Book a check

It works.
But is it safe to launch?

A 48-hour, 38-point production readiness check for apps built with Lovable, Bolt, Replit, v0 or Cursor. Automated scanners find the 20% a script can find. This finds the 80% it can’t — the logic your AI tool wrote confidently and wrong. Fixed price.

No call required to start. Send a URL, get the report in 48 hours.
Apps checked against all 38 points so far: one — my own, and the entire report is public.
Not ready to book? Run the same 38 checks yourself — the checklist is free.

98%of 1,072 scanned AI-built apps had at least one security flaw
16%had a critical one — anyone could read or change user data
308exposed their database key in the browser
172allowed data deletion with no authentication at all

Source: Symbiotic Security scan of 1,072 Supabase-backed apps built on Lovable, Bolt, Replit, v0 and Windsurf. Their research, not mine — cited because it is the best public measurement of this, and because the numbers below are the ones a scan like that never reaches.

And what a scan like that cannot see

Three findings from the audit I ran on my own AI-built booking app. No automated scanner reports any of them, because none of them is a vulnerability with a signature — each one is the product being wrong, quietly, while everything returns 200.

Found by hand, in my own app, and published in full — including the six findings I deleted because they did not survive a second look. Read the full audit →

Scan your own app in 30 seconds — free

Paste your app's URL. You get back what a stranger can already see: keys exposed in your JavaScript, security headers you are missing, and whether your original source is downloadable. No signup. Your database is never contacted.

This is the passive, outside-only version. The paid check verifies every finding by hand and covers the twenty-odd things a scanner physically cannot see — starting with business logic that fails politely instead of erroring.

The gap nobody warns you about

AI tools got you to a working app remarkably fast. What they quietly skipped is everything between "it works on my screen" and "strangers are using it with real data."

The database is often wide open

Row Level Security is off by default on new tables. Your app looks locked because the UI hides things — the database doesn't.

Payments look fine until they aren't

Unverified Stripe webhooks mean anyone can tell your app a payment succeeded. The money never arrives.

Validation lives in the wrong place

If the only check is in the form, it isn't a check. Requests don't have to come from your form.

How it works

  1. You send a URL

    Plus read access to the repo and database if you have it. If you don't, the external-only check still covers a lot.

  2. I run the checklist

    Automated scans plus a manual pass across 38 checkpoints. Every finding is verified by hand before it goes in the report.

  3. You get the report in 48h

    Findings ranked by severity, with the exact file, what breaks, and an estimate of how long each fix takes. Plus a 30-minute call to walk through it.

What gets checked

38 checkpoints across five areas. The full list ships with the report — nothing is hidden behind the invoice.

Access & data

  • Row Level Security on every table
  • Keys and secrets exposed in the browser bundle
  • Service-role keys reaching the client
  • Secrets committed to git history
  • Admin routes reachable without a session

Money & integrations

  • Stripe webhook signature verification
  • Prices trusted from the client side
  • Third-party API keys called from the front end
  • Email and file upload abuse paths

Correctness

  • Server-side input validation
  • Multi-tenant isolation — can user A see user B?
  • Error handling and what errors leak
  • Rate limiting on expensive endpoints

Launch readiness

  • Backups and whether a restore actually works
  • Security headers, HTTPS, CORS
  • Vulnerable dependencies
  • Account and data deletion paths
  • What happens at 100× today's traffic

AI products & widgets

  • Widget origin binding
  • Isolation between locations
  • Messenger webhook verification
  • Prompt injection resistance
  • Data retention
  • Product-promise stress test

I ran this on my own app first — here is everything it found

Before selling this to anyone, I pointed the checklist at a booking SaaS I built with AI. Two high-severity issues. One was a booking confirmed against an email nobody had verified — the rule existed only as a sentence inside a prompt, enforced by nothing. The tenant boundary everybody worries about? Solid under direct attack. What broke was the layer above it.

Read the full teardown →

Pricing

Fixed price on the check. Anything beyond it is quoted only after I've seen the actual scope — so neither of us is guessing.

External Check

$99
one-off · no repo access needed · 24h
  • Everything visible from outside
  • Exposed keys, headers, open endpoints
  • Short written report
Start
Most booked

Production Readiness Check

$199
one-off · full 38 points · 48h
  • Business-logic review — the rules your AI wrote as prose, not code
  • All 38 checkpoints
  • Findings ranked by severity
  • Exact files and fix estimates
  • 30-minute walkthrough call
  • One free re-check after you fix
Book it

Deploy Watch

$39/mo
cancel anytime · no fix hours
  • Re-scan on every deploy
  • Alert only when something is new
  • Dependency advisories tracked
Start

Watch + Fixes — $149/mo

Everything in Deploy Watch, plus two hours of small fixes each month and priority on anything urgent.

Start

Monitoring re-runs on every deploy, because that is when things break — not on a calendar. Fixes are billed separately, in stages, so the scope is always visible before you commit.

What this is not

Being straight about the boundaries is cheaper for both of us than discovering them later.

  • This is not a penetration test and not a certified security audit. It's a structured readiness review against a published checklist.
  • This is not GDPR compliance certification. I'll flag the obvious gaps; the legal opinion has to come from a lawyer.
  • Nothing gets attacked. I only inspect what you've given me access to. No probing, no live exploit attempts — ever.
  • No guarantees against being hacked. Anyone promising that is selling you something. This finds the known, common, high-impact failures — which is where nearly all real incidents start.

Questions

I built it myself with AI. Will you tell me it's garbage?

No. Most of these apps are genuinely good at what they do — the gaps are in the boring parts the tools skip by default. The report is a list of specific fixes, not a review of your abilities.

Can I fix things myself after the report?

Yes, and plenty of people do. Every finding includes the file and what to change, written so you can hand it straight to your AI tool. One free re-check is included so you can confirm it actually worked.

What if you find nothing?

Then you get that in writing, which is worth having before a launch. It has happened in about 2% of scanned apps — so plan for findings.

There are free scanners now. Why pay you?

Free scanners read what is exposed in your bundle — so does mine, for free, at the top of this page. What they cannot do is confirm a finding is not a false positive, or catch the failure that never throws an error: the assistant that offers a 09:00 slot at 16:21 with a confirm button under it. Every finding in a paid report is reproduced by hand before it reaches you. A scanner hands you a list. I hand you the two that actually matter, proven.

What do you need from me?

The live URL, read access to the repo, and read access to the database dashboard. If you can only give the URL, take the External Check instead.

How fast can you start?

Usually same or next day. The 48 hours starts when access lands.

Who’s behind this

I’m Slavik. I build and run half a dozen small web products of my own, and most recently an AI receptionist and booking app — which is where the unglamorous parts live: auth, payments, webhooks, keeping one tenant’s data away from another’s.

This service exists because I got that app to the point of launching it and had no honest way to answer the one question that mattered: is this safe to put in front of strangers? So I wrote the list I wanted to have. Then I ran it on my own app before I ran it on anyone else’s, and published everything it turned up — including the six findings I had to throw out, because they turned out to be wrong.

That write-up is the most useful thing I can show you. It’s the same report you’d get, run on my own code.

Read the audit I ran on my own app →

Find out before your users do

Send the URL. If there's nothing worth fixing, I'll tell you that in the first reply and you keep your $199.

Or email hello@itworksbut.com