Public scan · No login
Scan your app.
See what strangers can find.
Free. Runs the same scanner we use in coaching. No login, no install. Drop a zip or paste a public GitHub URL.
25 MB zip · 50 MB clone · 5000 files · 60s scan · Runs on rules only (no AI)
What we check
We check the eight places AI-built apps get hurt.
SEC
Leaked keys & passwords
Secret keys pasted into your code. Anyone who finds one can act as your app.
AUTH
Who can see what
Doors that skip the sign-in check, and data one customer can read that belongs to another.
INPUT
Malicious input
Places where a crafted input stops being data and starts giving your app orders.
CRYPTO
Weak encryption
Passwords and secrets protected with methods attackers already know how to break.
API
Open backend doors
Endpoints anyone can call, no limits on how hard, and debug switches left on in public.
LOG
What your logs give away
Secrets and personal data leaking into logs and error messages strangers can trigger.
WEB
Scripts planted in your pages
Ways an attacker can run their own code inside your app, as your users.
SUPPLY
Third-party code
Building blocks your AI pulled in that carry known holes attackers scan for.
Your upload auto-deletes in 7 days. Findings purge in 7days. Emails only used for cohort launch announcements — unsubscribe one click.
By scanning, you agree to our Terms and Privacy Policy.
Want a coach to walk it?
The scan is the door. Coaching is the room.
A scanner shows you what’s broken. A coach shows you why you keep writing it and how to stop. Early AI-dopters get the platform for free.