Blog
-
I scanned 652 AI-built apps. My scanner reported 41 serious findings. 12 were real.
Five weeks of passive scanning against AI-built SaaS products, three passes over the same corpus. The reported count went 1, then 3, then 20 without a single app changing, and then hand-checking the findings threw out 60% of them.
-
A $100 scanner and a person who signs off are not the same purchase
Automated pentests for AI-built apps are cheap, fast, and useful. Run them. But a scanner hands you a list and stands behind nothing. Here's the line between what a machine can check and what only a person who's accountable for the result can.
-
What I actually check in your app, and how
A plain walkthrough of the security review I run on apps built with Lovable, Bolt, Cursor and Supabase. The nine things I look at, most dangerous first, what's visible from the outside versus what isn't, and where automated scanners stop and a human has to take over.
-
A field guide to the holes AI leaves in payment sites
AI coding tools build the path where everyone is honest and skip the branch where someone lies. On a site that takes money or files, that branch is a dozen holes — and nearly all of them are the same mistake: trusting what the caller sent.
-
I let an AI agent build a SaaS blind. Here's the cross-tenant leak it shipped.
I had an AI agent conceive, spec, and code a full SaaS with no code review from me — then audited what it shipped. It looked done. It leaked one account's data to another. Here's the experiment and the finding.