DocsStart

Getting started

From a new account to a watched app in a few minutes.

Updated
On this page

In short

  • Enter your app's address at the top of vallit.net. The check starts at once, without an account, and its report opens with the score.
  • The report shows how serious each finding is and what kind it is. The details open once you sign up and take the report over.
  • After sign-up you choose how closely we watch the app: stay on Free or pick a plan. Either way the app is checked every day from then on.

Where in the app

The check starts in the form at the top of vallit.net. The account is made on the sign-up page, which the report's See the full report button opens.

The sign-up page with Continue with Google, the ringed Continue with email button and the Sign in link, under the heading Your app, watched from today.

Step by step

Steps 1 to 3 happen on vallit.net and on the report. Steps 4 and 5 happen on the sign-up page: step 4 with Google or Apple, or step 5 with your email. From step 6 on, you are in your new company.

The sign-up buttons: Continue with Google (4), Continue with email (5), and the Sign in link below them.
The sign-up buttons: Continue with Google (4), Continue with email (5), and the Sign in link below them. On a phone.
  1. Enter your app's address

    At the top of vallit.net, type the address into the field, for example myapp.com. Tick I own this app, or its owner asked me to check it. and click Check my app. The report opens with one row per check and fills in as each check finishes.

  2. Read the score

    When the last check is done, the report shows the score out of 100 and one sentence about it. Under Observations, each finding shows its severity and its kind, and Details locked in place of the rest.

  3. Open the full report

    Click See the full report. Signed out, you see the sign-up page, headed Your app, watched from today. If you already have an account, click Sign in under the buttons and follow Signing in.

  4. Sign up with Google or Apple

    If the page shows Continue with Google or Continue with Apple, click it and choose your account. The page reads Signing you in… for a moment. Go on at step 6.

  5. Or sign up with your email

    Click Continue with email. Type your address into Email and a password of at least 15 characters into Password. Click Create account. Vallit sends a 6-digit code to your address; type or paste it, and it is checked once the sixth digit is in.

  6. Take the report over

    The page is headed Take over this report and already holds the report's address. Company name holds the address too, such as myapp.com. Type your company's name over it, or leave it as it is. Tick I own this app, or its owner asked me to look after it. and click Take over this report. Without the tick, the box shakes and Tick this to continue. appears under it.

  7. Choose how we watch it

    The next page asks how closely to watch your app. It lays the free check beside the order: your app in three lanes, Free, Watch and Care, with the price per app, then monthly or yearly, then what is charged today. Click Continue free to stay free, or leave the app on Watch and click Start 14-day trial to try Watch and pay through Stripe after 14 days. Plans and billing compares them.

  8. Read the whole report

    Your app's page opens with the report you started on vallit.net, now with every finding, what it means and how to fix it. The check is not run again.

  9. Confirm your domain

    Under the band at the top, the Connect your DNS panel asks for one DNS record that proves the domain is yours. Confirm your domain walks through it. Once the record is found, the page shows Domain confirmed.

What happens behind the scenes

Vallit reads what your app already serves to any visitor, the way a browser does. It does not sign in, change anything or copy your data.

  • Every report covers 34 checks, listed on What we check. More checks read your code: they are part of a paid plan and run once you connect a repository. The report lists them as the questions they answer, so it counts more rows than there are code checks.
  • Your company takes the name under Company name. Until you type one, the field follows the address, such as myapp.com, and a cleared field gives the company that name too. Alerts go to the email you signed up with. Your company and Alerts show how to change both.
  • Vallit checks the address before it creates anything. An address it refuses leaves no company behind.
  • Vallit does not verify your tick. It records the tick with the check, and the tick lets that check run the targeted checks.
  • The requests come from VallitBot. Your server logs show its user agent, the name a visitor's software gives itself: VallitBot/<version> (+https://vallit.net/bot; …).
  • The guardian starts watching the app as soon as it is added. The guardian has the schedule.
  • Every first step you have not done yet waits in the Inbox, under Getting started or as a row of its own.
  • A check started on vallit.net belongs to no one until it is taken over. Anyone with its link sees the score, the severities and the kinds, never the titles, evidence or fixes. Anyone can check any address, so those details open only for the account that takes the report over.
  • An unclaimed report link opens for anyone who has it until the report is 90 days old. Its See the full report button leads to sign-up.
  • Only a check started on vallit.net without an account can be taken over. A report a company made, even one whose company was deleted, can never be.
  • app.vallit.net has no front page. Signed in, it opens your company; signed out, the sign-up page.
  • Taking over a report does not run the check again. Your browser remembers which report you came from for an hour, and sign-up does not carry it in its web address.
  • Only an account without a company can take a report over. With a company, add the app from Home instead.

If something goes wrong

On vallit.net

A check the app refuses opens the app's Check your app page, with your address kept and the reason under the field.

What you seeWhat it meansWhat to do
Please confirm you own this app or have been asked to check it.The box was not ticked.Tick the box and click Check my app again.
That does not look like a web address. Try something like myapp.com.The field holds something Vallit cannot read as an address.Enter the address as it appears in your browser's address bar, such as myapp.com.
We could not confirm the check came from a person.The check against bots did not pass.Reload the page and try again.
We could not start the check. Try again in a moment.The check did not start on our side.Wait a moment, then click Check my app again.

If the domain or your connection started too many checks in the last hour, the message says so and names the limit. Wait an hour and try again.

While you create the account

What you seeWhat it meansWhat to do
Enter your email address.The Email field is empty.Type your address, then click Create account again.
That email address does not look right.The address is missing a part, such as the @.Correct the address, then click Create account again.
You already have an account.An account with this address exists.Click Sign in instead beside the message. Your address goes with you to sign-in.
Use at least 15 characters.The password is shorter than Vallit asks for.Use at least 15 characters, for example a few unrelated words.
That password showed up in a known leak. Choose a different one.The password is on a published list of leaked passwords.Choose a password you have not used anywhere else.
That password is too easy to guess. Try a longer one.The password is too simple to accept.Use a longer password, for example a few unrelated words.
That code is not right. Check the email and try again.The digits do not match the code that was sent.Type the code from the newest email. The boxes empty themselves, so you can start again.
That code has expired. Send a new one.The code is too old to use.Click Resend code and use the code in the new email.
The check against bots did not pass. Try once more.The sign-up service took the attempt for a bot.Click Create account again.
Nothing happened. You can try again.The Google or Apple sign-up did not start.Click the button again, or click Continue with email.
Too many attempts. Wait a minute and try again.Several tries came in within a short time.Wait a minute, then try again.
Something went wrong on our side. Try again in a moment.The sign-up did not finish on our side.Wait a moment, then start again.

If no code arrives, look in your spam or junk folder. The page names the address it sent the code to. If that address is wrong, click Use a different email. Resend code unlocks 30 seconds after a code is sent.

On the first check

What you seeWhat it meansWhat to do
Tick this to continue.The ownership box is not ticked.Tick I own this app, or its owner asked me to look after it. and click Check my app again.
Enter the address of your app.The Address field is empty.Type the address, then click Check my app.
That does not look like a web address.The field holds something Vallit cannot read as an address.Enter the address as it appears in your browser's address bar, such as myapp.com.
We only check public web addresses.The address is private, such as localhost, or no server can be found for it.Check the spelling. Enter the address your visitors use, since Vallit only checks apps that are live on the internet.
The company could not be created just now. Try again in a moment.Setting up the company failed on our side.Reload the page. If a company is now listed above the form, click it. Otherwise start again.
We could not start the check. Try again in a moment.The company and the app exist, but the check did not start.Reload the page and click the company listed above the form. On the app's page, click Run a check.
That report already belongs to a company.The report you came from is already in a company, either from the start or because someone took it over.Enter your app's address, and a fresh check starts.

If the domain was checked too often in the last hour, the message says so and names the limit. Wait an hour and click Check my app again.