Sentrint scans the repository behind your AI-built app to surface exploitable security risks and guide you to a fix. It analyzes secrets, database access rules, dependencies, and risky code paths, then uses an AI layer to cut false positives and draft a platform-specific fix prompt for tools like Claude, Gemini, Cursor, and more. Reports grade your risk, explain each finding in plain English, and verify improvements across rescans, with strict privacy and ephemeral scanning enforced.
Hey, I'm Gourab, I built Sentrint after noticing the same mistakes over and over in apps built with Lovable, Bolt, v0 and Cursor: Supabase keys sitting in plain client-side JS, row-level security nobody turned on, dependencies nobody's touched since the AI wrote them. It's not just my impression, Symbiotic Security scanned 1,072 vibe-coded apps in June and found 98% had at least one flaw, and SupaExplorer separately found 11% of indie-launched apps leaking their database keys straight in the frontend. So I built the scanner I wanted to exist: point it at your GitHub repo, read-only, nothing pushed or changed, and your code gets cloned into an ephemeral, single-use instance that exists only for your scan and gets destroyed the moment it finishes, nothing sits around on our servers afterward, and you get back a plain-English report with your real score, every finding, and a fix written as a prompt you paste straight back into whatever AI tool built the thing. No terminal, no security background needed, and the free scan isn't a teaser, it's the whole scan, no card required. If you've shipped something with AI and never had it actually checked, I'd like to hear how it goes, run one and I'll walk through the results with you.