Security audit for AI-built apps
A vibe coding security audit,before someone hostile runs one.
If an AI tool wrote most of your codebase, nobody has actually read it. We do — by hand, against the checklist built from real vibe-code breaches — before your users or an attacker read it first.
2,000+
vulnerabilities found across 1,400+ scanned vibe-coded apps — including 400+ exposed secrets and personal data
Escape.tech, 2025
~50%
of code snippets generated by five major LLMs contained impactful, potentially exploitable bugs
Georgetown CSET, 2024
~56%
AI code security pass rate — flat since 2025 despite better models. Volume grew; safety did not.
Veracode, Spring 2026
What we look for — the list AI keeps getting wrong
Every documented vibe-code breach follows the same short list. Secrets and API keys shipped to the browser. Database tables with no row-level security. Authorization that exists only in the interface. No CSRF protection, no security headers, no rate limiting. Payments and webhooks that trust the client.
A December 2025 audit of fifteen production apps built with five major AI tools found sixty-nine vulnerabilities; every single app lacked CSRF protection. This is not a rare edge case — it is the default output.
The audit exists to answer one question honestly: what would break first, and how bad would it be? You get that answer in writing, ranked by risk, whether or not you ever hire us to fix it.
What the audit covers
- Secrets exposure
- API keys, tokens and credentials in client bundles, repos or edge functions — the fastest route to a five-figure cloud bill.
- Data access control
- Row-level security, object permissions and API authorization, tested as a real attacker would: with your own public keys.
- Authentication
- Session handling, password flows, role checks server-side, account takeover paths. Not just whether the login page exists.
- Injection & XSS surface
- Input validation, output encoding, and query construction — the classic OWASP list AI fails at documented rates.
- Payments integrity
- Whether prices, entitlements and webhooks can be manipulated from the client. Stub payments that always succeed get found here.
- Operational safety
- Backups, error monitoring, rate limits and dependency risk — what turns a bug into an outage, and an outage into data loss.
How it works
Send the URL
Live app URL, plus repo access if you can. One form field. Built with Lovable, Bolt, Cursor, v0, Replit or anything else.
Senior engineer reads it
By hand, against the breach-pattern checklist. Automated tools assist; judgment is human.
Written findings, 48 hours
Ranked by risk with a plain-language explanation of each issue. Fix it yourself, take it anywhere, or have us fix it at a fixed price.
Where to start
Client Delivery Sprint
$999 one-time
One defined outcome, delivered by a senior engineer on a fixed scope. The lowest-risk way to see how we work.
Embedded Delivery Pod
From $4,000 per month
Ongoing senior-led delivery with a clear monthly capacity. We prioritize with you, own delivery, and stay.
Every engagement starts the same way: the free technical audit. You see our thinking on a real project before any money changes hands.
Straight answers
- Why is the audit free?
- It is how every engagement starts. You see the quality of our thinking on your real code before spending anything. Some audits turn into rescue work; the rest cost you nothing and still make your app safer.
- Is this a compliance or penetration test?
- No. It is an engineering security review focused on the failure modes AI-generated code actually ships. If you need formal compliance work, the findings give you an honest starting point.
- What do you need access to?
- The live URL alone finds a lot. Read access to the repo finds the rest. We sign NDAs without drama, and we never need your production database.
- What happens to the findings?
- They are yours. We do not publish them, name you, or use them for anything except the report you receive.
Get the auditbefore someone else runs it.
Attackers scan for these holes automatically. A senior engineer finding them first is free and takes 48 hours.