For people who ship with AI and don't speak security
Find out what your app is leaking — in plain English.
Paste your app's URL. In about 30 seconds you'll get a security report sorted worst-first: what's exposed, what it means, and exactly how to fix it. No jargon, no enterprise sales call.
Tuned for AI codegen
Catches the exact mistakes Lovable, Bolt, Cursor and friends make — leaked keys, a Supabase service_role in the browser, an .env in /public.
Verifies before it touches
Deeper checks only run after you prove you own the domain with a DNS record. The free scan reads only what any visitor can already see.
Priced for indie hackers
Free first scan. $29/mo to watch one app continuously and get pinged the moment a new key leaks or a table opens up.
The report is the product.
Every finding tells you three things: what it means in a sentence, the evidence we saw (secrets always masked), and the exact fix. Sorted so the two things that can actually hurt you are at the top and the noise is at the bottom.
Pricing
Free to look. $29 a month to keep watching.
The free scan reads only what any visitor can see. The paid plan adds the deep checks on apps you own, and pings you the moment something new leaks.
Free scan
$0 · no signup
The passive engine — reads only what any visitor can already see.
- Scan any URL — no account needed
- Exposed API keys & secrets (incl. Supabase service_role)
- Exposed .env and reachable sensitive files
- Security headers, TLS, and cookie flags
- Leaked source maps
- Plain-English report, sorted worst-first
Pro
$29 / month · per app
The active engine on apps you own — plus monitoring and alerts.
- Everything in the free scan, plus:
- Deep checks on domains you own & verify
- Missing authorization on your endpoints
- Supabase Row-Level-Security gaps
- CORS-with-credentials & storage-bucket exposure
- Dependency CVEs
- Continuous monitoring + re-scan on every deploy
- Alerts (email / Slack / Telegram) on new or worse findings
- Saved history, trends, and multiple apps