Vol. 01 · Cohort 1 · Wed 1pm CT
Where should we start you?

Two quick questions. We’ll route you to the right page with the right view already selected.

Q1Why are you here?
Pick a path to continue.
Cohort01Eleven survived

Ship fast.
Don’t ship secrets.

Seatrial is the security track inside Early AI-dopters, a Skool community for people shipping with AI. Join the community to unlock the 12-week cohort — a human coach reviews the code your AI wrote before strangers do.

Coaching, not auditing. The point is that you learn it.

Cohort 1 live now · Live Wednesdays, 1pm CT
Five ways to read it
Step-by-step — same findings, your editor.
Public for 14 days · 3 forks · 22 stars · 2 keys exposed
What to do first

Rotate keys before investigating.

You have 1 critical and 1 high sitting in a repo where the repo has been public 14 days with 3 forks. The keys are live and someone else can see them. Rotate Stripe first, then OpenAI; the report below has the rotation links. Forensics can wait until your keys are dead.

public 14 daysforks 3stars 22public since 2026-05-05
Form
SS-002 · Rotation

Rotation steps

· 2 keys to rotate
  1. Step
    Stripe logostripe

    Stripe

    Webhook signing secrets are separate from API keys and must be rotated in the webhook config, not just the API keys page.

  2. Step
Demo data. Your scan opens on step-by-step.

How it works.

One question at four points in the app’s life: is it safe to put in front of people?

Scan

Scan it before launch.

Point Sentinel at your repo or live URL. It examines the app the way an attacker would, lands findings in plain words, and gives your AI a precise fix. A human coach (right now, that’s Ty) reviews them with you in the weekly session.

free · no login
Monitor

Monitor it in production.

A scan is a photograph; production keeps moving. Monitor re-checks on your cadence — weekly on the free plan, up to hourly on paid plans — and emails you only when something new appears. A known finding never re-alarms.

weekly → hourly
Verify

Verify what it claims.

Assay reads the claims your app makes and tests the code against each one. Each failure is triaged: a real defect in the code, or a stale claim in the spec — and when it can’t tell, it says so.

per claim
Certify

Certify each release.

Readygate issues version-locked release certificates — the claims that were verified, the scans that passed — and flips them stale the moment a new release ships.

early access
See the MCP workflow — install once, catch it three ways →

Shipped by Early AI-dopters.

Seatrial is the coaching platform for Early AI-dopters— a Skool community for people shipping with AI who don’t want to ship a breach. New members get auto-invited the moment they join the community. No waitlist, no gatekeeping.

Join Early AI-dopters already 200+ vibe-coders inside
I shipped a side project on Sunday, leaked a Stripe key in commit two, and didn’t notice until Wednesday’s session. Ty walked me through the rotation in ten minutes. Forensics after. Rotate first.
S. Reyes· Cohort 1 · ships in Cursor