Your AI built it.
Did it lock the doors?
Fortus reads your vibe-coded app's code and finds the security holes AI tools leave behind. You get a fix-prompt for each one, ready to paste into your AI agent. It never touches your live app.
No spam. One email when your spot opens.
The happy path works. That's the problem.
AI coding tools make the app work. They rarely make it safe. Here's what that looks like the day after launch.
Imagine your Stripe key gets scraped by lunch.
It shipped in your frontend bundle. Bots found it before your first user did.
Imagine someone types /admin, and it opens.
The link was hidden. The route wasn't protected.
Imagine a user changes 123 to 124.
Now they're looking at another customer's account.
See what attackers see
Frontend keys, source maps, backup files, exposed staging — mapped straight from your repo.
Prove it to buyers
A report you can attach when the enterprise security questionnaire lands.
Fix, don't just find
Every finding ships with a fix-prompt matched to your stack.
No noise
Checks look for "already handled" patterns too, so protected code doesn't get flagged.
The holes AI leaves most often, found in your code.
Leaked secrets
Deleting the file doesn't delete the key. Fortus checks your code and your git history.
Database access
RLS off, or perfect policies bypassed by the wrong key. Either way, your data is open.
Unprotected routes
Hidden is not access control.
Other users' data
Change one ID, see someone else's account. Fortus finds handlers with no ownership check.
Paywall bypass
If only the browser checks, your paywall is a suggestion.
AI bill blowups
An AI endpoint with no rate limit is an open bar tab.
…and more: unverified payment webhooks · missing input validation · exposed source maps · security headers · vulnerable dependencies
What a finding actually looks like
Redacted samples, not mockups.
Service-role key used in API route bypasses RLS
lib/supabase.ts:14
/api/admin/users has no auth check
app/api/admin/users/route.ts:1
AI completion endpoint has no rate limit
app/api/chat/route.ts:22
Scan. Read. Paste the fix.
Point Fortus at your repo.
It reads your routes, config, and database policies. Every finding cites the exact file and line.
You get a report plus fix-prompts. Paste them into Cursor, Claude Code, Lovable, or whatever built your app.
We read your code. We never attack your app.
Fortus doesn't send traffic to your site, run your app, or touch production. No surprise bills, no downtime, no risk to your users. Where your protection might live outside the code — like a WAF or a dashboard setting — Fortus says so. It marks those findings "needs review" instead of guessing.
Get the Vibe-Coder Security Checklist
The holes AI tools leave most often, each with a copy-paste fix-prompt for your AI agent. Free — join the waitlist and we'll send it to your inbox.
Questions
Does Fortus touch my live site?
No. It only reads code and config files.
What stacks does it support?
At launch: Next.js, Supabase, and Express. More stacks are on the roadmap.
Do I need to be a developer?
No. Every finding is explained in plain language and comes with a fix-prompt your AI agent can apply.
When can I use it?
v0.1 is in development now. Join the waitlist and you'll be first in.
Do I need to give it credentials?
No. Fortus reads your repo — it doesn't need database, hosting, or API credentials to scan.
What about things outside my repo — WAF, DNS, 2FA?
Flagged as "needs review," never a failure. Fortus doesn't guess at settings it can't see.
From the Fortus Blog
Practical security guides for builders shipping with AI.
Paste Your Own URL Into a Scanner Before Launch
Bots probe for missing HTTPS, weak headers, and exposed backups first. Run a 60-second self-review before attackers do.
Read →Change the User ID in Your API Request
Change one ID in your API request and you may see another user's data. The most common vibe-code bug, explained.
Read →Search Your Own Bundle for sk- Before Someone Else Does
Your Stripe or OpenAI key may be sitting in client JavaScript. How to find it in 60 seconds.
Read →Supabase RLS Was Off and Anyone Could Read Everything
With Row Level Security off, any logged-in user can read every row. Learn where RLS lives in migrations.
Read →My Users Found My Source in Their Browser
Shipping .map files or unminified bundles leaks your source to anyone with DevTools. Fix it in five minutes.
Read →