DevMeth

Show HN · Product Hunt · your first users

The pre-launch security checklist for AI-built apps

Launch day is when strangers — including bored ones with curl — first hit your app. This is the short list to clear before that happens, in the order you should clear it. Every item links the check that automates it.

A week out — secrets and history

  • ▢No API keys, tokens, or passwords in source — including the ones you committed and deleted. secrets-in-git-history
  • ▢.env is gitignored, and .env.example contains placeholders, not real values. env-example-real-values
  • ▢Nothing server-only is reachable from client bundles (check your browser tab's Network panel for key-shaped strings). secrets-in-client-bundle
  • ▢CI workflow files can't leak secrets on pull requests. ci-secret-exposure

A week out — access and data

  • ▢Every API route checks auth server-side — log out and confirm the important pages actually block you. authless-api-route
  • ▢Admin routes verify roles on the server, not in the UI. client-side-role
  • ▢Records are read by owner, not just by ID. idor
  • ▢Database policies: RLS on, policies not permissive, no browser-direct queries. supabase-rls
  • ▢Auth endpoints rate-limited; reset tokens unguessable. auth-rate-limit

Launch day — the public surface

Launch day — the money paths

  • ▢Payment amounts verified server-side against the catalog, never trusted from the client. payment-amount
  • ▢Paid API endpoints check entitlement before serving. paid-endpoint-auth
  • ▢Webhooks verify signatures against the raw body. webhook-signature

Run it, don't read it

The free scan runs the Critical half of this list in about two minutes. The Launch Pack ($179) adds the Rescue tech-debt scan, unlimited re-scans until every fix is verified green, and a badge you can put on the launch post — which is the honest version of "trust me, it's checked".

DevMeth checks the 48 known AI-code failure patterns — not a penetration test or a security guarantee. A clean scan means the known patterns were checked and clear; it is not a guarantee of security.

Check your app — free

10 Critical checks, no signup, results in about two minutes. Every finding is masked and carries a paste-ready fix prompt.

Run the free scan