Exposed secrets
Finds risky env files, API keys, tokens, database URLs, and credentials.
Rules-first launch review
Upload your AI-built app and get a practical review of exposed secrets, authentication risks, payment issues, database configuration, dependencies, and launch readiness.
No code execution · Temporary files deleted after scanning · Only masked results are stored
Scanner coverage
Focused checks for the launch risks AI-built apps most often ship with.
Finds risky env files, API keys, tokens, database URLs, and credentials.
Reviews database rules, public policies, RLS signals, and privileged service-role usage.
Checks admin pages, internal routes, sensitive APIs, and client-only access checks.
Looks for unsafe checkout flows, client-side payment state, exposed Stripe secret usage, and missing server-side validation.
Flags high and critical package vulnerabilities without low-priority noise.
Checks the deployed URL for missing headers, exposed files, debug output, and basic launch hygiene.
How it works
Choose the app you want to review and upload a ZIP of the source project.
Rules inspect code, config, database policy files, dependencies, and the optional deployed URL.
Get grouped issues, evidence, and AI Developer Tasks you can hand to a coding assistant.
Trust and privacy
ZIPs and extracted source files are deleted after scanning, temporary workspaces are removed, uploaded code is never executed, and only masked result data is stored.
Scan only projects you are authorized to review. This is a pre-launch review, not a replacement for professional testing, and it does not guarantee security.