Waitlist open ยท 0%

Find the 12 security holes Cursor, Lovable, v0, and Bolt leave open by default. Paste your URL, get a report your investor will not flag.

Public-surface security scan of your AI-built SaaS. Twelve vibecode-default holes, stack-aware patches, investor-ready PDF.

0of 5 on waitlist

Bring a friend who'd use this. Each signup pulls the launch closer.

See it live

$4.99 lifetime ยท or $19 / month SaaS ยท no charge today

๐ŸŒ Web toolยทdev tools

Built by someone who already shipped 30+ tools

30+
tools shipped
2,300
weekly Google impressions
35d
day-by-day streak
12
ranked in top-10

For a sense of what shipped looks like: relly.permissionlabs.com โ†—

What it does

Twelve holes ship by default. Find yours before the buyer does.

Click any card to jump to its deep dive below.

Who it's for

Built for these decisions.

If any of these are your question, this is the tool.

Solo founder who built with Cursor

What did the agent leave open when it wired Supabase auth?

โ†’ Twelve-row scorecard with the RLS schema gaps, the service-role key check, and the CORS rule. Patch SQL inline.

Indie hacker on Lovable, v0, or Bolt

Is my Stripe webhook actually verifying signatures?

โ†’ Live POST test against your webhook endpoint with a forged signature. Pass or fail with the verification snippet to drop in.

Founder before a VC due-diligence call

What will the partner's security advisor flag in week one?

โ†’ PDF with the twelve categories. Every red row carries the patch. Hand it over before they ask.

Side project gaining first paying users

Did I leak any service-role keys when I deployed?

โ†’ Public bundle grep for service-role patterns, NEXT_PUBLIC misuse, leaked env keys. Each hit links to the file and the line.

The problem

AI coding tools optimize for a working demo. Production is your job.

Pentesters who audit AI-built SaaS see the same 12 holes repeat across every stack. Supabase RLS off on the public schema. Stripe webhook signature not verified. The session token written to localStorage instead of an HttpOnly cookie. Service-role keys baked into the client bundle. CORS Access-Control-Allow-Origin set to a wildcard. Open redirect on the auth callback. The reason is structural: AI coding tools optimize for a working demo, not a hardened production deploy, and they almost never flag the missing rule. The user sees green checkmarks and goes live. The first paying buyer or the partner's security advisor or the first scraper finds the hole in week two. The cost is not the audit fee. It is the silent leak you do not know about for six months.

What you'd get

Four pieces, one tool.

Each piece ships in the first build for waitlist members. SaaS upgrades layer on top.

01 ยท feature

Twelve vibecode-default categories scanned

Supabase RLS coverage, Stripe webhook verification, service-role key exposure, environment variable leaks, CORS wildcards, OAuth callback open redirect, JWT storage, CSRF protection, rate limits, error message disclosure, dependency typosquats, build artefact secrets. Each row comes with a pass or fail and a one-line reason.

Trust signal scorecard
47
  • Real founder photo
  • Real testimonials with photos
  • OKSpecific metrics with units
  • Custom typography
  • OKCustom design tokens
  • Social proof above the fold
  • OKFooter with company details
02 ยท feature

Live test on your live URL

We send the requests an attacker sends. Forged Stripe webhook, anonymous Supabase query against a protected table, unauthenticated POST to admin routes, redirect probe on the auth callback. Real-traffic test, not a static lint pass.

Pre-bill alert
โฐ
Cursor Pro renews in 3 days
$20/mo ยท last used 2 days ago
โš ๏ธ
Midjourney renews in 3 days
$30/mo ยท last used 41 days ago
03 ยท feature

Fix patches sized to your stack

Detected Next.js 15 app router and Supabase: you get the route.ts diff and the policy SQL. Detected Hono on Cloudflare Workers: you get the middleware snippet. Each patch is small enough to paste, not a thirty-page playbook.

AI subscriptions detected
  • Cursor Pro
    $20/mo
  • Claude Pro
    $20/mo
  • GPT Plus
    $20/mo
  • Midjourney Standard
    $30/mo
  • GitHub Copilot
    $10/mo
  • Perplexity Pro
    $20/mo
  • ElevenLabs Creatortrial
    $22/mo
  • Replicate
    $25/mo
Monthly total$167
04 ยท feature

One-page investor-ready PDF

Twelve rows, pass or fail, last scan date, framework detected, scan hash. Hand it to a VC partner or attach it to your enterprise buyer's security questionnaire response. Re-runs on every deploy you connect.

Saved scenarios
  • Default plan
    Survives 40y
  • 2008 stress
    Year 17
  • Aggressive draw
    Year 11
  • Conservative
    Survives 40y
  • + Save current scenarioSaaS
Why paid

Today's tools don't do this.

A VC partner's security advisor finds an exposed service-role key in week two of due diligence. The contract delays a month, the founder spends a weekend rewriting auth and rotating keys, $0 to $200K of pipeline depending on the deal. A first enterprise buyer asks for a one-page security summary the founder cannot produce.

โœ—Generic OWASP dependency scan. No AI-builder pattern set, no live URL test, no Supabase RLS check, no Stripe webhook forge.
Their pricing
โœ—Code-side static analysis only. Will not catch a live CORS wildcard, a runtime service-role leak, or a Stripe webhook that accepts forged signatures.
Their pricing
โœ—Capable scanner, steep learning curve. No AI-builder default rule set, no patch suggestions sized to Next, Hono, Supabase, or Stripe.
Their pricing
Pentest agency engagement
โœ—Accurate, often two to four weeks of lead time, $5K to $25K per engagement. Final report lands after your VC call already happened.
Their pricing
Vibecode Audit
โœ“Pattern set tuned to AI builders ยท Live-surface test, not static lint ยท Stack-aware patches that paste in ยท One-page deliverable for the buyer or partner
$4.99
Price anchor
Compared to
Senior dev contractor security review, 1 hour
Their price
$100~200 / hour
What you get
Same twelve-category audit, same patch suggestions, $4.99 once, re-runs on every deploy you connect.
โœ“
What you get now

Twelve-category scan on your live URL, framework auto-detection, fix patches per stack, one-page PDF, downloadable scan hash for the buyer or partner.

โ†—
What's coming

Deploy-hook webhook so the scan re-runs on every push. CI integration. Custom rule packs for niche stacks. Multi-project dashboard. SaaS upgrade tier ($19/month).

ยท
What's not included

Full source-code review, on-call incident response, certified penetration test report for SOC 2 or ISO 27001 evidence. For those, retain a security firm.

Pricing

Which price would get you on the waitlist?

No charge today. The click tells me which tier is real demand. Early access price โ‰  launch price.

Join the waitlist

Want this built?

Drop your email. No charge, no spam. You're saying "yes, I'd actually use this." That's the signal I'm looking for.

Hi, I'm Hyunyoung.

Solo builder ยท Choppy Toast

This page is a quick vibe-coded probe to test demand and gather feature requests. The actual product, when it ships, will be a polished, hand-built tool, not this scaffold.

For a sense of what "polished and shipped" looks like, here's another product I built: relly.permissionlabs.com.

FAQ

Honest answers.

Then I wait. The waitlist stays live forever, no expiry, no archive. The faster you bring a friend who built their app with Cursor or Lovable, the faster I build it. That is the whole engine.

More

More upcoming tools.

๐Ÿงฉ

Extension Listing Kit

SaaS

Upload each screenshot, promo tile, and description once. We resize and crop every image to the exact spec the Chrome Web Store, Firefox Add-ons, and Edge Add-ons each ask for, hold one copy of your name, summary, and description per store and per language with the character limit checked as you type, and run a pre-submit pass that names every missing or out-of-spec asset before you hit publish.

Waitlist 0%Waitlist open
๐ŸŽฌ

Video Bloat Audit

Web tool

Paste a URL. We find every autoplay and background video on the rendered page, show the real transfer weight and how much each one adds to your largest paint, estimate the monthly bandwidth bill at your actual traffic, and hand you a ranked plan to swap each clip for a poster, a lazy load, a smaller encode, or a scripted animation.

Waitlist 0%Waitlist open
๐Ÿ“‰

Decompound Calc

Web tool

See exactly when your retirement money runs out.

Waitlist 0%Waitlist open
๐Ÿ’ธ

AI Stack Cost

SaaS dashboard

One dashboard for every AI subscription you forgot about.

Waitlist 0%Waitlist open
๐Ÿ”

Vibe Check

Web tool

Find every AI-generated tell on your landing page.

Waitlist 0%Waitlist open
๐Ÿฆ

Account Stack 2026

Web tool

Tell us your income. We tell you exactly where to put each dollar across 401k, Roth IRA, HSA, and backdoor.

Waitlist 0%Waitlist open
๐Ÿ›ก๏ธ

Ad Precheck

Web tool

Paste your ad copy, image, and landing URL. Get a per-platform rejection score for Meta, Google Ads, and AdSense before you submit.

Waitlist 0%Waitlist open
๐Ÿ”ฌ

Silent AI Audit

Mac app

Find every AI model silently installed on your Mac. See the size, last access, and how to remove each one.

Waitlist 0%Waitlist open
โšก

EV Power Bill

Web tool

See your real EV charging bill before you buy the car.

Waitlist 0%Waitlist open
๐Ÿชค

Before You Install

Web tool

Paste a package. See the supply-chain risk before you run install.

Waitlist 0%Waitlist open
๐Ÿงฎ

LLM Self-host Cost

Web tool

See if self-hosting an LLM actually beats the API bill.

Waitlist 0%Waitlist open
๐ŸŽ

App Store Precheck

Web tool

Paste your app metadata, screenshots, and Info.plist. Get a per-guideline rejection score before you hit Submit for Review.

Waitlist 0%Waitlist open
๐Ÿ›๏ธ

UK Stamp Duty Surcharge

Web tool

Stack the non-resident surcharge, additional property, and first-time buyer relief in one calculator. See your real SDLT before you exchange.

Waitlist 0%Waitlist open
๐ŸŒถ๏ธ

Spice Graveyard

iOS app

Scan the spice rack once. Get told what to cook tonight with the bottles you already own, and stop buying duplicates.

Waitlist 0%Waitlist open
๐Ÿ 

Home Addition Cost

Web tool

Paste a contractor bid for your home addition. Get a line-by-line read on what is fair, what is padded, and what scope cut drops the total without losing the room.

Waitlist 0%Waitlist open
๐Ÿ’Š

Accutane Tracker

iOS app

Log your Accutane course like the dermatologist would. Daily lip dryness, side-effect severity, dose ladder, blood-draw reminders, and a photo timeline that shows where week 12 actually got you.

Waitlist 0%Waitlist open
๐Ÿงด

PIH Fade Plan

Web tool

Tell us your skin type, breakout history, and how much post-acne brown is left. Get a 16-week active routine that switches between azelaic, niacinamide, vitamin C, and tretinoin based on how your skin actually reacts in week 2, 4, 8, and 12.

Waitlist 0%Waitlist open
๐Ÿงน

Tailwind Exit Plan

Web tool

Paste a Tailwind component or a repo URL. Get a structured CSS migration plan that pulls out reusable classes, scaffolds CSS modules with design tokens, and hands the team a 4-week refactor schedule with the file to open on Monday.

Waitlist 0%Waitlist open
๐Ÿ–ฅ๏ธ

VMware Exit Plan

Web tool

Paste your VMware renewal quote, host counts, and license SKUs. Get a per-hypervisor cost split across Proxmox, Hyper-V, OpenShift, and Nutanix, the migration hour estimate, and a 90-day cutover schedule that names the cluster to drain first.

Waitlist 0%Waitlist open
๐Ÿ‘ถ

Child Investment Planner

Web tool

Type your kid's age, your monthly budget, and your tax bracket. Get a side-by-side projection for 529, UTMA, and Roth IRA at age 18, the contribution that fits your budget, and the one-page memo that names the account to open first.

Waitlist 0%Waitlist open
๐Ÿšช

RMM Escape Plan

Web tool

Paste your NinjaOne invoice, endpoint count, and add-on list. Get your real all-in per-endpoint cost, a dated cancellation letter that respects the 60-day notice clock, and a migration matrix scored to your size across Action1, Level.io, Endpoint Central, and Syncro.

Waitlist 0%Waitlist open
๐Ÿฆ

Bank Freeze Exit Plan

Web tool

Type your monthly cash flow, your balance range, and your current business bank. Get a freeze-risk score for every provider, the morning-of runbook if your account locks, a named backup account at a second institution, and a one-page memo for your bookkeeper.

Waitlist 0%Waitlist open
๐Ÿ”Œ

Host Lock-In Escape

Web tool

Paste your host, plan tier, and what you deploy. Get a lock-in risk score across Netlify, Vercel, Render, Fly.io, and Cloudflare Pages, a redeploy config built from your own env vars and redirects, and a one-page runbook for the morning your account gets suspended with the site still live.

Waitlist 0%Waitlist open
๐Ÿ“‹

After-Death Money Checklist

Web tool

Tell us the state and the rough size of the estate. Get whether you can skip full probate, which bills you actually have to pay and which die with the person, the order to notify the banks and the agencies, and a one-page memo for the family.

Waitlist 0%Waitlist open
๐ŸŒก๏ธ

Heat Safety Planner

Web tool

Tell us who is going outside, what they are doing, and your zip code. Get a clear go, modify, or cancel call for today's heat, the work-rest and water schedule for those conditions, the early heat-illness signs to watch in that specific person, and the safe hours to move it to.

Waitlist 0%Waitlist open

5 more on the waitlist and I build this.

No charge today. Drop your email, lock in the early-access price, and you hear first when it ships.

Email me directly

Built by a real person. No silent vaporware.