RD / Services

Security review for AI-built apps

Built your app with Cursor, Lovable, Bolt or Copilot? I check the authentication, data access and API keys that AI-generated code often gets wrong, before real users and real data arrive.

150+ security vulnerabilities reported · 7 acknowledged by Meta · 2 Linux kernel CVEs

  • Authentication
  • Data access & RLS
  • Secrets & API keys

For founders, solo builders and small teams who shipped quickly with AI coding tools and now need to know whether one user can reach another user’s data.

Before launch, before taking payments or before onboarding your first business customers.

What we examine

  • Review sign-up, login, sessions and password reset.
  • Check who can read and change whose data, including row-level and object-level rules in Supabase, Firebase or your own API.
  • Look for secrets and API keys exposed in the client, the repository or public storage.
  • Test payment, webhook and admin flows that trust the client too much.

How an engagement runs

Send a short brief

The product, what changed, what you need to know and by when. A paragraph is enough, and I reply within three days.

Get a written proposal

Scope, method, exclusions, deliverables, price and dates. Confidentiality, NDA and retesting terms are agreed in the same proposal.

Follow the work as it develops

For assessments, you see evidence and priorities as they emerge. For engineering, you review the agreed milestones.

Report and walkthrough

You receive the report or the delivered work and a walkthrough with your team. Any further fixes or verification are agreed with you.

Security vulnerabilities I have reported

I have reported 150+ security vulnerabilities, including seven in Facebook and Instagram that Meta validated and acknowledged. Your application gets the same attacker’s view: authentication, permissions and the business logic between them.

See the track record

Questions before we begin

Is this the same as an automated scan?

No. Scanners and AI review tools catch common patterns. I test the app the way an attacker would: I sign up, switch between accounts and try to reach data that is not mine.

What do you need from me?

The app URL, two test accounts with different roles and, if possible, read access to the repository and backend settings. Please do not send production passwords by email.

Which stacks do you cover?

Apps built with tools such as Cursor, Lovable, Bolt, Replit, v0 or Copilot, typically on Next.js, React, Supabase, Firebase or a Node.js API. Tell me your stack and I will confirm the fit.

How quickly will you reply?

Within three days at most. You get questions about your product or an outline of the proposal.

What does it cost?

Published prices are starting points. The final price depends on scope and technical complexity and is fixed in the written proposal before work starts.

How long does it take, and when can you start?

Duration and start date depend on the scope, the technical complexity and my current workload. The proposal states the dates.

Can we work under an NDA?

Yes. Confidentiality terms, including an NDA if you need one, are agreed as part of the proposal before you share code, credentials or findings.

Is a retest included?

Retesting is agreed for each engagement in the proposal: which findings, which version and the time window.

Do you work with agencies?

Yes. Agencies can bring me in for a client’s project. Delivery terms, including white-label reports, are agreed case by case in the proposal.

Related reading

Services

08Contact

Shipping something that handles user data?

Send me a short brief. I reply within three days with questions or a proposal outline, and the price is agreed in writing before work starts.