Perfai Security - Find & fix live vulnerabilities in Vibe Apps with 1-prompt.

by•
Autonomous access control security for Vibe-coded apps. Our platform finds and fixes live vulnerabilities in your vibe-apps built on Replit, Lovable, Claude Code, Cursor, and other AI-coding tools. 1-prompt makes your app production-ready in minutes without requiring security expertise.

Add a comment

Replies

Best

Hey Product Hunt!  👋 Qutub here from .

 

Over the last 18 months, I've found vibe-coders — including myself — opening Replit, Lovable, Cursor, Copilot, Claude Code (any of the various AI-coding tools) and within a few hours, they have something that looks and functions like a real product, with login, dashboards, payments, database records, admin screens, user roles, and the foundations for handling customer data.

 

And that's awesome because the app looks finished!

But that's when the serious builders ask:

"Is this actually safe to put on the internet?"

The Problem

Every app has permissions about who can do what. Customer X should only see X's own data, not someone else's. A normal user should not gain admin access. These permissions are also called access controls.

The problem is that even a small app will have thousands of access controls. Here is the simple math:

6 Roles x 10 Data x 100 Actions => 6,000+ access controls

These access controls live in three places: the app pages people click on, the API endpoints (where the app sends and gets data), and the database (where the data is stored). AI tools build apps fast. But they skip most of these checks in all three places. That is how data leaks and hacks happen.

The Solution: Perfai Security

Autonomous security for AI & vibe-coded Apps

You just paste your app's URL. No code needed. Then our AI agents do three things:

  1. Vision Agent: Learns your app. It navigates through every page, API, and action, with every app role.

  2. Security Agent: Tests every access control. It checks the pages, workflows, API endpoints, and the accessible database. It finds the doors that are open but should be locked.

  3. Fix Agent: It tells your AI-coding tool (Replit, Lovable, Cursor, Claude Code, etc.) how to fix these vulnerabilities, and verifies the attack paths are patched.

It also keeps watching. Every time you update your app, a locked door can open by accident. We check again after each update, and tell you what broke before anyone else can find it.

And since all of this is done in minutes (relative to what would previously take dev teams weeks to accomplish), the entire loop can be run again with every new update.

Direct Benefits of using Perfai Security?

  • You save $100K+ in breach costs.

    • Find vulnerabilities no other tools cover.

    • Find live issues before users, attackers, or bug bounty hunters do.

    • Secure your apps against the excessively growing attack-surfaces.

  • Protect enterprise deals and funding rounds by showing what is being covered, continuously.

  • Reduce compliance and privacy risks.

  • Save $10K–$40K in manual testing time and effort by automating.

  • Prevent customer churn and reputation damage associated with logic issues.

Early Traction:

So far we have secured 4,000+ apps. We found and fixed 28,400+ vulnerabilities. We saved our customers $27.5M in bug bounties. And for our contributions to the overall security field, we have been awarded Innovator of the Year by CloudX.

Product Hunt Offer:

For the Product Hunt community, Perfai Security's Pro-plan is offered at 50% discount with the discount code

Discount Code: PRODUCTHUNT50

You can start testing by pasting your app URL — no source-code access required — and getting your first vulnerability results within minutes.

Thanks for checking out Perfai Security.

Build fast. But don’t ship blind.

 Many congratulations Qutub, Intesar and team on the launch! :)

How I met the maker: I met Qutub a few weeks ago when he pitched me the product. We had a few back-and-forth conversations on the messaging and assets before the launch was ready to go live, and I really enjoyed brainstorming and discussing it with him.

What is the product?

Perfai Security is an autonomous security platform for vibe-coded apps. It finds and fixes live access-control vulnerabilities in apps built with tools like Replit, Lovable, Claude Code, Cursor, and other AI coding platforms.

Why I endorse it?

I endorse it because it tackles a real problem for modern builders: shipping fast often means shipping blind on security. Perfai makes it much easier to catch and fix vulnerabilities before they reach users, without needing a security expert on hand.

Enter your vibe-coded app's URL and find vulnerabilities in minutes:

  Great launch. AI makes apps easy to build, but permission mistakes cause most data‑privacy leaks. Even small apps have thousands of access checks.

Perfai Security helps builders — and bug‑bounty hunters — find these issues fast.

   
Thank you! You nailed it. Permission mistakes are the #1 cause of data leaks, and even small apps have thousands of access checks. Way too many to test by hand.


That's exactly what Perfai does. Just enter your app URL and our AI agents test every role and permission combo for you. You get a pentest-style report with proof for every issue found. We also do drift detection, so if new issues show up as your app changes, you'll know.

 Congratulations Intesar and the team on the launch!

I met Intesar and the team at AI DevSummit 2026 a couple months ago. We are a stealth startup that hadn't done any formal security testing, and Intesar offered to help. That conversation turned into a real engagement.

Perfai is an autonomous security platform that finds and fixes live vulnerabilities in AI-built apps. It maps your full attack surface: UI workflows, API endpoints, token security, privacy compliance, and runs hundreds of tests simultaneously across OWASP and its own AI-native framework, and tells you exactly what to fix.

Why I endorse it: Because it delivered real findings, fast. Across two test runs on our platform, Perfai executed 258 automated tests(240 security tests across 7 API endpoints and 11 UI workflows, plus 18 privacy tests) and surfaced 6 high-severity issues we didn't know about: 2 security vulnerabilities (missing RBAC and rate limiting) and 4 privacy compliance gaps (missing GDPR user rights endpoints). What impressed me most was the follow-through. Intesar and the team facilitated multiple reruns as we addressed each finding, confirming fixes were holding before marking them resolved. We have not tried the fix agent yet. That is next on our list. If you're building and haven't done a security pass yet, this is the fastest way to find out what you're missing.

 Congrats on the launch! nice niche "Vibe-coded apps"

Hey ProductHunt! 👋 Intesar here — CEO of Perfai Security.

This is my third company (DCHQ was acquired by HyperGrid and APIsec), and out of everything I've built, this is the one that keeps me up at night in a good way — because the timing is so obviously right.


Here's the thing about vibe coding that most people miss: the AI coding tools are incredible at making an app look and function like a real product in a few hours. What they're not good at is remembering that "User A shouldn't be able to see User B's invoices" is a rule that has to be enforced in three separate places — the UI, the API, and the database — every single time you ship an update. Nobody's shipping blind on purpose. They just don't have a security team checking access control on every prompt-to-deploy cycle, and honestly, neither did I on my first two companies until it hurt.


So we built Perfai Security as a pre-launch security testing platform for exactly this moment — the gap between "it works on my screen" and "it's live with real users." Paste a URL, our agents map your app, attack its access controls the way a real bad actor would, and hand your AI coding tool (Cursor, Replit, Lovable, Claude Code, whatever you're using) the exact fix — before you ship, not after someone finds it for you. They keep watching every future deploy too, so regressions don't sneak back in. No security background required on your end.


Huge credit to the team who actually built this: Hai, Dr. Abdullah (engineering), Dr. Habeeb (AI), Ghouse (customer success), and Qutub, who wrote the comment above and has been carrying GTM on his back.

If you're vibe-coding anything that touches real user data, I'd genuinely love for you to run it through Perfai Security and tell me what you find (or what we got wrong). I'm in the comments all day — ask me anything about the product, the roadmap, or what "6,000+ access controls in a small app" actually means in practice.

Thanks for checking us out. Build fast, ship safe. 🚀


— Intesar CEO, Perfai Security ()

Ran it on a small Replit app and it flagged an exposed API key plus a sketchy redirect I genuinely missed, super easy fix flow. Wish I'd had this a few months ago when I shipped something embarrassingly broken.

 Thanks for sharing that.. an exposed API key and an open redirect are exactly the kind of issues that can slip through when you're shipping quickly with AI. It's usually not carelessness, just not having time to inspect every endpoint and flow.

Glad Perfai caught them in one pass. If you've got a larger app with multiple roles and real user data, that's where it starts finding the more interesting access control issues too. Give it a run and see what it turns up.

Thanks again for sharing the results!

 This is awesome to hear! Thanks for sharing.


An exposed API key and a sketchy redirect are exactly the kind of bugs that slip through when you ship fast. Glad the fix flow made it easy too. That's the goal: find it, fix it, move on.


And don't feel bad about the earlier app. Almost every vibe-coded app we test has issues like this. You're ahead of the game now.


If you want to scan more apps, the free tier is there, and we're giving away 50% discount codes for the launch. Every scan comes with a full pentest-style report. Need extra credits or help onboarding another app? Just reach out. Happy to help!

Scanning live deployed vibe apps rather than static source is the right call. Most tools miss runtime behavior entirely. We've run into situations where AI-generated code introduces subtle auth gaps that only surface under specific API call sequences. How does your scanner handle stateful multi-step exploits? Can it chain requests across endpoints to trigger a vulnerability that no single request would expose?

 that's exactly the right question, and yes 🔥. It's one of the biggest reasons we built the Vision Agent. Instead of looking at isolated endpoints, it learns how your app actually works by mapping the workflows and request sequences it uses, like create → update → approve → read

The Security Agent then replays those flows and mutates them to uncover things like multi step privilege escalation, state transition abuse, creating an object as role A and accessing it as role B, or skipping an approval step a few calls earlier. These are the kinds of stateful authorization issues that only show up across a sequence of requests, so most scanners never see them.

Every finding comes with the exact request chain needed to reproduce it. Business logic chaining is an area we're continuing to push hard on.

Give it a try and see what sequences it surfaces in your app. It's free:

 Great question! This is exactly why we test live apps instead of just code. Some auth bugs only show up when requests happen in a certain order, and code scanners can't see that.


Yes, we handle multi-step exploits. Our Security Agent learns how your app works, then chains requests across endpoints and roles. For example, it logs in as a low-level user, grabs an object ID from one endpoint, and tries to use it somewhere else. That's how we catch bugs no single request would find.


On average, Perfai finds dozens of critical vulnerabilities and active data leaks, and it fixes them instantly too. Full coverage across UI, API, data, and roles, at a fraction of pentest cost.


Try it free at . Just enter your app URL to start. We're also giving away 50% discount codes for the launch. If you need extra credits or help onboarding your app, reach out to me anytime. Happy to help!

Can Perfai detect business logic vulnerabilities, or is it mainly focused on authorization issues? BTW, congrats on shipping..

 thank you, and great distinction to draw. Access control is business logic. It's the highest-value slice of it, and the one missed most often. So that's where we go deepest: BOLA/BFLA/IDOR, privilege escalation, cross-tenant isolation, multi-step workflow authz.

But we don't test at the "is there an auth check?" level. The Vision Agent builds a semantic model of your app with the roles, objects, actions, state... all taken into account. And our Security Agent can reason about the intended rules and then try to break them, such as:

  • skip a workflow step

  • replay a state transition

  • mutate an object you own to reach one you don't

  • chain a privilege escalation

That's all 'logic'-level attacking. Pure economic-logic abuse (price/coupon/quota manipulation, business-invariant races) is what we're expanding into next. Want to see what it flags on yours? You can use our discount code to get 50% off on the Pro plan (in pinned comment)

 
Thank you!


Great question. Our core focus is access control: roles, permissions, and data exposure across UI, API, and data layers. That's where most real-world breaches happen.


But there's a lot of overlap with business logic. Since our agents learn your app's actual workflows, they catch logic gaps tied to access, like skipping steps in a flow to reach data you shouldn't, or performing actions your role shouldn't allow. Pure business logic bugs like pricing errors aren't our focus today, but the access side of logic flaws is well covered.


Try it free at and see what it finds. You get a full pentest-style report with every scan. We're also giving away 50% discount codes for the launch. If you need extra credits or help onboarding your app, just reach out. Happy to help!

Tools like this are usually judged by what they catch, but the harder part is what slips through.

Do you have a sense of that side - cases where something looked clean but was found later? That would matter more to me than the total number of vulnerabilities found.

Congrats on the launch!

Hello I'm particularly excited to answer your question! 

Raw vuln counts are a vanity metric. And you're right... what slips through is the real test. A few ways we attack the false-negative problem head-on:

We measure against a known denominator. The Vision Agent enumerates the full access-control matrix (roles × objects × actions), so we report coverage (what share of that surface we actually exercised) not just a pile of findings. You see what we tested, not only what we caught.

Gaps are reported as gaps, never as green. An auth wall we couldn't cross, or a path we lacked credentials for, or a flow needing business context we can't infer ("this discount should never apply to enterprise SKUs"), etc. All those surface as explicit coverage gaps, not a false "clean."

"Looked clean, found later" is a first-class case. Every deploy gets re-tested, and as our attack models improve, we re-scan existing apps. So yesterday's "clean" can legitimately become today's finding. Coverage is a living thing, not a one-time snapshot.

And every finding is exploit-verified, so what you do get isn't diluted by false positives. We'd rather hand you an honest "here's what we didn't reach" than a green checkmark that lies.

 

Thank you! And this is one of the best questions we've gotten.

Honest answer: yes, things can slip through. No tool catches everything, and anyone who says otherwise is selling you something.


Here's how we think about it. We're focused on access control, so bugs outside that scope (like injection or business logic errors) are not what we hunt. Within access control, our coverage comes from testing every role against every data type and action, so the misses tend to be edge cases like flows the agent couldn't reach, not whole categories.


When a customer or pentester finds something we missed, we treat it as a bug in our system. We add it to our test framework so every app we scan after that gets checked for it. That feedback loop is how our coverage grows.


If you want to see for yourself, try the free tier at . You get a full pentest-style report, so you can compare it against your own findings. We're giving 50% discount codes for the launch too. Need extra credits or onboarding help? Just reach out!

the "mutate an object you own to reach one you don't" part is what caught my attention. if that attack succeeds against a live production app, the agent didn't just find the vulnerability, it exploited it for real against real data. is there a safe/sandboxed mode where the mutation attempts happen against a snapshot or shadow copy, or does running this against a production app with real customers mean you're accepting some risk of the test itself causing the exact damage you're trying to prevent

 great question, you decide what Perfai Security points at. You hand us any base path or app URL. The aggressive, state-changing pass runs against a staging environment, a preview deploy, or a clone/snapshot, not necessarily your live prod. The blast radius is your call, not ours.

And even then, proving an access-control break almost never requires destroying data. For "mutate an object you own to reach one you don't," the vuln is proven the moment the system authorizes the cross-boundary action for the wrong principal... making the 'authorization' the finding. We assert that the boundary is crossable but we don't complete the destruction to prove it. So the check never depends on a destructive write, and anything genuinely state-changing you route to the staging/clone URL you give us.

You can sign up free at (or 50% off the Pro plan with our Product Hunt discount) and I'd be happy to connect and walk you through pointing it at a staging clone.

 Really good question. You're right that this is where most testing tools get risky.


Perfai Security is production-safe, unlike regular pentesting. Here's why:


We don't run injection attacks at all. Those are the tests that can damage your app, database, logs, APIs, containers, and third-party integrations. We focus on access control testing, which is safe by design.


The agent also uses its own test accounts, not real customer accounts. When it checks if it can reach data it shouldn't, it's testing if the door opens, not pulling customer data. For risky actions like updates or deletes, it only tests against objects it created itself. Real records are never touched.


So the test itself won't cause the damage it's trying to prevent. That safety is core to how we built it.


Try it free at and get a full pentest-style report of your app. We're giving away 50% discount codes for the launch too. If you need extra credits or help onboarding, just reach out. Happy to help!

 that boundary-crossable-not-destructive distinction is clever. one thing I'm wondering: since the agent only tests against objects it created itself, could that miss bugs that only trigger on real customer data shapes, like an IDOR that depends on a specific ID encoding or a legacy record format from before some migration? or does the agent seed test objects that mimic whatever data patterns it finds in the app already

 

Sharp question, and you've spotted the real trade-off in safe production testing.


Here's how we close that gap: the agent doesn't test from just one account. It signs up dozens of role accounts across multiple tenants, so we're recreating the real shape of your app: many users, many roles, many tenant boundaries. IDOR bugs are cross-account by nature, like tenant A reaching tenant B's objects. With dozens of accounts in play, those boundaries get tested from every angle, using real IDs your app actually generated.


Since the accounts sign up through your real flows, the objects they create follow your app's real ID encoding and data patterns, not synthetic fakes.


You're right that a truly one-off legacy record from an old migration is harder to cover safely, and honestly, no production-safe tool can poke at real customer records without becoming the risk itself. What we can promise: every ID scheme and data shape your app produces today gets tested across role and tenant boundaries, and drift detection catches new patterns as they ship.

 that's a fair boundary to draw honestly, most tools would oversell that last mile. quick one on "drift detection catches new patterns as they ship" - what's the actual signal there? is it watching for new endpoint shapes/ID formats showing up in traffic, or does it need a redeploy/rescan to notice the app changed?

Dropping a major upvote, qq does the security agent test for complex injection flaws (like SQLi or NoSQL injection) alongside the broken object-level access controls? congrats 👏

Really appreciate the kind words, !!
Our access control testing platform compliments DAST / SAST testing tools that already test for injection flaws. And so as to not compete, but rather ensure the un-addressed majority of threat categories are secured against, we built Perfai Security around access control vulnerability testing.

 Thanks for raising this, all the best for your launch🙌

 

Thanks for the upvote!


Straight answer: no, we don't run injection tests like SQLi or NoSQL injection. That's by design. Injection attacks can damage a live app's database, logs, and third-party integrations. We built Perfai to be production-safe, so we stay away from that category on purpose.


Our focus is access control: BOLA, broken role permissions, and data exposure across UI, API, and data layers.
Our agents chain requests across endpoints and roles to find the gaps that single-request scanners miss. That's where most real breaches happen, and it's safe to test on live apps.


For injection coverage, we pair well with a code scanner or a scheduled pentest. Think of us as the layer that covers what those tools can't see at runtime.


Try it free at and get a full pentest-style report. We're giving away 50% discount codes for the launch too. Need extra credits or help onboarding your app? Just reach out. Happy to help!

Congrats. How does Perfai distinguishes between intentional permissions and actual access control vulnerabilities?

Great question  

We start by learning what access is intended. Perfai Security reads the app's UI and role structure to find the base for who's meant to see what before building a permission map from it. Then we replay the same API calls as different users, roles, and tenants and compare what actually comes back.

The distinction is in the response. We only flag it when a user actually receives unauthorized data they were never meant to see. If the endpoint returns their own data, an error, or empty results, that's intended behavior and we leave it alone. We go a step further by excluding resources that are shared by design.

Above all of this, we surface permission anomalies such as cases where the app's real behavior contradicts its own intended access model (a user who should be blocked isn't, or an authorized user is wrongly denied). That's how we separate deliberate permissions from genuine broken-access-control, IDOR, and privilege-escalation issues.

 
Thank you! This is one of the hardest problems in access control testing, so great question.


Here's how we approach it. Our agents first learn your app's intended permission model by exploring what each role sees in the UI. If a page, button, or data field never appears for a role, but the API still serves it, that's a strong signal of an unintended gap. The UI is basically your app telling us what you meant to allow.


We also weigh the data itself. A viewer role reading a public blog post looks intentional. A viewer role pulling another user's private records through a direct API call almost never is.


And for edge cases, you can mark a finding as intended behavior, and we won't flag it again in future scans. Your feedback tunes the results to your app.


Try it free at and get a full pentest-style report. We're giving away 50% discount codes for the launch too. Need extra credits or help onboarding your app? Just reach out. Happy to help!

Do you think you can add a GitHub Actions integration to automatically trigger scans after each deployment??

 Appreciate the comment! This integration already works today. Drop in a GitHub Actions step (our CI/CD API is built for it): it triggers a scan, waits, and fails the build on new Criticals with a dedicated CI service-account role, job-id idempotency so retries don't double-scan, and auto-created GitHub issues for findings. It's a copy-paste snippet from our docs right now; one-click Marketplace Action is next. Happy to send you the snippet

 
Testing after every deploy is exactly where this should go, since apps change fast and stale results lose value.


The good news is our setup makes this easy to build. Since a test only needs your app URL, a GitHub Action just has to hit our API after deploy. No agents, no repo access needed.


In the meantime, you can trigger re-tests in one click, and we do drift detection, so when your app changes, we catch new gaps that the last test couldn't see.


I'd love your input on how you'd want the Action to work (fail the build on criticals? just report?). DM me and let's shape it together.


Try it free at and get a full pentest-style report. We're giving away 50% discount codes for the launch too. Need extra credits or help onboarding your app? Just reach out. Happy to help!

123
•••
Next