Skip to content

Everything we know, written down.

Written for founders who ship with AI tools and would rather not become security engineers. No gated PDFs, no email wall, no account. Including one checklist that will save you money by making a check unnecessary.

Where to start.

Four of these five pages will not sell you anything. That is deliberate: most of what puts an AI-built app at risk is testable by hand in an afternoon, and you should do that first.

If you are about to launch, open the pre-launch checklist and work down it. Twenty checks, roughly three and a half hours, free, and no account. The first two items — whether your database can be read from the browser, and whether one account can fetch another's records — account for most of the serious findings we see in AI-built products.

If you are not convinced this is a real problem, the risks page collects the published numbers with their sources: how often models pick the insecure route, how many live AI-built apps carry a flaw, and what a breach costs on average. No claims of ours, only third-party research you can check.

If you are deciding what to buy, the comparison with a penetration test is the honest version, including the two rows where an automated check is the wrong answer and you should commission a human instead.

If you want to know exactly what we test, the coverage page lists all 14 areas and every probe inside them, plus what is deliberately out of scope. The definition page is the shorter route if you would rather read what a security check is before reading what ours does.

Or skip the reading.

Point a check at your live app and have the answer in a couple of hours, from €59.

Check my app