Independent audits for AI-built software
Different technical questions need different evidence. These pages separate code review, application security, production readiness and technical due diligence, so you can pick the validation that matches the decision in front of you rather than the one with the widest name.
By the question you are asking
Each of these answers a different question, needs different access, and produces different evidence. Start from the decision you are about to make.
An independent audit of the code your AI tools wrote
Independent validation of AI-generated code: source analysis, dependency checks, and runtime verification against OWASP, NIST SSDF and CWE mappings, with the evidence behind every result graded and uncovered controls named.
Security audit for an AI-built application, with evidence attached
A security audit for AI-built SaaS covering public attack surface, source, dependencies, access control and the running system, with every result graded by evidence strength and shareable as a Passport.
Audit your vibe-coded app before real users find the problems
An independent audit for applications built with AI coding tools. Tests the deployed app, the source and the running system against named standards, grades the evidence behind every result, and publishes what it found.
What a production readiness audit examines before you launch
An independent evaluation of whether software is ready for real users: security controls, secrets, access control, dependency health, error handling, observability, backups, rollback and query performance, each with its evidence graded.
Evidence-backed technical due diligence for software startups
How technical due diligence works on a software startup, what an investor-led review costs, and where repeatable technical evidence supplements the people running the process rather than standing in for them.
By the tool that built it
The same validation, written for what each builder tends to leave behind. StackAttest validates what the tool produced; it does not integrate with the tool.
A Lovable security audit that produces evidence, not reassurance
An independent security audit for applications built with Lovable. Tests how access is enforced, how keys are handled and what the running system actually does, grades the evidence behind every result, and names the controls the run could not reach.
A Cursor security audit of what your sessions actually shipped
An independent security audit for software written with Cursor. Tests server-side authorisation, input validation, secret handling, dependencies and the deployed system against named standards, with an evidence grade on every result and uncovered controls named.
Independent validation of what Claude Code built
An independent audit of a codebase an AI coding agent wrote across many sessions. Tests authorisation, secrets, dependencies and the running system against named standards, grades the evidence behind every result, and names the controls it could not reach.
A security audit for a v0 app, checked at the Next.js boundaries
An independent audit for applications generated with v0. Checks the boundaries a Next.js app is judged on: Server Actions, Route Handlers, middleware, the client and server split, public environment variables and webhook handling, with every result graded.
Audit the application Bolt generated, before strangers use it
An independent security audit for applications generated with Bolt. Tests the deployed app, the source and the running system against named controls, grades the evidence behind each result, and says which controls the run could not reach.
Audit what your Replit project exposes once it is running
An independent security audit for software built and deployed on Replit. Covers what is publicly reachable, where secrets end up, which endpoints ask who is calling, and what persists between runs, with the evidence behind every result graded.
By the stack underneath
Where the data boundary lives, and what has to be true for it to hold.
An independent security audit for the app you built on Supabase
An independent security audit for applications built on Supabase. Covers row level security, the two keys and what each is for, storage rules, database functions and cross-tenant isolation, with the evidence behind every result graded and uncovered controls named.
Find out whether your row level security policies scope anything
A focused audit of Supabase row level security: tables left unprotected, policies that admit every signed-in user, policies that trust a tenant id from the client, and write commands nobody wrote a rule for. Checked in source and against the running application.
Your Supabase service role key, and what happens if it leaks
One Supabase key belongs in the browser and one must never reach it. How to tell which one you shipped, how to check the deployed bundle and the repository, and why rotating comes before editing any code.
Before you buy an audit
The reference pages explain one failure at a time, and the free check returns a real result about a deployed application without an account. Neither needs a conversation with us first.