Security check for AI-built apps

AI app builders get you from idea to live app fast, and they wire it straight to a hosted backend. The mistakes that leak user data are the same ones any app can make, and they are easy to miss when you did not write the code yourself.

One ordinary visit to the page you enter — what any browser sees. No scan, nothing stored.

What goes wrong

Apps built with tools like Lovable, Bolt, v0 or Cursor usually talk to a backend such as Supabase or Firebase directly from the browser. HatTest is not affiliated with any of them; it checks the app you shipped, whichever tool built it. The common failures:

  • The database answers anyone. Access rules (Supabase RLS, Firebase Security Rules) that are off or too broad let a stranger read your users' data.
  • A secret key in the frontend. A service_role key, a payment key or an AI API key pasted into client code ships to every visitor.
  • Files that should never be served. A .env file, a .git folder or source maps published along with the site.

For a deeper look at your backend, see the Supabase and Firebase pages.

What HatTest checks

The free scan asks as the anonymous public: what can a stranger read or reach? The deep scan signs in as two test accounts you create in your own app and checks whether one user can reach the other’s data. These are the checks that matter most here; the full catalog runs 156.

  • high Anonymous read exposes sensitive data
  • high Firestore collection is world-readable (open security rules)
  • high Supabase service_role key exposed
  • high Stripe live secret key exposed
  • high OpenAI API key exposed
  • high Anthropic API key exposed
  • high Environment file (.env) publicly served
  • medium Git repository metadata exposed (.git)
  • low Source map exposes original application source
  • high Cloud bucket is world-listable and holds private-looking files
  • high Authenticated user can read another user's sensitive rows Deep scan

What’s free, and what it never does

Running a scan is free (up to 5 a day), and so are the severity scoreboard, the informational findings and your site profile. The negative findings, each with its evidence and a plain-English fix, are a $50 unlock per report.

  • It never runs your code. It looks at what your live app already serves and answers.
  • It only scans a site you have verified you own. The no-signup check above is the exception, and it only reads what any browser sees.
  • It does not write to your data. Every check that would write is switched off on this deployment, marked above.
  • It never tells you a site is “secure.” It reports what it found, and names anything it could not check.

Verifying a site an AI tool hosts for you

To run the full scan you prove you own the site, once. HatTest gives you a meta tag that starts <meta name="hattest-site-verification". It must be in the HTML your homepage actually serves, so add it to the <head> of your index.html through your builder's code view, or ask the builder to add it there. A tag added by JavaScript after the page loads will not be seen. If you use your own domain, a DNS TXT record works instead.

Questions

Do I need to read my app's code to use this?

No. HatTest is black-box: it looks at your live app from the outside, the way any visitor or attacker would. You never share your code, and nothing is installed.

My builder says my app is secure. Why check?

Generated apps work, but access rules and where keys end up depend on prompts and settings that are easy to get wrong. HatTest tests what is actually live, and it never claims a site is secure, only what it found and what it could not check.

What does it cost?

Running a scan is free, and so are the scoreboard and informational findings. The negative findings, each with evidence and a fix, are a one-time unlock per report.

Run the full scan, free