Skip to content
SELFOIA
Free check
Open menu

How we handle your app, code and keys.

We work from your code, your database structure and test accounts we create. We never ask for database passwords, secret keys or your customers' data. We never change your live app without your written OK.

The short version

  • Read-only access to your code. Nothing more by default.

  • We test with our own test accounts, ideally on a copy of your app with fake data.

  • We never ask for database passwords, secret keys or data exports.

  • If a check shows real customer data, we stop at the first proof and copy nothing.

  • Nothing changes in your live app without your written OK.

  • When the work ends, we delete our copies.

What access we ask for

For a Vibe Code Audit we need three things. We send you step-by-step instructions for each.

  1. 1.

    Your code, read-only. Access to your GitHub repository that lets us read but not change anything, or a zip file of the code. How to share it: we send you the exact steps for your setup.

  2. 2.

    Your database structure, not your data. An export of your tables, your access rules (Supabase Row Level Security policies: the settings that decide who can see what), your functions and your storage settings. How to share it: we send you ready-made queries. You run them and send us the result. No customer data is included.

  3. 3.

    Test accounts we create ourselves. We sign up to your app like any user would, ideally on a staging copy (a private copy of your app with fake data). How to share it: send us the staging link, or tell us it's fine to create test accounts on your live app.

If we see real customer data

Your keys and secrets

  • We never ask for your database password, your Supabase service_role key (the master key that skips all database rules), your Stripe secret key or your AI provider keys.

  • If you send us a secret by mistake, we delete it on our side and ask you to replace it: create a new key and switch the old one off. We'll show you how.

  • If we find a secret that's already exposed, for example in your app's code, we show only the first few characters in our report and tell you to replace it first.

  • Test-account passwords we create for your app are stored in a password manager and deleted at the end.

What we never do

  • Change your live app, database or settings without your written OK.

  • Run invasive tests: no load tests on your live app, no floods of requests, no attempts to take it down.

  • Guess real users' passwords or log in as real users.

  • Trick your staff or your users.

  • Test an app without the owner's written permission, or test anyone else's app.

  • Copy, download or keep your customers' data.

  • Share your code or findings with anyone outside the engagement.

  • Name your app or company in public without your written consent.

It's a review, not a penetration test. We look for problems the way a careful engineer would, without attacking your app.

The free check only looks from outside

For a free check we look only at what any visitor can already see: your page, its public code and its security settings. We don't log in, query your database or call your API. You confirm the app is yours when you ask for the check. If we spot a leaked secret, we share the details only after you prove the app is yours: with an email from the app's domain, a small file we ask you to put on your site, or a screenshot from your own account.

Your written permission comes first

Before a paid review starts, you confirm in writing that you own the app (or are authorized by its owner) and that we may test it within the access listed above. It's part of our Service Terms. We don't start without it.

Confidentiality and NDAs

Our Service Terms already include confidentiality: your code, your findings and your business stay between us. If you need a separate NDA, we'll sign yours or send you ours. Whoever works on your app is bound by the same confidentiality in writing. Every report is read and signed by Denys.

Do we use AI tools on your code?

Yes, to work faster, but only under terms or settings that don't let the provider train on your code, and never with your secrets or your customers' data in them. Every finding is checked by a person before it reaches you.

What we keep, and for how long

Delete

  • Your code copy, database structure export and our working notes: deleted within 30 days of final delivery (for On-call CTO and Guard: of the end of the engagement), unless you ask us in writing to keep them longer.
  • Test accounts we created in your app: we delete them, or ask you to, when we finish.
  • Anything sensitive you sent by mistake: deleted as soon as we see it.

Keep

  • Your report, so we can re-check or answer questions later. We keep an archive copy, with our emails about the work, for 3 years after the work ends, only to deal with questions or claims. You can ask us to delete any other copies.
  • Our contract with you, with the report, for 3 years after the work ends. Invoices, and any contract that supports one, for as long as Romanian accounting and tax law requires.
  • An anonymized log of the kinds of problems we find (for example “E02 · database rules off”), with no app name. We use it to improve our checks. We publish combined numbers only from apps whose owners agreed.

At the end, we remind you to remove our access. You can remove it at any time.

GDPR

SELFOIA S.R.L. is a company in Bucharest, Romania, so the EU's data protection law (GDPR) applies to anything personal we handle. Our Service Terms include a data processing agreement (DPA) that covers personal data we might come across, even by accident. This page describes how we work; it isn't legal advice for your own app.

Privacy · Terms

How it works, step by step

  1. 1

    Free check.

    You send your app and what worries you. We reply in writing within 2 business days: the three biggest risks anyone can see from outside, and which of your scanner's warnings are real.

  2. 2

    Book the audit.

    You pay online and confirm your written permission. We take 3 new audits a week.

  3. 3

    Share access.

    Read-only code, the database structure export, and a staging link if you have one. We send the steps.

  4. 4

    Review.

    We review your app across the five zones: Leaks, Break-ins, Money, Speed and Safety net. Every report is read and signed by Denys.

  5. 5

    Report.

    In 3 business days: every problem in plain English, ranked by severity, each with a fix prompt for your tool and a 2-minute check. Plus a recorded walkthrough and an optional 30-minute call.

  6. 6

    Fix.

    Fix it yourself with the prompts, or book a Fix Sprint or a Speed & AI-Cost Sprint. Your audit fee counts toward a Fix Sprint or Speed & AI-Cost Sprint booked within 30 days.

  7. 7

    Close.

    You remove our access, we delete our copies, and you replace any keys we saw.

How fast we reply

  • Free check: Written reply within 2 business days

  • Vibe Code Audit: Report in 3 business days, counted from when we have access

We're not a 24/7 emergency service. If you think a key has leaked right now, replace it first, then write to us.

Questions about access and data

Will you see my customers' data?

No. We work from your code, your database structure and test accounts we create. We don't ask for database passwords or your customers' data. If a check shows real customer data, we stop at the first proof and copy nothing.

Do you need access to my live app?

No. A staging copy with fake data is best. If you don't have one, we can test on your live app with our own test accounts, only with your OK and without touching real users' data.

What if I accidentally send you a key?

We delete it on our side and ask you to replace it: create a new key and switch the old one off. We'll show you how. Once a key has been shared, the only safe fix is a new one.

Do you sign NDAs?

Yes. Our Service Terms already include confidentiality, and if you need a separate NDA, we'll sign yours or send you ours.

How do I give you read-only access to my code?

We send you the exact steps for your setup. It's either read-only access on GitHub or a zip file of your code. Either way, we can't change your code.

What happens to my code after the audit?

We delete our copy, the database structure export and our notes within 30 days of final delivery, unless you ask us in writing to keep them longer. You keep the report. We remind you to remove our access.

Will you change anything in my app?

Not during an audit. In a Fix Sprint we only change what's in the agreed plan, and nothing goes live without your written OK.

Start with the free check. It only looks from outside.

Send us your app. No access needed, no call required. Written reply within 2 business days.