Exposed API keys
Stripe, OpenAI, Anthropic, and service_role JWTs leaked in JavaScript bundles.
Live security scan · AI-built apps
Paste your live URL. We probe exposed keys, Supabase gaps, weak headers, and public files the way an attacker would. Every finding ships with a fix prompt for Cursor or Lovable.
$ noetfield-scan --target your-app.com Waiting for URL…
Scan complete
Need a human team to fix and ship securely?
Request Studio security reviewWhat we catch
We test the failure modes that show up again and again on AI-generated MVPs.
Stripe, OpenAI, Anthropic, and service_role JWTs leaked in JavaScript bundles.
REST endpoints and RLS gaps that let anonymous clients read or write data.
Missing CSP, HSTS, X-Frame-Options, and other transport protections.
Wildcard origins on endpoints that should be locked to your domain.
Public .env, .git, package.json, and config files reachable from the internet.
HTTP-only deploys and missing hardening on cookies and TLS.
How it works
We only need the address your customers already use. No repo access.
Headers, bundles, Supabase hosts, and common exposed paths. Read-only GET requests.
Each finding includes a prompt you paste into Cursor, Claude, or Lovable.
Vibe coding security
Noetfield Scan is a vibe coding security scanner built for founders who ship with AI. It is the fastest way to check whether your Lovable app, Bolt.new prototype, or Cursor project leaks Stripe keys, leaves Supabase row-level security off, or ships without CSP and HSTS.
Unlike generic header checkers, we probe live JavaScript bundles, public API surfaces, and database endpoints the way attackers search vibe-coded SaaS on Vercel and Netlify.
Broken Supabase RLS is the top critical finding on AI-built stacks. We surface open REST paths and client-side service_role tokens before your launch post goes viral for the wrong reason.
Every finding includes a copy-paste prompt for Cursor, Claude Code, or Lovable so you close gaps without becoming a security engineer overnight.
FAQ