Fortus Publication

Fortus Blog

Security for AI-Built Software. Practical guides, 60-second self-reviews, and fix-prompts for builders shipping with Cursor, Claude Code, Lovable, and v0.

Pre-Launch • 4 min read

Paste Your Own URL Into a Scanner Before Launch

Picture this: the night before launch, you finally type your own app's address into someone else's tool — a free header checker, a TLS grader, a backup-file probe — and watch it list problems you have lived with for months.

Transport & Headers Read →
Access Control • 5 min read

Change the User ID in Your API Request: Finding IDOR Before Users Do

Here is the shortest security test in web development: log in, open your own data, change the ID in the request, and see what comes back. Picture this: your orders live at an endpoint with your user number in the path.

Authorization Read →
Secret Leaks • 4 min read

Search Your Own Bundle for sk- Before Someone Else Does

Imagine you ship on a Friday afternoon. The AI assistant wired the checkout and the chat feature straight from the frontend because that was the simplest working architecture, and everything works.

API Security Read →
Database Security • 5 min read

Supabase RLS Was Off and Anyone Could Read Everything

Picture this: you launch on Supabase, auth works, your dashboard shows your own data, and you ship. Then imagine a curious user opens DevTools, queries the same table directly with their own authenticated session...

Postgres & RLS Read →
Build & Deploy • 5 min read

My Users Found My Source in Their Browser: Fixing Exposed Source Maps

Imagine shipping your app, getting a friendly message from a user, and realizing they are reading your original source code in their browser. Not the minified bundle — the real thing, with component logic, route structure, and comments intact.

Bundlers & Production Read →

Ship fast. Ship locked.

Fortus reads your repo and catches the security holes AI builders leave behind — with copy-paste fix-prompts for your AI agent.