Security check for apps you built with AI

Find the holes before someone else does.

You shipped an app with Lovable, Bolt, Cursor or another AI assistant. Paste its URL and Lockright checks it the way a stranger would, for the mistakes that actually get people: leaked keys, Supabase tables and buckets anyone can read, functions and admin pages with no login check. You get a score, and every problem comes with a fix prompt you paste straight into your AI editor.

One-time purchase · Universal Mac app for Apple silicon and Intel (tested on Apple silicon) · No account, no subscription

my-app.com · read-only audit 4 of 6 locked Stop and fix: 1 critical problem.
SecretsLocked
Database & storageCritical
Functions & adminLocked
Headers & domainMedium
Public filesLocked
CORSLocked
  1. Database & storageAnon can READ table "profiles"Critical
  2. Headers & domainNo Content-Security-PolicyMedium
Illustration: a made-up app with one open table and no CSP.

Six locks, checked the way a stranger would.

These are the boring, predictable holes, not exotic exploits. They're also the ones AI-built apps leave open most often.

1 · secrets

Secrets

Reads every JavaScript file your site ships and looks for keys that should never be there: a Supabase service_role key (full access to your database), Stripe, OpenAI and Anthropic keys, AWS, GitHub and email-service tokens.

2 · database & storage

Open tables and buckets

Asks your Supabase tables for rows and your storage buckets for file lists using only the public key, exactly like a stranger's browser would. If Row Level Security or a storage policy is wrong, it shows you what came back.

3 · functions & admin

Doors with no lock

Calls your edge functions with no login and with a fake one, and tries /admin and routes like /api/users. Anything that answers can be used by anyone, on your bill.

4 · headers & domain

Headers, HTTPS and email

Browser protections (CSP, HSTS, clickjacking), your HTTPS certificate and redirects, cookie flags, and the SPF and DMARC records that stop strangers sending email as you.

5 · public files

Files that shouldn't be public

Looks for a deployed .env under every name and folder it hides in, an exposed .git folder, backups, source maps and folders that list every file inside them.

6 · cors

Over-open CORS

Tests whether any website can call your API with your visitors' logins attached.

Plus: Code tells

Point it at your project folder and it lists risky leftovers: a .env that got committed or dropped in the public folder, a secret under a VITE_ or NEXT_PUBLIC_ name, placeholder secrets, security TODOs nobody finished, disabled auth checks, eval(). It never edits your files.

Three steps. No code.

  1. 1

    Paste your app's URL

    Lockright reads the JavaScript your site already ships and finds your Supabase project, its public key, and the tables, functions and buckets the app uses. You check the list and save.

  2. 2

    Run the audit

    Usually under thirty seconds. You see exactly which checks will run, and why any are skipped, before it starts. The result is a score: 4 of 6 locked.

  3. 3

    Paste the fix, run again

    Every problem has a fix prompt written for your AI editor. Copy one, or copy the fix pack to fix them all worst first, then re-run to see the lock close. History keeps every run.

Fits how you already build.

Lockright doesn't stop at a report. It hands the fix to the tool that wrote the code, and keeps checking after you ship.

  • Fix prompts. One click copies a prompt for Cursor, Claude Code, Lovable or Bolt that explains the problem and asks for the smallest safe fix.
  • Inside your AI editor. A built-in MCP server lets Claude Code and Cursor run the audit and read the results while you work.
  • On every deploy. --fail-on high fails a CI build when a lock opens. A ready GitHub Action is included.
  • Every week. Turn on a weekly re-check and get a notification if a deploy opened a lock.
  • Reports you can send. Save any run as a PDF or Markdown for a client or a co-founder.

Safe to point at your live site.

Every check makes the same kinds of requests a normal browser makes. Nothing is written, changed or deleted.

  • Runs on your Mac. Your target details and reports stay in a folder on your computer. The only thing Lockright sends to us is your license key: once when you activate, and about once a month to check it.
  • Refuses the wrong key. Paste a service_role key by mistake and it stops and tells you.
  • Write tests stay locked away. Proving whether strangers can change your data is command-line only, never allowed against production, and sits behind four separate safeguards.
  • Learn as you go. A Learn tab explains the severity scale, every check, and the jargon, in plain English.

Built for your stack.

A static site or PWA on Cloudflare Pages, GitHub Pages, Netlify or Vercel, with an optional Supabase backend and edge functions.

What it isn't

It isn't a penetration test or a substitute for a security review. It checks the common holes, fast. No Supabase? You still get the secrets, headers, HTTPS, cookies, email, public files, admin routes and CORS checks.

$19. Once.

A universal Mac app for Apple silicon and Intel, tested on Apple silicon. Run it as often as you like, on every app you own.

Buy Lockright

Sold through Gumroad. Your receipt has the license key. Needs macOS 11 or later.

Questions

Do I need to know how to code?

No. You paste your app's address and Lockright finds the rest. Results come in plain English, and every problem has a fix prompt you can hand to your AI editor.

Can my AI editor run it?

Yes. Lockright includes an MCP server. Add it to Claude Code or Cursor with the command shown in Settings, then ask your editor to scan your site and fix what's open.

Can I run it in CI?

Yes. lockright scan https://your-app.com --fail-on high exits with an error when a High or Critical problem shows up. A GitHub Action example is included. Build servers read your license key from a secret and don't count as one of your computers.

How does the license key work?

Your Gumroad receipt has one key. Paste it into Lockright once and that computer is activated for the app, the command line and the MCP server, online or off. One key covers up to five of your own computers, and you can release one in Settings to move it.

Is it safe to paste my Supabase anon key?

Yes. The anon key is the public key your app already sends to every visitor's browser. Lockright uses it to see what a visitor could see. It refuses to run with a service_role key, which is the one you must never share.

Will it change anything on my site or database?

No. The app is read-only. Write tests exist only on the command line, only against staging or local databases, and only after you type the app's name to confirm.

Why is it a Mac app and not a website?

To check your site the way a stranger would, it has to read another site's responses, and browsers block websites from doing that. So Lockright runs on your computer instead.

macOS says it can't open Lockright.

Lockright isn't notarized by Apple yet. Open it once, then go to System Settings › Privacy & Security and click Open Anyway. You only do this the first time.

Windows?

Not yet. The Mac app comes first.

What if I don't use Supabase?

Secrets, headers, HTTPS, cookies, email, public files, admin routes and CORS work on any website. The Supabase table, storage and edge-function checks are skipped, the score says so ("4 of 4 locked · 2 not checked"), and Lockright tells you why.