Your AI writes code. Audit AI proves it's safe to merge.
A verified security engineer for AI-generated Next.js + Supabase apps: find the bug that lets one customer read another customer's data, reproduce it in a sandbox, propose the minimal fix, then run the same attack again to prove the fix holds.
- Scan a public repository, free and without an account: auditai.sh · sample report
- Open-source scanner and eval corpus: auditai-scanner ·
npx auditai-scan . - A check on every pull request: GitHub App
- A deliberately vulnerable app to try the whole loop on: auditai-playground
- Precision measured by hand on repositories the engine had never seen: auditai.sh/stats
- Building in public: @Audit_AI · Bluesky · YouTube
In our demo app one table has no row level security, so anyone holding the public key reads every private note. A scan finds it, one migration closes it. The voice is synthetic; the demo is real. Also on X.
audit-ai-rls-hole-39s.mp4
Watch on YouTube or in the scanner README.
Solo founder plus AI coding agents, which is exactly the customer. Progress, numbers and failures are published as they happen, the unflattering ones included.


