Perfai Security - Find & fix live vulnerabilities in Vibe Apps with 1-prompt.

by•
Autonomous access control security for Vibe-coded apps. Our platform finds and fixes live vulnerabilities in your vibe-apps built on Replit, Lovable, Claude Code, Cursor, and other AI-coding tools. 1-prompt makes your app production-ready in minutes without requiring security expertise.

Add a comment

Replies

Best

Congrats on the launch. How much time does it typically take to generate report? I am guessing it may vary based on the complexity of the app?

Thank you You can get the first results in minutes, but yes it scales with complexity and may take up to 1 hour based on the load. The work is proportional to your access-control matrix (roles × data objects × actions), so a small app is minutes and a large multi-role one takes a bit longer. But we're talking minutes-to-hours vs. the weeks a manual pentest of the same surface would need. And because it's that fast, you can re-run the whole thing on every deploy.

 
Thank you!


You guessed right, it depends on the app. The agents explore every page, API, and role combination, so a small app finishes in under an hour, while a large app with many roles and data types can take a few hours.


The good news: it's fully hands-off. Paste your URL, and the agents do the rest, including signing up their own test accounts. You can watch the live activity log while it runs, and the full pentest-style report lands when it's done. Re-tests after app updates are faster too, and drift detection flags what changed.


Try it free at . We're giving away 50% discount codes for the launch too. Need extra credits or help onboarding your app? Just reach out. Happy to help!

Perfai reduces the barrier to security testing as the workflow is as easy as pasting the URL. Congrats on launching today.

Much appreciated  
That’s exactly what we’re trying to solve. With so many vibe-coded apps going live, security testing needs to fit the builder’s workflow. Perfai Security makes it possible for solo founders and small teams to deep-test access controls in live apps without needing enterprise security teams, long setup cycles, or manual testing expertise.

 
Thank you! That's exactly the goal.


Security testing has always had a high barrier: expensive pentests, complex tools, or needing an expert on the team. Most builders just skip it. So we made the barrier one paste. Drop in your URL, and our agents explore your app, sign up their own test accounts, and test everything across UI, API, data, and roles.


No setup project, no security background needed. And with drift detection, coverage stays fresh as your app changes, so it's not a one-time check.


Try it free at and get a full pentest-style report. We're giving away 50% discount codes for the launch too. Need extra credits or help onboarding your app? Just reach out. Happy to help!

Does Perfai support authentication providers like Clerk, Auth0, or Supabase Auth out of the box?

 yes! Because we test black-box from your app's URL, we authenticate through your real login flow using the test credentials you provide for each role. This way, Clerk, Auth0, Supabase Auth and the rest all work. We meet your app wherever it lives instead of needing a separate integration per provider. If you've got a specific setup in mind, let us know and we can confirm the exact flow.

Would genuinely love to have you run something through it.

 
Great question! We're auth agnostic. If a typical user can sign in to your app, our agents can too. Clerk, Auth0, Supabase Auth, custom logins, all work out of the box. Our Vision Agent handles the sign-in flow the same way a real user does, and it even signs up its own test accounts if your app supports sign-up.


The only limitation right now is MFA or OTP beyond email. Email-based OTP works fine, but codes sent to phones or authenticator apps aren't supported yet.


Once in, we run full access control testing across UI, API, data, and roles, with drift detection catching new gaps as your app changes.


Try it free at and get a full pentest-style report. We're giving away 50% discount codes for the launch too. Need extra credits or help onboarding your app? Just reach out. Happy to help!

Congrats on the launch! The re-check on every update is the part that matters most, since a lot of these tools only catch access-control gaps once and then go stale. Does that re-scan run automatically after each deploy, or do you have to trigger it?

 spot-on! Both modes exist, but automatic is the whole point. You can fire a run manually anytime (one prompt / paste-URL), but the real setup wires it into your pipeline so it runs automatically on a scheduled basis or with each deploy... GitHub Actions steps (or our CI/CD API / deploy webhook) can trigger the scan, wait, and fail the build on any new Critical. Each run diffs against your last clean baseline, so you only hear about what changed, not the same list again. Set it once and every future deploy can re-test itself.

 

Thank you! And you nailed it. A scan from last month means nothing after today's deploy. Vibe-coded apps change fast, so stale results are a real problem.


You can trigger a re-scan anytime with one click, and we support scheduled scans so your app gets checked regularly without you thinking about it. Hooking scans into your deploy pipeline is on the roadmap too, so every push gets tested automatically.


Since we only need your app URL, re-scans are zero setup. Same coverage every time: UI, API, data, and roles.


Try it free at and get a full pentest-style report with every scan. We're giving away 50% discount codes for the launch. If you need extra credits or help onboarding your app, just reach out. Happy to help!

 That's exactly the setup I was hoping to hear baseline diffing so you only see what changed is a nice touch. Congrats again on the launch.

Congratulations! Does this work with any deployed web app, or is it mainly built for apps created with AI coding tools?

 It works with any deployed web app that has a URL. We test black-box from the outside, so we're fully stack-agnostic. It doesn't care whether you hand-wrote it, vibe-coded it, or inherited it. The "vibe-coded" framing is where our solution is needed most right now, but the engine tests any app with roles, APIs, and a database. The only place the AI-coding tool matters is the fix handoff... our Fix Agent delivers remediation through an MCP server you drop into any IDE (Cursor, VS Code, Claude Code…), and it works even if you just want the exact patch to apply yourself. Point it at any URL and see. You can sign up for free or get 50% off our pro plan using the discount code (in pinned comment).

 
Thank you!


It works with any deployed web app. If it runs in a browser and has a URL, we can test it. Doesn't matter if it was built by AI agents, a dev team, or ten years ago by a contractor nobody remembers.


We talk a lot about vibe-coded apps because they're the most at risk: shipped fast, often with no security review, and full of access control gaps. But the testing itself doesn't care who wrote the code. Our agents test the running app across UI, API, data, and roles, so any stack works: React, Rails, PHP, whatever.


Same simple flow for everyone: paste your URL, our agents explore, sign up their own test accounts, and get to work. Drift detection keeps coverage fresh as the app changes.


Try it free at and get a full pentest-style report. We're giving away 50% discount codes for the launch too. Need extra credits or help onboarding your app? Just reach out. Happy to help!

How well does Perfai handle multi-tenant SaaS applications with complex permission hierarchies?

Hi! This is our home turf  Multi-tenant SaaS is where access control gets brutal, and it's what we test hardest. The Vision Agent builds a per-tenant identity map with every role across your hierarchy (org → workspace → team → resource, plus nested roles and inherited/overridden permissions) and the Security Agent then attacks on two axes: horizontal being classic cross-tenant isolation breaks and vertical being whether a member can escalate to admin/owner inside a tenant. It reasons over the effective permission, not the declared one, so inheritance quirks and role-override edge cases get exercised. Cross-tenant leakage is the highest-severity class we hunt.

 

Great question. Multi-tenant SaaS is honestly where Perfai shines, because cross-tenant data leaks are the scariest access control failures out there.


Our agents map your app's roles, data types, and actions, then test the combinations. That includes tenant boundaries: can a user in Company A reach Company B's data through a direct API call, a shared object ID, or a side door the UI never shows? Those are exactly the bugs that hide in complex permission hierarchies, and no single-request check finds them.


For hierarchies like org admin, team admin, member, and viewer, we prove what each level can and cannot reach across UI, API, and data. The agents sign up their own test accounts where possible, and you can add accounts for roles that need invites.


Drift detection matters here too, since permission models change as you ship new features.


Try it free at and get a full pentest-style report. We're giving away 50% discount codes for the launch too. Need extra credits or help onboarding your app? Just reach out. Happy to help!

Congrats! Is Perfai Security looking at the running app, the codebase, or both? The “live vulnerabilities in Vibe Apps” wording makes me curious about where it plugs into a developer workflow, especially for teams using AI agents or vibe coding tools to ship fast.

Much appreciated!!   Perfai Security looks at the running app from the URL you give it. That's exactly what "live vulnerabilities" means. We test the deployed, running system the way an attacker actually hits it, not static source analysis, andso we need zero codebase access to find issues. Where it plugs into your workflow is the fix side. The findings flow back through an MCP server (perfai-mcp-server) you drop into your IDE (Cursor, VS Code, Claude Code…), and into CI/CD via a GitHub Actions step so every deploy auto-re-tests.

 
Thank you!


We test the running app, not the codebase. That's a deliberate choice. Code scanners can't see runtime behavior, like an auth gap that only shows up when requests happen in a certain order, or a role that can reach data it shouldn't. Those bugs live in the running app, so that's where we test.


It also makes setup dead simple: just enter your app URL. No repo access, no CI config, no agents to install. That fits vibe coding perfectly, since the code changes constantly and often nobody's reading it anyway. Ship your app, drop the URL in, and re-scan after big updates.


Our agents test across UI, API, data, and roles, so you get full app coverage no matter what tool wrote the code.


Try it free at and get a full pentest-style report. We're giving away 50% discount codes for the launch too. Need extra credits or help onboarding your app? Just reach out. Happy to help!

Hi Qutub Syed, nice idea and the site looks good, I like the “test a live app by URL” approach, especially for small builders who don’t have a security team.

I tried entering my app URL and clicking “Test now”, but nothing seemed to happen on my end. I may be missing a step, or it could be a browser issue. Just wanted to flag it in case it helps with the launch feedback.

 really appreciate you trying it out and flagging that. Team's already looking into it.

 Here's an update: You didn't miss a step.. we had a security policy on our end that was blocking the "Test now" request. It's fixed now, so after a quick refresh, give it another try and you should go straight into the scan.

 Great, glad it helped! I’ll give it another try. Good luck with the rest of the launch.

 Thanks, appreciate it!

Does Perfai only detect vulnerabilities, or can it automatically suggest or apply fixes as well?

Hi , thanks for asking. Perfai Security offers both, and this is where Perfai Security really shines. We don't just stop at a list of vulnerabilities.

We ship an MCP server (perfai-mcp-server) you drop into your IDE (Cursor, VS Code, or any MCP-compatible agent). Once connected, it pulls your reported issues directly into the editor, and for any issue it generates a context-rich fix prompt with exact endpoint, vulnerability, remediation contexts. Your IDE's coding agent then implements the fix right in your codebase, following your existing patterns and architecture.

We deliberately keep the developer in the loop rather than auto-patching your repo. This way, we never require any code-access. And so the fix lands in your editor where you review and merge it like any other change.

So it's detection → guided remediation → fix, without Perfai Security ever writing to your code behind your back.

TL;DR — Perfai Security maps your app, detects vulnerabilities, provides the fixes, and then retests to verify the issues are patched.

 

Great question! Both. We detect and fix.


Every finding comes with an instant fix you can apply with one prompt in your code agent, like "Fix All", "Fix Critical", or "Fix #2". You don't need to be a security expert or spend hours figuring out how to patch each issue yourself. The Fix Agent hands you exactly what to do.


That's the full loop: our agents test your live app across UI, API, data, and roles, find the gaps, and give you one-prompt fixes. And with drift detection, we catch new issues as your app changes, so you're never relying on a stale report.


All this without paying thousands for a pentest. You get a full pentest-style report on the free tier at . We're also giving away 50% discount codes for the launch. Need extra credits or help onboarding your app? Just reach out. Happy to help!

This launch caught my eye since every other product is vibe-coded now sometimes without even involvement of a technical team member. However, for teams with devs, can developers customize scan depth for staging versus production environments?

 great question, and yes. You run different profiles per environment. You can go deep and aggressive in staging with seed test tenants, exercise state-changing and destructive attack paths, full-matrix coverage... because nothing's at risk. On production it runs in a safe, non-destructive mode (read-only checks, no mutating actions) so always-on monitoring never touches live data.

 
Thanks! You're right, so many apps ship now with no security review at all. That's exactly who we built this for.


For teams with devs, yes, there's room to tune things. You can set up separate apps in Perfai for each environment, so your staging and production scans run with their own settings, credentials, and roles. Since Perfai is production-safe by design (no injection attacks, test accounts only, no real data touched), you can run full-depth scans on production without worry. That's a big difference from regular pentesting.


Devs also get detailed findings with the exact request chains that triggered each issue, so fixes are fast.


Try it free at and get a full pentest-style report. We're giving away 50% discount codes for the launch too. Need extra credits or help getting your team's apps set up? Just reach out. Happy to help!