Public data paths
Routes, storage buckets, documents, or tables that can be read without the user access you intended.
Same-day AI app safety pass
A $49 triage pass for founders who built with Lovable, Bolt, Replit, Cursor, v0, Base44, Supabase, Firebase, or Stripe and need a quick read on whether the launch is leaking data, keys, or access.
Exposure checklist
Routes, storage buckets, documents, or tables that can be read without the user access you intended.
API keys, webhook secrets, signing keys, admin tokens, service role keys, and private endpoints exposed to the browser.
Login redirects, protected pages, admin views, password reset, session expiry, and cross-user data checks.
Over-open rules, rules that only work in preview, unauthenticated writes, and missing owner checks.
Test/live key mismatch, unverified webhooks, duplicate fulfillment, and subscription access not matching payment state.
Preview-only assumptions, missing environment variables, server/client mismatch, and logs that point to the first blocker.
Deliverable
The biggest findings first, with plain-language impact and what to fix next.
See sample formatRun the checklist before paying. If the score is weak, send the result and I can quote the smallest useful review.
Open free checkerNormal user-flow evidence, deploy/log clues, and code references when repo access is provided.
If there is a clean repair path, I quote the smallest useful sprint. If not, I say so.
Boundary
Send a public app link, read-only repo access, builder details, logs, or screenshots from tools you own.
Checks stay inside normal app usage, code/config review, deploy logs, and authorized project access.
No brute force, no scraping private records, no guessing credentials, and no testing apps without permission.
Move before launch