Pre-launch security for apps built with coding agents
No fear, no jargon wall. Each guide is one specific exposure that coding agents ship by default, why it matters in plain terms, and how to check for it on your own app before you launch.
The five questions to answer before you put a coding-agent app in front of real customers, and how to check each one yourself.
8 min · Updated 26 Aug 2026
Row Level Security is what stops one customer reading another's rows. Ten checks to run before you launch.
9 min · Updated 26 Aug 2026
Anything in your client bundle is public. Here is how to tell whether a secret key is sitting in yours, and how to fix it.
7 min · Updated 26 Aug 2026
Twelve checks to run on an AI-built app before real customers touch it, in the order that finds the worst things first.
11 min · Updated 28 Aug 2026
Your Firebase config is meant to be public. Security rules are the only control left — here is how to tell whether yours hold.
10 min · Updated 28 Aug 2026
NEXT_PUBLIC_ means public. Here is how to check what yours are carrying, and the order to fix it in if one is a secret.
8 min · Updated 28 Aug 2026
The UI is not the boundary. Here is how to read what your endpoints really send, and why hiding a field in the front end changes nothing.
9 min · Updated 22 Sep 2026
The free Preflight is passive and read-only. It checks your app for exactly the exposures this guide describes and returns a score, a verdict and one finding with its evidence. No signup, no card.