Deterministic proof,
not a warning.

Find out whether strangers can read or change your customers' data. In plain language, with the evidence and a fix you can paste into your AI builder.

Free passive scan, no signup. Active scans only run after you confirm you own the site.

your-app.lovable.app
Example report
1 issue needs action
Leak
  • Table profiles is readable without logging inExpected: owner only · a stranger read 214 rows · evidence attached
    Leak
  • Table orders could not be testedPolicy needs a signed-in user · define an access model
    Unverified
  • HTTPS and HSTS are set correctlyTLS 1.3 · certificate valid 71 days
    Safe
  • No secrets detected in the JavaScript bundle14 files checked
    Safe
Fix it with AI

Enable row level security on profiles and add a policy so users can only select their own row…

Illustrative report. Not real customer data.

Built for apps made with

  • Lovable
  • Bolt
  • v0
  • Replit
  • Base44
  • Cursor
  • Supabase
  • Vercel

Plain-text names, no endorsement implied. The one-prompt connector is verified on Lovable; support on other builders varies.

Start free.
Prove the rest.

Paste a live URL. No account. The passive scan reads what your site shows the world: headers, TLS, DNS, files, the JavaScript bundle and your Supabase setup. You get a plain-language report, a PDF and fix prompts.

Start a free scan
Included freeLive

Passive scan, plain-language report, PDF export, "Fix it with AI" prompts.

After you authorizeOwner only

Thorough active scans (nuclei, nmap, ZAP) run only on sites you confirm you own.

In testingTesting

Dashboard with connected builders, checks about every 30 minutes and alerts.

Paid plans aren't set yet. The URL scan is free.

URL scanner

Scan a site
Security headersExample
P0Content-Security-PolicyMissing
P0Strict-Transport-SecuritySet
P1Referrer-PolicySet
Don't setX-XSS-ProtectionRemove

Headers, TLS and DNS

Security headers checked against a prioritised checklist, plus HTTPS, certificates, SPF and DMARC.

Exposed in the browserExample
/assets/index-4f2a.js
const supabase = createClient(
  "https://xyzcompany.supabase.co",
  "eyJhbGciOiJIUzI1…" // anon key
)
/.env → 200 OK, file is public

Secrets, files and vulnerable libraries

Finds secrets in your client bundle and publicly reachable files (a public Supabase anon key is normal; your access policies decide what it can read), plus known-vulnerable JavaScript libraries, trackers and AI-crawler access.

Fix it with AIExample
Add a Content-Security-Policy header to this app that allows scripts only from the same origin…
PDF report

Plain language, then the fix

Every finding says what it means for your users. Copy a prompt into your builder; you stay in control of the change.

Supabase leak proof

Not a guess from a checklist. SafetyVibe tests access against the rules you define and reports one of three verdicts, each with the evidence.

0
Safe

No stranger access found

The tested reads and writes matched your rules. The verdict covers the tested scope, nothing more.

1
Leak

Someone can read or change data

A test demonstrated access a stranger shouldn't have. You get the request that proved it, and the fix.

2
Could not verify

The proof didn't finish

Something blocked the test. The report says what, so a missing result never looks like a pass.

In your AI workflow

MCP serverExample
{
  "mcpServers": {
    "safetyvibe": {
      "url": "https://mcp.safetyvibe.eu/mcp"
    }
  }
}
get_security_rulesdefine_access_modelrun_access_testsscan_site

Give your coding agent security tools

Point Claude Code, Cursor or another MCP client at our server. Your agent can define access rules, run the tests and scan sites.

One-prompt connectorExample
$ bun add safetyvibe-connect
$ bunx safetyvibe-connect setup --claim-token ••••••
✓ 678 packages reported · Supabase project linked
✓ Connected. Checks re-run after every install.

Paste one prompt into your builder

Your builder's AI installs the safetyvibe-connect npm package. It sends the dependency list and, if used, your public Supabase URL and anon key, never source code or secrets. Dependencies are checked against OSV.dev.

Dashboard TestingExample
shop-demoLovable1 leak
booking-appBoltSafe
crm-mvpv0Unverified
Next check in 24 min

Every app in one place

Connect builders from a catalog of 30, get checks about every 30 minutes and an alert when something changes. Currently in testing.

Start with a free site scan.

See your findings in plain language, and what to fix next.

Scan your site free