StackAttestTechnical Trust
Audits

Independent audits for AI-built software

Different technical questions need different evidence. These pages separate code review, application security, production readiness and technical due diligence, so you can pick the validation that matches the decision in front of you rather than the one with the widest name.

By the question you are asking

Each of these answers a different question, needs different access, and produces different evidence. Start from the decision you are about to make.

By the tool that built it

The same validation, written for what each builder tends to leave behind. StackAttest validates what the tool produced; it does not integrate with the tool.

Lovable security audit

A Lovable security audit that produces evidence, not reassurance

An independent security audit for applications built with Lovable. Tests how access is enforced, how keys are handled and what the running system actually does, grades the evidence behind every result, and names the controls the run could not reach.

Cursor security audit

A Cursor security audit of what your sessions actually shipped

An independent security audit for software written with Cursor. Tests server-side authorisation, input validation, secret handling, dependencies and the deployed system against named standards, with an evidence grade on every result and uncovered controls named.

Claude Code security audit

Independent validation of what Claude Code built

An independent audit of a codebase an AI coding agent wrote across many sessions. Tests authorisation, secrets, dependencies and the running system against named standards, grades the evidence behind every result, and names the controls it could not reach.

v0 security audit

A security audit for a v0 app, checked at the Next.js boundaries

An independent audit for applications generated with v0. Checks the boundaries a Next.js app is judged on: Server Actions, Route Handlers, middleware, the client and server split, public environment variables and webhook handling, with every result graded.

Bolt security audit

Audit the application Bolt generated, before strangers use it

An independent security audit for applications generated with Bolt. Tests the deployed app, the source and the running system against named controls, grades the evidence behind each result, and says which controls the run could not reach.

Replit security audit

Audit what your Replit project exposes once it is running

An independent security audit for software built and deployed on Replit. Covers what is publicly reachable, where secrets end up, which endpoints ask who is calling, and what persists between runs, with the evidence behind every result graded.

By the stack underneath

Where the data boundary lives, and what has to be true for it to hold.

Before you buy an audit

The reference pages explain one failure at a time, and the free check returns a real result about a deployed application without an account. Neither needs a conversation with us first.

Security checks, explainedRun the free checkSee an example Passport