Digibastion helps people and teams reduce practical security risk before an incident. The public site combines guided security checklists, an OpSec quiz, threat intelligence, security guides, curated tools, and professional review services. VANTAGE extends that work with external domain trust evidence for Web3 and Web2 teams.
Supported by the Ethereum Foundation Ecosystem Support Program in 2025.
| Product | Best for | Start here |
|---|---|---|
| Digibastion | Individuals, builders, security teams, and anyone learning practical digital security | Security checklist, OpSec quiz, threat intelligence, guides |
| VANTAGE by Digibastion | Teams that need evidence about DNS, email, TLS, web, frontend, phishing, breach, and Web3 trust paths | Public overview and score lookup, security checks, use cases |
| Security services | Founders and teams that want hands-on OpSec or full-stack security review | Services |
If you are unsure where to begin, take the quiz, complete the essential checklist items it recommends, and use the threat feed to keep those controls current. Organizations evaluating a domain should start with VANTAGE.
The repository currently contains:
- 274 checklist items across 11 security categories, with local progress and threat-profile guidance.
- An eight-question OpSec assessment with server-validated scoring, shareable results, and a leaderboard.
- A unified threat-intelligence experience for RSS advisories, Web3 incidents, and provider-attributed incident records, plus optional email alerts and digests.
- 71 published security guides covering wallet safety, phishing, DeFi, smart contracts, privacy, incident response, and developer security.
- 28 curated security-tool entries and a broader resources directory.
- OpSec consulting and full-stack review service pages.
- Private administration surfaces for analytics, ingestion health, scheduled operations, and API-key management.
- VANTAGE, live at
vantage.digibastion.com, with public score previews, private evidence workflows, and research, knowledge, checks, use-case, and incident-note libraries.
These counts describe the current source tree, not usage or performance claims. Live application routes and the VANTAGE pages above were checked on 2026-09-27. This project's backend is managed by Lovable Cloud: database, functions, users, logs, and secrets are inspected through View Backend in the owning Lovable project, not through a separately accessible Supabase dashboard or separate Supabase credentials. VANTAGE private workflows require access to that product's own environment.
See Product and architecture for route, system, data-flow, and deployment details. See Roadmap for the small set of prioritized next outcomes; completed production work is recorded in Implementation history.
Requirements:
- Node.js 22.12 or later
- npm
- Lovable-provided public browser configuration, or your own external backend project when testing data-backed changes in isolation
git clone https://github.com/Raiders0786/digibastion.git
cd digibastion
cp .env.example .env
# Add public VITE_SUPABASE_* browser values only when overriding the defaults.
npm ci
npm run devThe development server is available at http://localhost:8080. Run the full
release gate before opening a pull request:
npm run checknpm run check runs TypeScript, lint, unit tests, and a production build.
Only browser/publishable values belong in .env; they do not grant backend
ownership or dashboard access. For the deployed project, maintainers manage
service-role keys, cron secrets, feed credentials, and email credentials via
View Backend in Lovable. Moving backend ownership outside Lovable requires
migration to a separately owned external backend project.
api/ Vercel request handlers
public/ Static metadata, PWA, crawler, and image assets
src/components/ Shared React UI
src/data/ Checklist, article, tool, and resource content
src/pages/ Public, service, subscription, and admin routes
src/integrations/supabase/ Generated database types and browser client
src/utils/ Shared client utilities
supabase/functions/ Deno Edge Functions
supabase/migrations/ Database schema, policies, functions, and jobs
docs/ Current architecture and historical operations
External threat providers are ingested independently on the server and
normalized into news_articles. Provider-specific incident details stay in
news_articles.metadata, while sanitized aggregate run outcomes are recorded
in threat_intel_ingestion_runs. This keeps credentials and raw provider
payloads out of the public client.
Useful contributions include correcting a security recommendation, reviewing an article against primary sources, improving mobile or accessible behavior, adding tests, proposing a reputable threat source, or reproducing a bug. Start with CONTRIBUTING.md and open an issue before a large or architecture-changing implementation. Product ideas and field reports are welcome in GitHub Discussions.
Please report security vulnerabilities privately as described in SECURITY.md.
This repository is source-available, not OSI-approved open source. The
LICENSE contains the MIT text plus a Commons Clause restriction that
prohibits selling, leasing, or providing paid services based on the software
without prior permission. Non-commercial use, modification, and sharing are
allowed subject to the full license terms. Contact raiders@digibastion.com
for commercial licensing.
The project owner still needs to decide whether the long-term model should remain Commons Clause source-available or move to an unmodified open-source license. Until that decision is made, the LICENSE file controls.