Launched this week

Keelscan
Find the data leaks in your app before buyers do
6 followers
Find the data leaks in your app before buyers do
6 followers
Keelscan continuously scans your code, live app, and Supabase/Firebase for the security holes that stall B2B and healthcare deals, with plain-English fixes and a shareable report.






Hey Product Hunt ,
I'm Liban, solo founder at CraftRipple.
Keelscan came out of a pattern I kept hitting: AI-built apps ship fast, but they leak. Exposed Supabase tables, missing row-level security, API keys in the client bundle, the kind of thing that doesn't break the app, so nobody notices until a buyer's security review does. Then the deal stalls, or worse.
I got tired of finding these by hand, so I built a scanner that does it continuously. Point Keelscan at your code and live app and it checks for the security holes that actually kill B2B and healthcare deals, then hands you a plain-English fix and a report you can share with the buyer who asked.
It's built for solo founders and small teams shipping AI-built apps who can't afford a security team but still have to answer "is this secure?"
Free scan, no signup, try it on something you shipped this week: https://keelscan.com
I'm opening 50 founding spots at $29/mo for life for early folks who want the full continuous version.
Genuinely want to hear what Keelscan finds in your app (and where it misses). Ask me anything about the build, the security side, or going solo.
Honestly the shareable report is already a nice touch, but I think it would be super helpful if Keelscan could let buyers actually leave comments or sign off on specific findings right inside that report, kind of like a lightweight review mode. That way our security team and the client are literally talking about the same line item and we skip a ton of back-and-forth over email before the deal can move forward.
@muammer1168425 Thanks, this is a good call, and it's where the report wants to go. The catch: the share link is account-free on purpose so whoever you send it to can just open it, your security team, the client, an auditor, and comments mean identity. I'm not making any of them sign up to say "accepted".
Likely shape: a status per finding (accepted / disputed / fixed) plus a thread, everyone replying through the link, no account, just a name typed once so you can tell who said what. Would that cover it, or does it need to feed a ticket on your side too?
Scanned a side project and the report flagged a Supabase row-level security issue I had no idea was exposed. The plain-English fix actually made sense without me digging through docs.
@nurcandemi21842 Thank you for actually running it on something real. That's the exact finding I built it for. RLS is the sneaky one because the app works fine while it's wrong, so nothing tells you until a buyer looks. Mind if I quote you on the site? And what did it miss? That's the most useful thing you could tell me