Ship fast,Claude, Codex, Lovable, Base44, Cursor, Supabase




stay covered.
Security that runs inside your agency's pipeline, on every project you build for clients.
The stack I specialize in
What I actually check.
Same models, same training data, same stack.The mistakes repeat, and that’s what makes them findable.
Is your database enforcing what you think it is?
The deepest check and the one nothing else does. I read your policies against your actual data model and test them as each of your roles.
Is your code written the way AI writes it when nobody asks for security?
Static analysis against rules I wrote for this stack, not the generic ruleset. Keys ending up in the browser bundle, request data written straight into the database.
Can it be broken into from outside, logged in as a real user?
Runtime testing against the deployed app, authenticated as each role you’ve defined, not a scan of the front door.
Is anything secret in the open?
Credentials committed to the repository, service keys and AI keys readable by any visitor, environment variables exposed to the client.
Is anything shipping with a known vulnerability?
Your actual dependency manifest checked against published vulnerabilities, the ones that were fine when you shipped and aren’t now.
Did a person verify all of it?
Every finding reproduced by hand before it reaches you, false positives removed, and re-ranked by what it would actually cost you. You get a short list of real problems, each with proof.
Is your database enforcing what you think it is?
The deepest check and the one nothing else does. I read your policies against your actual data model and test them as each of your roles.
Is your database enforcing what you think it is?
The deepest check and the one nothing else does. I read your policies against your actual data model and test them as each of your roles.
Is your code written the way AI writes it when nobody asks for security?
Static analysis against rules I wrote for this stack, not the generic ruleset. Keys ending up in the browser bundle, request data written straight into the database.
Can it be broken into from outside, logged in as a real user?
Runtime testing against the deployed app, authenticated as each role you’ve defined, not a scan of the front door.
Is anything secret in the open?
Credentials committed to the repository, service keys and AI keys readable by any visitor, environment variables exposed to the client.
Is anything shipping with a known vulnerability?
Your actual dependency manifest checked against published vulnerabilities, the ones that were fine when you shipped and aren’t now.
Did a person verify all of it?
Every finding reproduced by hand before it reaches you, false positives removed, and re-ranked by what it would actually cost you. You get a short list of real problems, each with proof.
Two ways I work with agencies.
Gate
The audit before you hand the project over. Every real way the app can be broken into, proven, with the fix.
Priced per project
Monitor
A one-time install that re-runs the testing on every pull request. No retainer.
Priced per install
Here’s how I test, how the continuous layer gets installed, and what it looks like on your side when someone pushes code.
Who this is for.
If three of these are true, we should talk.
01 / 05
You ship client MVPs and internal tools fast, on Supabase, using Lovable, Bolt, Cursor or Claude.
You’re good at shipping. Nobody on the team is a security person, and you wouldn’t know how to hire one if you wanted to.
No client has ever asked “is this secure?” You know one eventually will.
You’ve run a scanner at some point, it came back clean, and you didn’t entirely believe it.
Losing a client over a security problem would hurt more than the problem itself.
You ship client MVPs and internal tools fast, on Supabase, using Lovable, Bolt, Cursor or Claude.
See if we’re a fit.
Your details are never shared or sold. See our privacy policy.
Questions I get asked.
If yours is not here, the call is the fastest way to get a straight answer.
Generic scanners look for classic vulnerabilities (injection, unsafe eval) that AI-built agency apps rarely contain. They miss the patterns that actually recur on this stack. So I wrote my own rules for those patterns: request data written straight into a database write, a key exposed to the browser, a Stripe webhook that never verifies its signature. On top of that I check your Supabase configuration by hand, which no code scanner can read at all. That’s where the worst issue on this stack lives.
You get a specific fix for every finding, not “this is broken.” A code snippet or a configuration change your team or your AI tool can apply directly. Once you’ve applied them, I re-check at no cost to confirm each one actually resolved the issue.
That’s exactly what the report says: what was checked and what came back clean. I’d rather tell you it’s solid than manufacture findings to justify the fee. The report also includes the findings I reviewed and dismissed, so you can see a person went through it rather than taking my word for the result.
No. The audit stands on its own. The continuous layer is there if you want it once you’re shipping regularly, and it’s a one-time install with no retainer. There’s no requirement to take it, and I won’t chase you for it.
Priced per project by complexity for the audit, a one-time fee for the monitoring install, and a wholesale rate per client roster if you resell it. Never per seat, never per hour. I’ll give you real numbers on the call once I know the shape of the app.
Yes, deliberately. It’s the reason I find what generalists miss. The deepest check I run reads your database policies against your actual data model, and that’s specific to Supabase. If you’re on something else, tell me on the form and I’ll say honestly whether any of it transfers. I’d rather tell you no than guess on a stack I don’t know.