Security proof for Lovable, Bolt, v0, Replit & Cursor

Is your app Shippable?

Paste your URL and, in seconds, see exactly what a stranger could pull from your database, secrets, and files right now — before you ship.

Free scanNo credit cardRead-only · ownership verified

Every finding is demonstrated, not assumed
Scans are 100% read-only
Ownership verified before every scan
The problem

AI app builders skip the boring, critical stuff

Lovable, Bolt, v0, Replit and Cursor are great at shipping features fast. They don't ask "should this table be public?" — and most founders don't know to ask either.

Unlocked databases

Supabase ships with Row-Level Security off by default. If nobody turns it on, the public “anon” key — sitting right in your page source — can read every row in every table.

Secret keys in the browser

Stripe, OpenAI, and Supabase admin keys occasionally end up baked into the JavaScript bundle your visitors download — visible to anyone who opens dev tools.

Public files & missing headers

Storage buckets left open, disabled email confirmation, missing security headers — small settings that quietly add up to a wide-open app.

Not a guess. Proof.

Every finding shows its work

Other tools flag a setting and hope. Shippable actually demonstrates the issue — read-only — so you can see exactly what a stranger could see, with your own eyes.

Critical

Table 'users' is readable by anyone

Your users table has no Row-Level Security policy. The public anonymous key embedded in your site's front-end can query it directly — no login required.

Proof — live evidence, not a claim
GET https://xyzcompany.supabase.co/rest/v1/users?select=*&limit=2Authorization: Bearer <public anon key found in your page source> → 200 OK — read 2 row(s) anonymously table holds ~1,284 rows total columns exposed: id, email, full_name, stripe_customer
Critical

Stripe secret key exposed in the browser

A live Stripe secret key (not the safe publishable one) was found inside a JavaScript file your app ships to every visitor.

Proof — live evidence, not a claim
FOUND IN: /assets/bundle-a3f1c9.js (line 4,812) sk_live_51NcX7K••••••••••••••••••••••••a8Kd key type: Stripe secret key (live mode) redacted here — full value only shown to you, after verification
The paid upgrade

That's the free layer. Here's what happens when you send in a team.

A multi-agent AI team actively attempts to exploit your app — not just read it — always scoped from your free scan first, so it never runs blind.

Live — AI Red Team scan
→ Scoped from your last scan — 2 critical, 1 high, 1 medium already confirmed
→ Agent · Auth — attempting privilege escalation on /admin…
→ Agent · Business logic — testing checkout for price manipulation…
→ Agent · Injection — fuzzing 14 input fields for SQL & command injection…
→ Agent · SSRF — probing whether your server will fetch internal URLs…
→ 3 of 4 attempts confirmed exploitable. Full proof unlocked on Starter.

Hard cost ceiling per run · results in minutes, not seconds · never billed blind

How it works

From URL to fixed in four steps

1

Paste your URL

Just the link — myapp.lovable.app. Nothing to install, no GitHub access needed.

2

Prove it's yours

We generate one line for your page's <head> — plus a ready-made prompt to paste straight into whatever AI built it.

3

We scan, read-only

Secrets, database rules, storage, headers — checked in under a minute. Nothing is ever changed on your app.

4

Copy-paste the fix

Exact SQL, or a plain-English prompt for your AI builder to apply. Re-scan anytime to confirm.

Pricing

Know for free. Then bring in the AI team.

Seeing that you have a problem should never cost anything.

Free

$0 / forever
  • One scan, full severity counts
  • Ownership verification
  • Proof & evidence for each finding
  • Copy-paste fixes (SQL + AI-builder prompts)
  • Continuous re-scanning & alerts
  • AI Red Team scans
Scan for free

Growth

For teams shipping daily
$39 / month
  • Everything in Starter
  • 8 AI Red Team scans/mo — double the offensive coverage
  • Built for teams pushing multiple deploys a week
Cover every deploy

Need more coverage? Extra AI Red Team scans are $6 each, anytime.

Find out before someone else does.

One free scan. No credit card. Takes about a minute.

Scan your app free