Free tools for AI-built apps
You built it with Lovable, Bolt, Cursor, v0, or Replit. It works, real people are using it, and now you want to know it is not leaking user data. These checks are the ones we run first in paid reviews, free and self-serve. No email, no gate.
Schema check, in-browser
Supabase RLS Policy Checker
Paste your schema, see which tables strangers can read. Runs entirely in your browser.
Eight checks against your Row Level Security setup, triaged into blocking, urgent, and can wait, with the corrected SQL for each. Your SQL never leaves the page: no upload, no signup, and you can watch the network tab to confirm.
Check my policies →Live-app scan
Leak Check
Paste your live URL, get a launch-readiness read in about a minute.
This one probes the running app instead of the schema: reachability, SSL, auth flow, payment path, exposed keys in your client bundle, and open Supabase tables. Plain-English green, yellow, or red on each.
Scan my live app →More tools are on the way, roughly one a month, each one a check we already run by hand in paid work.
Found something you do not want to fix alone?
These tools catch the gaps a scan can catch. A Ship Check is the human version: a ranked report on your whole app, every finding with a proof you can re-run. And if you already know something is wrong, skip the queue and talk to us directly.