Seaworthy by AISynq

Your AI-built app works. That does not mean it is safe.

Paste your app’s address and get a grade in under a minute. If something is wrong, we tell you what it is in plain words, and we write the fix as a prompt you paste back into the tool that built the app.

Scan my app freeNo account. The grade comes before we ask for anything.

The tool that built your app cannot mark its own homework. Asking Lovable or Cursor whether the code it wrote is secure gets you the same confidence that produced the problem. Seaworthy has never seen your app before and has no reason to like it.

External grade D, score 48 out of 100. Anyone with your address can read your customers table.

Anyone with your address can read your customers table.

48 / 100 · checked 14 of 14 · medium confidence

https://example-app.com

Seaworthy · scanned

What the research says

  • 99%

    of 30,998 live AI-built apps scanned in August 2026 had at least one security finding.

    vibe-eval.com, Vibe Coding Security Monthly, August 2026

  • 57%

    of reachable Supabase-backed apps, 2,096 of 3,680, let anyone read a database table without logging in.

    vibe-eval.com, Vibe Coding Security Monthly, August 2026

  • 1 in 23

    shipped a working secret key in code the public could download.

    vibe-eval.com, Vibe Coding Security Monthly, August 2026

What it costs

The bill arrives before the warning does.

This is what your app sends to every visitor. Anyone can read it.

main.a91f2c.js · downloaded by every browser that opens your site
SUPABASE_URL: "https://yourproject.supabase.co",
STRIPE_SECRET_KEY: "sk_live_EXAMPLE_NOT_A_REAL_KEY",
ANTHROPIC_API_KEY: "sk-ant-EXAMPLE_NOT_A_REAL_KEY",

Two of those three should never have left your server. We find them in one in twenty-three AI-built apps.

vibe-eval.com, Vibe Coding Security Monthly, August 2026

1.5 million

API tokens exposed within 72 hours of one AI-built app launching, along with 35,000 email addresses. The founder had written no code. The cause was a database key in the browser with row level security switched off.

Wiz research on Moltbook, January 2026

These are the four that show up most often in AI-built apps, and none of them announce themselves.

  • Your model key, spent by a stranger

    An AI key sitting in your browser code is a key anyone can copy. They do not attack you. They just use it, at volume, and you find out on the invoice at the end of the month.

  • Your customer table, readable by anyone

    Your app tells every visitor where your database is. If the access rules are off, the address is the whole password. Names, emails, whatever else is in there.

  • Payments you never received

    If the webhook that hears about successful payments does not check the signature, anyone can post a fake one and get the thing they did not buy.

None of these need an attacker looking for you. They need somebody bored with a browser and your address.

Scan my app freeSixty seconds. No account. You see the grade first.

Three steps.

  1. 01

    Paste your address

    We look at your app the way a stranger on the internet would. No login, no code, nothing installed. You get a grade from A to F and one sentence telling you what it means.

  2. 02

    Connect the repository

    For the full audit we read your code and your database settings. Read-only, and the copy of your code is deleted the moment the scan finishes.

  3. 03

    Paste the fix prompt

    You get a prompt written for the tool that built your app. Paste it in, let the tool make the changes, then run the scan again to confirm the grade moved.

The free scan only sees what the public internet sees. It cannot read your code, so it cannot tell you whether a logged-in user can reach another user’s data. That needs the full audit.

What you are actually buying

Software finds it. I explain it. That second part is the product.

Every scanner on the market gives you a list. A list is where most founders stop, because the next question is which of these actually matters for my app, and no tool answers that. So every paid tier here includes time with me, on a call, going through your findings and telling you what to do first.

My consulting rate is [NEEDS REAL NUMBER] an hour. Thirty minutes of it is inside a $149 audit, which is most of what you are paying for.

Twelve years building and shipping production software for DHL, AT&T, DirecTV, Accenture, the Singapore Government and Simons Group. I founded AISynq. I run these myself and I do not send anyone else.

  • A list becomes a decision

    Thirty findings sorted by severity is still thirty things. On the call we agree which three matter for your app this week, and which you can leave.

  • The awkward questions get answered

    Whether your particular setup makes a finding worse or harmless. A scanner cannot know; it has never seen your business.

  • Somebody is accountable

    A tool has a support queue. On Verified, my name is on the letter, which is why the letter is worth handing to an investor.

How this comparesIncluding the two things the cheap scanners do better.

What happens to your code

  • The free scan never touches your code. It reads only what your app already sends to every visitor.
  • For a paid audit we clone the repository, scan it, and delete the copy in the same job, including when the scan fails.
  • We never train anything on your code and we never keep it.
  • Findings and evidence are kept for 90 days, then deleted. Delete your app from Seaworthy and everything goes at once.

Some scanners run entirely on your own machine and never see your code at all. That is genuinely safer, and if it matters more to you than the rest of this page, buy one of those.

What it costs.

  • Audit

    $149

    one-off, per app

    You have one app and you want to know, once, whether it is safe to have users on.

    • All 36 checks, not the 14 the free scan can reach
    • Your code and your database rules, read directly
    • A fix prompt written for the tool that built your app
    • Thirty minutes with Radwan, going through the findings
    • One re-check after you fix it, to confirm the grade moved
    • A PDF you can send to whoever asked

    One app. A second app is a second audit.

    Book the audit
  • Most useful if you are still shipping

    Monitor

    $99

    a month, per app

    You ship every week, and the thing you broke on Tuesday should not wait for a customer to find it.

    • Everything in Audit, every week
    • An email the moment the grade drops
    • An email the moment a new problem appears
    • A badge for your site that shows the current grade
    • Thirty minutes with Radwan each month
    • Cancel from the billing portal, no email required

    Weekly means weekly. Break it on Tuesday and you hear on Sunday.

    Start monitoring
  • Verified

    $499

    one-off, per app

    Somebody is about to ask whether your app is safe: an investor, an enterprise customer, a partner.

    • Everything in Audit
    • Radwan reviews every finding by hand, not just the report
    • A recorded walkthrough you can forward
    • A signed letter naming what was checked and when
    • Sixty minutes with Radwan, not thirty
    • Two re-checks

    The letter says what was checked. It is not a penetration test and it does not claim to be.

    Book Verified

Every paid tier includes thirty minutes with him on a call, going through your findings.

Auditing a portfolio? There is a page for that.