Find the 12 security holes Cursor, Lovable, v0, and Bolt leave open by default. Paste your URL, get a report your investor will not flag.
Public-surface security scan of your AI-built SaaS. Twelve vibecode-default holes, stack-aware patches, investor-ready PDF.
Bring a friend who'd use this. Each signup pulls the launch closer.
$4.99 lifetime ยท or $19 / month SaaS ยท no charge today
Built by someone who already shipped 30+ tools
For a sense of what shipped looks like: relly.permissionlabs.com โ
Twelve holes ship by default. Find yours before the buyer does.
Click any card to jump to its deep dive below.
Built for these decisions.
If any of these are your question, this is the tool.
What did the agent leave open when it wired Supabase auth?
โ Twelve-row scorecard with the RLS schema gaps, the service-role key check, and the CORS rule. Patch SQL inline.
Is my Stripe webhook actually verifying signatures?
โ Live POST test against your webhook endpoint with a forged signature. Pass or fail with the verification snippet to drop in.
What will the partner's security advisor flag in week one?
โ PDF with the twelve categories. Every red row carries the patch. Hand it over before they ask.
Did I leak any service-role keys when I deployed?
โ Public bundle grep for service-role patterns, NEXT_PUBLIC misuse, leaked env keys. Each hit links to the file and the line.
AI coding tools optimize for a working demo. Production is your job.
Pentesters who audit AI-built SaaS see the same 12 holes repeat across every stack. Supabase RLS off on the public schema. Stripe webhook signature not verified. The session token written to localStorage instead of an HttpOnly cookie. Service-role keys baked into the client bundle. CORS Access-Control-Allow-Origin set to a wildcard. Open redirect on the auth callback. The reason is structural: AI coding tools optimize for a working demo, not a hardened production deploy, and they almost never flag the missing rule. The user sees green checkmarks and goes live. The first paying buyer or the partner's security advisor or the first scraper finds the hole in week two. The cost is not the audit fee. It is the silent leak you do not know about for six months.
Four pieces, one tool.
Each piece ships in the first build for waitlist members. SaaS upgrades layer on top.
Twelve vibecode-default categories scanned
Supabase RLS coverage, Stripe webhook verification, service-role key exposure, environment variable leaks, CORS wildcards, OAuth callback open redirect, JWT storage, CSRF protection, rate limits, error message disclosure, dependency typosquats, build artefact secrets. Each row comes with a pass or fail and a one-line reason.
- Real founder photo
- Real testimonials with photos
- OKSpecific metrics with units
- Custom typography
- OKCustom design tokens
- Social proof above the fold
- OKFooter with company details
Live test on your live URL
We send the requests an attacker sends. Forged Stripe webhook, anonymous Supabase query against a protected table, unauthenticated POST to admin routes, redirect probe on the auth callback. Real-traffic test, not a static lint pass.
Fix patches sized to your stack
Detected Next.js 15 app router and Supabase: you get the route.ts diff and the policy SQL. Detected Hono on Cloudflare Workers: you get the middleware snippet. Each patch is small enough to paste, not a thirty-page playbook.
- Cursor Pro$20/mo
- Claude Pro$20/mo
- GPT Plus$20/mo
- Midjourney Standard$30/mo
- GitHub Copilot$10/mo
- Perplexity Pro$20/mo
- ElevenLabs Creatortrial$22/mo
- Replicate$25/mo
One-page investor-ready PDF
Twelve rows, pass or fail, last scan date, framework detected, scan hash. Hand it to a VC partner or attach it to your enterprise buyer's security questionnaire response. Re-runs on every deploy you connect.
- Default planSurvives 40y
- 2008 stressYear 17
- Aggressive drawYear 11
- ConservativeSurvives 40y
- + Save current scenarioSaaS
Today's tools don't do this.
A VC partner's security advisor finds an exposed service-role key in week two of due diligence. The contract delays a month, the founder spends a weekend rewriting auth and rotating keys, $0 to $200K of pipeline depending on the deal. A first enterprise buyer asks for a one-page security summary the founder cannot produce.
Twelve-category scan on your live URL, framework auto-detection, fix patches per stack, one-page PDF, downloadable scan hash for the buyer or partner.
Deploy-hook webhook so the scan re-runs on every push. CI integration. Custom rule packs for niche stacks. Multi-project dashboard. SaaS upgrade tier ($19/month).
Full source-code review, on-call incident response, certified penetration test report for SOC 2 or ISO 27001 evidence. For those, retain a security firm.
Which price would get you on the waitlist?
No charge today. The click tells me which tier is real demand. Early access price โ launch price.
Want this built?
Drop your email. No charge, no spam. You're saying "yes, I'd actually use this." That's the signal I'm looking for.
Hi, I'm Hyunyoung.
Solo builder ยท Choppy Toast
This page is a quick vibe-coded probe to test demand and gather feature requests. The actual product, when it ships, will be a polished, hand-built tool, not this scaffold.
For a sense of what "polished and shipped" looks like, here's another product I built: relly.permissionlabs.com.
Honest answers.
Then I wait. The waitlist stays live forever, no expiry, no archive. The faster you bring a friend who built their app with Cursor or Lovable, the faster I build it. That is the whole engine.
More upcoming tools.
Extension Listing Kit
SaaS
Upload each screenshot, promo tile, and description once. We resize and crop every image to the exact spec the Chrome Web Store, Firefox Add-ons, and Edge Add-ons each ask for, hold one copy of your name, summary, and description per store and per language with the character limit checked as you type, and run a pre-submit pass that names every missing or out-of-spec asset before you hit publish.
Video Bloat Audit
Web tool
Paste a URL. We find every autoplay and background video on the rendered page, show the real transfer weight and how much each one adds to your largest paint, estimate the monthly bandwidth bill at your actual traffic, and hand you a ranked plan to swap each clip for a poster, a lazy load, a smaller encode, or a scripted animation.
Decompound Calc
Web tool
See exactly when your retirement money runs out.
AI Stack Cost
SaaS dashboard
One dashboard for every AI subscription you forgot about.
Vibe Check
Web tool
Find every AI-generated tell on your landing page.
Account Stack 2026
Web tool
Tell us your income. We tell you exactly where to put each dollar across 401k, Roth IRA, HSA, and backdoor.
Ad Precheck
Web tool
Paste your ad copy, image, and landing URL. Get a per-platform rejection score for Meta, Google Ads, and AdSense before you submit.
Silent AI Audit
Mac app
Find every AI model silently installed on your Mac. See the size, last access, and how to remove each one.
EV Power Bill
Web tool
See your real EV charging bill before you buy the car.
Before You Install
Web tool
Paste a package. See the supply-chain risk before you run install.
LLM Self-host Cost
Web tool
See if self-hosting an LLM actually beats the API bill.
App Store Precheck
Web tool
Paste your app metadata, screenshots, and Info.plist. Get a per-guideline rejection score before you hit Submit for Review.
UK Stamp Duty Surcharge
Web tool
Stack the non-resident surcharge, additional property, and first-time buyer relief in one calculator. See your real SDLT before you exchange.
Spice Graveyard
iOS app
Scan the spice rack once. Get told what to cook tonight with the bottles you already own, and stop buying duplicates.
Home Addition Cost
Web tool
Paste a contractor bid for your home addition. Get a line-by-line read on what is fair, what is padded, and what scope cut drops the total without losing the room.
Accutane Tracker
iOS app
Log your Accutane course like the dermatologist would. Daily lip dryness, side-effect severity, dose ladder, blood-draw reminders, and a photo timeline that shows where week 12 actually got you.
PIH Fade Plan
Web tool
Tell us your skin type, breakout history, and how much post-acne brown is left. Get a 16-week active routine that switches between azelaic, niacinamide, vitamin C, and tretinoin based on how your skin actually reacts in week 2, 4, 8, and 12.
Tailwind Exit Plan
Web tool
Paste a Tailwind component or a repo URL. Get a structured CSS migration plan that pulls out reusable classes, scaffolds CSS modules with design tokens, and hands the team a 4-week refactor schedule with the file to open on Monday.
VMware Exit Plan
Web tool
Paste your VMware renewal quote, host counts, and license SKUs. Get a per-hypervisor cost split across Proxmox, Hyper-V, OpenShift, and Nutanix, the migration hour estimate, and a 90-day cutover schedule that names the cluster to drain first.
Child Investment Planner
Web tool
Type your kid's age, your monthly budget, and your tax bracket. Get a side-by-side projection for 529, UTMA, and Roth IRA at age 18, the contribution that fits your budget, and the one-page memo that names the account to open first.
RMM Escape Plan
Web tool
Paste your NinjaOne invoice, endpoint count, and add-on list. Get your real all-in per-endpoint cost, a dated cancellation letter that respects the 60-day notice clock, and a migration matrix scored to your size across Action1, Level.io, Endpoint Central, and Syncro.
Bank Freeze Exit Plan
Web tool
Type your monthly cash flow, your balance range, and your current business bank. Get a freeze-risk score for every provider, the morning-of runbook if your account locks, a named backup account at a second institution, and a one-page memo for your bookkeeper.
Host Lock-In Escape
Web tool
Paste your host, plan tier, and what you deploy. Get a lock-in risk score across Netlify, Vercel, Render, Fly.io, and Cloudflare Pages, a redeploy config built from your own env vars and redirects, and a one-page runbook for the morning your account gets suspended with the site still live.
After-Death Money Checklist
Web tool
Tell us the state and the rough size of the estate. Get whether you can skip full probate, which bills you actually have to pay and which die with the person, the order to notify the banks and the agencies, and a one-page memo for the family.
Heat Safety Planner
Web tool
Tell us who is going outside, what they are doing, and your zip code. Get a clear go, modify, or cancel call for today's heat, the work-rest and water schedule for those conditions, the early heat-illness signs to watch in that specific person, and the safe hours to move it to.
5 more on the waitlist and I build this.
No charge today. Drop your email, lock in the early-access price, and you hear first when it ships.
Built by a real person. No silent vaporware.
