Chalermpon Ananwattanakit
Solo founder. The auth checks AI forgot. The kind tests pass. The kind that leaks every customer's data with one URL change. I scan for them in 5 days. $497.
Solo founder. The auth checks AI forgot. The kind tests pass. The kind that leaks every customer's data with one URL change. I scan for them in 5 days. $497.
Async security review for solo SaaS founders shipping with AI. Covers the bugs AI ships and tests don't catch: routes that skip the auth check, URL changes that leak every customer's data, password resets that confirm which emails are users, multi-tenant bleed. I scan your code, then in 5 days you get a short report naming each one, in plain English, with an AI prompt to apply each fix in your AI coding tool. Read once, report sent, access deleted. $497 ($197 for the first 3 customers).
the first time you change a number in a URL and another customer's data just loads, it isn't dramatic. no error, the page just renders like it should. that's the bug AI writes and your tests wave through, because the test only ever logs in as one user. /invoices/1043 is yours, /invoices/1044 is someone else's.
one cheap habit catches most of it. after AI builds anything touching other people's data, log in as user A and try to open user B's stuff by changing a number. ten minutes, and it's where the real bugs hide.