Skip to content

Security audit for AI-built apps

It works. Is it safe?

You shipped with Cursor, Lovable or Bolt. AI writes the happy path and skips keys, payments and rate limits. I find what breaks first.

Fixed price · 48 hours · no calls · read-only

What I usually find

The same holes, almost every time

  • 01

    Leaked API keys

    OpenAI or Supabase service-role keys in client JavaScript. DevTools, then your bill.

  • 02

    Unsigned payment webhooks

    Anyone can POST “payment succeeded” and the app believes it.

  • 03

    Missing row-level security

    One API call dumps the user table.

  • 04

    Cloud bill traps

    Cheap at 10 users. Thousands a month at 10,000.

  • 05

    No rate limiting

    Login and signup open to brute force and spam.

  • 06

    Happy-path code

    The first failed API call is a 500 for your user.

What you get

A report you can act on

  • A 10–15 page PDF in plain English

  • Every finding: what breaks, what it costs, how to fix it

  • P0 / P1 / P2 — fix P0 this week

  • A short video of the critical issues

Process

How it works

  1. 01

    Send the repo

    Read-only GitHub invite or a zip. I don’t change your code.

  2. 02

    48 hours

    Every finding is verified by hand. If it’s in the report, it’s real.

  3. 03

    Fix or hand off

    Give the report to your developer — or I close the critical issues in 3–5 days.

Price

One price.

$500

fixed

  • Full repo
  • Plain-English PDF
  • Prioritized findings
  • Video walkthrough
  • 48 hours

Not sure? Message me — I’ll send 5 findings free.

Start the audit

Then I fix it

Found holes? I close them.

Critical issues in 3–5 days, $2,000–$5,000 from the report. No hourly billing. Same person who found them.

FAQ

Questions

  • Do you need production access?

    No. The repository is enough.

  • Will you change my code?

    No. Fixes are a separate job, with your approval.

  • What stacks?

    Next.js, React, Node, Go, Supabase, Firebase, Stripe, Vercel. TypeScript and JavaScript.

  • Who are you?

    Anton Goncharik. I build and repair web services. Cases are on the main site. Cases on the main site

  • Why not run a scanner?

    Scanners dump 200 findings. 180 are noise. I tell you which 5 will hurt.

One leaked key away from a bad week.

Get the audit