Security scanningfor AI-built apps

Finds exposed secrets, misconfigured RLS, and auth bugs in apps built with Lovable, Bolt, Cursor, or Claude. No GitHub access needed.

Free preview · Fix prompts and recheck from $9

53 of 61 lacked standard headers·14 critical findings·May 2026 early samplemethodology →

Example finding

CRIT

Supabase RLS disabled on users

Anon key exposed in client bundle. Any visitor can read and write all rows without auth.

CVE-2025-48757 patternExample, not a prevalence claim

Fast first-pass review. Not a penetration test. Checks the public surface and artifacts you provide. Cannot prove your app is fully secure. See our research on AI-built app vulnerabilities →

From the same maker

Two tools. One guarantee: no secrets leak.

VibeScan · Web

Scan your deployed app

Checks your live app's surface for exposed API keys, misconfigured Supabase RLS, missing security headers, and more. No code or repo access needed.

Sieve · macOS

Sieve app icon

Guard your local secrets

Before you push: scan local AI coding histories and environment files for leaked API keys and credentials. Processing stays on your Mac.

Get Sieve for Mac

VibeScan catches what's already live. Sieve catches what's about to ship. Use both.

AI tools generate code fast. The security gaps they leave behind are systematic — the same patterns appear across Lovable, Bolt, Cursor, and Claude-built apps. VibeScan checks for the most common ones without requiring access to your source code.

VibeScan's first 61 completed scans found 14 critical findings, including live Stripe secrets and Twilio credentials in public JavaScript. VibeScan fetches your deployed bundle, scans for credential patterns, and decodes JWTs to check for privileged roles.