Fortus Fortus
Join waitlist

Your AI built it.
Did it lock the doors?

Fortus reads your vibe-coded app's code and finds the security holes AI tools leave behind. You get a fix-prompt for each one, ready to paste into your AI agent. It never touches your live app.

No spam. One email when your spot opens.

The happy path works. That's the problem.

AI coding tools make the app work. They rarely make it safe. Here's what that looks like the day after launch.

Imagine your Stripe key gets scraped by lunch.

It shipped in your frontend bundle. Bots found it before your first user did.

$1,204.00 ↑

Imagine someone types /admin, and it opens.

The link was hidden. The route wasn't protected.

yourapp.com/admin
Admin panel — no auth check

Imagine a user changes 123 to 124.

Now they're looking at another customer's account.

/orders/123
Your order
Someone else's order

See what attackers see

Frontend keys, source maps, backup files, exposed staging — mapped straight from your repo.

Prove it to buyers

A report you can attach when the enterprise security questionnaire lands.

Fix, don't just find

Every finding ships with a fix-prompt matched to your stack.

No noise

Checks look for "already handled" patterns too, so protected code doesn't get flagged.

The holes AI leaves most often, found in your code.

Leaked secrets

Deleting the file doesn't delete the key. Fortus checks your code and your git history.

Database access

RLS off, or perfect policies bypassed by the wrong key. Either way, your data is open.

Unprotected routes

Hidden is not access control.

Other users' data

Change one ID, see someone else's account. Fortus finds handlers with no ownership check.

Paywall bypass

If only the browser checks, your paywall is a suggestion.

AI bill blowups

An AI endpoint with no rate limit is an open bar tab.

…and more: unverified payment webhooks · missing input validation · exposed source maps · security headers · vulnerable dependencies

What a finding actually looks like

Redacted samples, not mockups.

Critical

Service-role key used in API route bypasses RLS

lib/supabase.ts:14

High

/api/admin/users has no auth check

app/api/admin/users/route.ts:1

Medium

AI completion endpoint has no rate limit

app/api/chat/route.ts:22

Scan. Read. Paste the fix.

01

Point Fortus at your repo.

02

It reads your routes, config, and database policies. Every finding cites the exact file and line.

03

You get a report plus fix-prompts. Paste them into Cursor, Claude Code, Lovable, or whatever built your app.

- const key = "sk-live_51H..."
+ const key = process.env.STRIPE_KEY

We read your code. We never attack your app.

Fortus doesn't send traffic to your site, run your app, or touch production. No surprise bills, no downtime, no risk to your users. Where your protection might live outside the code — like a WAF or a dashboard setting — Fortus says so. It marks those findings "needs review" instead of guessing.

read-only/live traffic

Get the Vibe-Coder Security Checklist

The holes AI tools leave most often, each with a copy-paste fix-prompt for your AI agent. Free — join the waitlist and we'll send it to your inbox.

Leaked secrets
Unprotected routes
Missing ownership checks
Paywall bypass
Unrated AI endpoints

Questions

Does Fortus touch my live site?

No. It only reads code and config files.

What stacks does it support?

At launch: Next.js, Supabase, and Express. More stacks are on the roadmap.

Do I need to be a developer?

No. Every finding is explained in plain language and comes with a fix-prompt your AI agent can apply.

When can I use it?

v0.1 is in development now. Join the waitlist and you'll be first in.

Do I need to give it credentials?

No. Fortus reads your repo — it doesn't need database, hosting, or API credentials to scan.

What about things outside my repo — WAF, DNS, 2FA?

Flagged as "needs review," never a failure. Fortus doesn't guess at settings it can't see.

Ship fast. Ship locked.