AI App Radar DACH
How are AI-built apps doing in Germany, Austria and Switzerland?
Every three months we passively scan — the way a browser would — the discoverable population of AI-built web apps with a German, Austrian or Swiss connection and publish the shares. No hostnames, no screenshots, nothing attributable to a single site: only numbers over groups of at least 20 apps, citable under CC-BY 4.0.
The first run is coming.
Numbers appear here once a run has closed and covers at least 20 discoverable apps. Methodology and opt-out are already in place — if you do not want your domain in the radar, you can remove it now.
Methodology
The radar measures what is discoverable: apps in builder directories, on builder subdomains (such as *.lovable.app or *.bolt.host) and with a recognisable builder fingerprint, supplemented by certificate transparency logs and the Common Crawl index. Apps on their own domain without markers are under-represented. The correct reading is therefore “x% of the n discoverable apps with a DACH connection”, never “x% of German Lovable apps”. Attribution to DE, AT or CH happens after the scan via domain ending and legal findings; whatever cannot be attributed counts as not attributable and serves as a control group.
The scan is passive and browser-equivalent: it loads what any browser loads when opening the site, clicks nothing, fills in no form and creates no account. The user agent names us and this page, and robots.txt is respected — anyone who excludes us there is skipped.
What is loaded
- HTML, bundles and HTTP headers
- the page in a headless browser: trackers before consent, cookies, accessibility
- publicly served source maps
- robots.txt, sitemap and linked legal pages
Never
- sensitive paths such as /.env or /.git
- backend probes — database schema, row counts, buckets
- creating accounts or testing login throttling
Only shares over groups of at least 20 apps are published. No hostname, no URL, no screenshot and no finding attributable to a single site. Internally the raw data carries a hash that never leaves the database; the target list expires 90 days after the last scan.
Before every publication the field sweep runs against a control group of well-maintained professional sites — any severe hit there is a false-alarm candidate. The last sweep (24 August 2026) found five errors in platform detection; all are fixed. The false-alarm estimate per rule is stated in the quarterly report. The numbers here are shares over a sample, not proof about any individual app.
If you do not want your domain in the radar, remove it: prove control via DNS TXT, file or meta tag — we then delete all observations and the target and exclude the domain from every future run. Without DNS access, an email is enough.
Remove your domainHow to cite
decivo AI App Radar DACH, methodology 2026.15, decivo.de/rescue/radar
Numbers and JSON are available under CC-BY 4.0. Please cite as “decivo AI App Radar DACH” with a link. Raw numbers as JSON