now.
The page and its back end, as the public reaches it.
- ✓Served over HTTPS
- ✓Every link and picture on the live Home answers
- ✓The live page loads without failed requests
- ✓No script errors on the live page
- ✓No insecure (http://) resources
- ✓Domain records (DNS)
- ✓Every link on the public page answers
- ✓Module info agrees (registry, catalogue, build)
- ✓No secret in the page or the JavaScript it ships
- ✕Deployed from main (the release branch) — being fixedserves dev-paul — releases ship from main (Developer module branch policy / the repo’s default branch)
Checked Oct 3, 2026, 6:21 p.m. against build 1.4.283 (4616b94). Cyber Check reads the Home a visitor sees, then compares every claim on it with the code of the build that is serving it — a label or a screenshot is not evidence; working code is. It also checks every link, HTTPS, shipped secrets, DNS, the public page, and the registry — then the other way: what the app offers that its Home never says. After a full first pass, it rechecks each app on any night its code, its build or its Home changed.