Scan rule · RSC-DET-007
Services and routes of the app detected
Architecture & SEOSeverity: Info
Reads from the shipped JavaScript what the app talks to: own routes, backend services (Supabase, Firebase …), AI providers and other third-party services — as a list with method and location.
Scan tier
External scan (anonymous)
How to fix it
No action; puts the other findings into context. Every third-party service belongs in the privacy policy, every own route needs a server-side access check.