Paste a repo. In a few minutes you get an audit where every finding cites its evidence — the query we ran, the answer we got.
Runs read-only. Source deleted after the scan. No account needed.
We scan read-only, cite evidence for every finding, open verified fix PRs, and keep watching under care.
Static engines, schema replay, and — with your say-so — live probes, in an isolated sandbox. Read-only, and your source is deleted after the scan.
Each finding carries a location and a measured-or-estimated label. The query we ran, the answer we got. No evidence, no finding.
A fix passes a verification ladder — rescan, typecheck, tests — before we open the pull request. You review; nothing merges itself.
Push-triggered rescans, scheduled full scans, and alerts only at the level you choose. A monthly summary of what changed.
141 checks across 8 families. From Supabase row-level security to Stripe webhooks — one concrete example per family:
a table readable without a session, proven by the query we ran
a service-role key in client code, with the file and line
a webhook handler that never verifies the signature
a password reset flow that leaks whether an email exists
a server action with no auth check inside its boundary
a 4 MB bundle measured five times, median reported
a column that averages 4 KB per row, priced at your tier
no backups on the database your business runs on
A sample transcript. Nothing here runs against your app without your say-so, and nothing merges without your review.
A one-time audit, or a care plan that re-asks every question on a schedule.
We scan with read access and nothing else. Active probes against your live app run only after you have proven you own it.
Optional connections — a database role, a Supabase token, Vercel, Stripe — are scoped, used for the scan, and never stored in our database.
Your source never persists outside the scan sandbox. Snippets stored with findings are at most ten lines and pass a redactor.
We never execute your application. Fixes are proposed as pull requests you review; nothing merges itself without your standing opt-in.
What we keep: findings, evidence excerpts, and reports, under a retention policy you can see. What we sell: audits and monitoring. What we don't: your data.