Fortus Blog
Security for AI-Built Software. Practical guides, 60-second self-reviews, and fix-prompts for builders shipping with Cursor, Claude Code, Lovable, and v0.
Paste Your Own URL Into a Scanner Before Launch
Picture this: the night before launch, you finally type your own app's address into someone else's tool — a free header checker, a TLS grader, a backup-file probe — and watch it list problems you have lived with for months.
Change the User ID in Your API Request: Finding IDOR Before Users Do
Here is the shortest security test in web development: log in, open your own data, change the ID in the request, and see what comes back. Picture this: your orders live at an endpoint with your user number in the path.
Search Your Own Bundle for sk- Before Someone Else Does
Imagine you ship on a Friday afternoon. The AI assistant wired the checkout and the chat feature straight from the frontend because that was the simplest working architecture, and everything works.
Supabase RLS Was Off and Anyone Could Read Everything
Picture this: you launch on Supabase, auth works, your dashboard shows your own data, and you ship. Then imagine a curious user opens DevTools, queries the same table directly with their own authenticated session...
My Users Found My Source in Their Browser: Fixing Exposed Source Maps
Imagine shipping your app, getting a friendly message from a user, and realizing they are reading your original source code in their browser. Not the minified bundle — the real thing, with component logic, route structure, and comments intact.
Ship fast. Ship locked.
Fortus reads your repo and catches the security holes AI builders leave behind — with copy-paste fix-prompts for your AI agent.