Free · Written reply within 2 business days
Get a free security check of your AI‑built app.
Send us your app's link, your scanner results, or both. Within 2 business days, a real person writes back with the top 3 risks anyone can see from outside, and which of your scanner's warnings are worth fixing. Free. No call. No obligation.
What you get for free
Your top 3 risks.
What anyone can see from outside your app, ranked and explained in plain English. If we find fewer than three, we say so.
A read-out of your scanner.
Paste results from Lovable's security scan, Supabase Security Advisor or any other tool. We tell you which warnings are real and which can wait.
A clear next step.
Sometimes that's “you're fine for now.” If you need more, we tell you what and why.
How we check: from the outside only
A free check is passive. We look only at what your app already shows every visitor, the same things your browser receives when you open it.
We look at
- the HTML of your public pages
- the JavaScript files your site sends to every visitor (where leaked keys show up)
- security headers (settings your server sends that tell browsers what to block)
- your SSL certificate (the padlock in the address bar)
- the scanner results you paste
We don't
- log in or create accounts
- send requests to your database or API (the back door your app talks to)
- try passwords or guess links
- run anything that could slow your app down
- change anything in your app
The deeper checks, like whether users can see each other's data, need your code and your permission. That's the Vibe Code Audit.
If we spot a secret, we check it's your app first
If we find something sensitive, like a secret key in your public code, we tell you that we found it. We share the details only after you confirm the app is yours. It takes a minute, and you pick the way:
- 1.
Reply from an email address on your app's domain.
- 2.
Add a small file we send you to your site.
- 3.
Send a screenshot from your own scanner account.
Until then, you get the general advice that applies to any app. This protects you: nobody can use our free check to learn about an app that isn't theirs.
What happens next
- 1
Right away:
you get an email confirming we have your request.
- 2
Within 2 business days:
we check what's visible from outside and read your scanner results.
- 3
You get a written reply:
your top 3 risks, what your scanner got right, and the next step we'd suggest.
- 4
Your call:
fix it yourself, book an audit, or book a 30-minute call to talk it through. No follow-up pressure.
Who the free check is for
For
- Founders who built an app with Lovable, Bolt, Cursor, Replit, v0, Base44 or Claude Code, and now have real users, real payments, or both.
Not for
- Apps you don't own or aren't authorized to have checked. We don't check competitors' apps or apps you found online.
Questions about the free check
What do I get for free?
A written reply within 2 business days with the top 3 risks anyone can see from outside your app, a read-out of any scanner results you paste, and the next step we'd suggest. It's free, with no call and no obligation. If we find fewer than three risks, we say so.
Do I need a call?
No. Everything happens in writing: you fill in the form, and we reply by email. If you'd rather talk, you can book a 30-minute call, but it's optional. You can read the reply first and decide in your own time.
Will you touch my app?
No. A free check is passive. We look only at what your app already shows every visitor: its public pages, public code, security headers and SSL certificate, plus the scanner results you paste. We don't log in, create accounts, contact your database or change anything.
Why do you ask me to confirm the app is mine?
Because details about a security problem are dangerous in the wrong hands. If we spot something sensitive, like a secret key, we share the details only with the owner. Confirming takes a minute: an email from your app's domain, a small file on your site, or a screenshot from your scanner account.
My app isn't live yet. Can I still get a free check?
Yes, if you have scanner results. Paste what Lovable's security scan, Supabase Security Advisor or another tool reported, and we'll tell you which warnings matter before you launch. Without a link or scanner results there's nothing for us to look at yet; the launch checklist is a good place to start.
What's the catch?
There isn't one. The free check shows you how we work and whether a full audit is worth it for your app. Sometimes the honest answer is “not yet,” and we'll say that. If you want more, the audit is a fixed price, listed on our pricing page.
Rather talk it through?
Book a 30-minute call. Bring your app and your questions.
SELFOIA