Skip to content

For AI-built codebasesBuilt with Claude Code, Cursor, Lovable or Bolt?

You shipped fast.Now find out what it cost you.

AI writes working code quickly. It also leaves committed API keys, outdated dependencies and missing permission checks behind. Connect a repository and get an automated review that shows you exactly what to fix first — in language you do not need a security engineer to translate.

3-day trial · card required · read-only GitHub access

harbourline/harbour-app · main

Needs attention

Two live credentials are committed to this repository and three dependencies have published advisories. Rotate the credentials first — the exposure continues until you do.

2

Critical

3

High

3

Medium

3

Low

CriticalHigh confidence

Supabase service role key committed to the repository

apps/web/.env.production:7

CriticalHigh confidence

Next.js version allows middleware authorization to be bypassed

package-lock.json · next 15.2.2 → 15.2.3

MediumLow confidence · requires human review

API route reads a record by id without an ownership check

app/api/invoices/[id]/route.ts:9

Not covered by this audit: SQL files, 38 vendored files, and ESLint stopped at its time limit after 310 of 412 files.

Illustrative example. Automated findings require review and are not a penetration test.

What we check

Five things AI-assisted code gets wrong

Not because the model is careless, but because it cannot see your whole system — and neither can a founder reading a diff at midnight.

Credentials in your code

API keys, database secrets and tokens committed to the repository. The single most common finding, and the one that costs the most.

Dependencies with known advisories

Your lockfile read against the public advisory database, with the exact version that fixes each one.

Missing permission checks

Endpoints that fetch a record by id and return it without confirming it belongs to the person asking.

Unsafe patterns

Raw HTML rendering, string-built SQL, cookies without the Secure flag, and other patterns with a long history of going wrong.

Reliability gaps

Swallowed errors and unawaited promises — the reason a webhook can report success while quietly doing nothing.

What we could not check

Every report names the files skipped, the languages unsupported and the scanners that ran short. Coverage you cannot see is not coverage.

Four steps

Connect a repository. Read the report. Fix. Re-scan.

The first audit takes a couple of minutes. You do not install anything, and you do not give us write access.

Connect GitHub

Install our GitHub App and pick the repositories it may see. Read-only, and you choose the list.

Start an audit

Choose a branch. We fetch a snapshot into an isolated sandbox and run the scanners that fit your languages.

Read the report

Findings ordered by what matters, each with the file, the line, the evidence and what to do about it.

Fix and re-scan

Re-run against your fix branch. The report tells you which findings you closed and which are new.

How we handle your code

We never run your code. Not once, not anywhere.

A code scanner that installs your dependencies to check them has already executed whatever those dependencies wanted to run. That is the supply-chain attack we exist to warn you about, so we refuse to perform it.

No dependency installation

We read your lockfile and check the exact versions it pins against the advisory database. Nothing is installed, so nothing gets to run.

Isolated, disposable sandboxes

Each scan runs in its own throwaway container with no network access, no credentials in its environment, and hard CPU, memory and time limits.

Your source is not kept

The snapshot is destroyed when the scan ends. We keep the findings and short evidence excerpts — never whole files, never an archive.

Read-only, least privilege

The GitHub App asks for read access to repository contents and nothing else. It cannot push, open pull requests, or change your settings.

Honest limits

What this is — and what it is not

It is

  • An automated code-health and security review
  • Evidence you can check yourself, line by line
  • A prioritised list of what to fix first
  • An honest account of what was not covered

It is not

  • A penetration test
  • A certification or compliance audit
  • A guarantee that your code has no problems
  • A substitute for a human review before you scale

Automated analysis finds classes of problems, not every problem. We report potential issues with a confidence level, and we mark the ones a person needs to judge. We will never tell you your code is secure, because no tool can honestly say that.

Pricing

Two plans. Both start with a 3-day trial.

Solo for a founder shipping one or two codebases, Team for several. The trial needs a card and runs the full product; there is no free plan.

Solo
For a founder shipping continuously and re-scanning as they fix.
$29.00
Billed monthly
  • 3-day trial, card required
  • 20 reviews per month
  • 3 connected repositories
  • 3 workspace members
  • Weekly scheduled reviews
  • Shareable report links
  • What changed since your last review
Team
For a team with several codebases and someone accountable for all of them.
$99.00
Billed monthly
  • 3-day trial, card required
  • Unlimited reviews, within fair use
  • 10 connected repositories
  • 10 workspace members
  • Daily scheduled reviews
  • Shareable report links
  • What changed since your last review

Find out before your users do

One repository, one audit, a few minutes. If it comes back clean, that is worth knowing too.

3-day trial · card required · read-only GitHub access