Security audit for products shipped with v0, Lovable, Bolt, Cursor, Claude Code, Replit and Supabase — before hackers do vibehacking.
Why now
You did vibecoding. Hackers do vibehacking. service_role exposed in the client, RLS disabled in Supabase, IDOR in AI-generated routes, secrets in public env vars, weak auth. The code compiles. The app loads. And it's wide open.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Disabled RLS, loose policies, service_role in the client, anonymous abuse and RLS bypass via view.
NEXT_PUBLIC with private key, hardcoded JWT secret, .env committed, token in bundle.
Missing signature validation, webhook replay, prompt injection in LLM handler.
Misconfigured provider, reusable magic link, no rate limit on login, poorly validated JWT.
AI-generated routes without ownership check, guessable REST endpoints, trusted params.
Public buckets by default, no MIME validation, path traversal, eternal signed URLs.
Prompt injection, prompt leak, open cost, accessible system prompt, OpenAI key drain.
No rate limit on paid endpoints, LLM DoS, free-tier quota abuse.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Focus on early/mid-stage startups and no-code/low-code agencies shipping product in days on modern stacks.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. Every finding ships with a reproducible PoC + a ready-to-paste Cursor/Claude Code prompt that applies the fix in your stack's patterns.
1-3 weeks depending on surface. A v0 + Supabase + Stripe app usually takes 7-10 business days with one senior pentester.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.