CyberSauce

Security audits for AI-built apps

CyberSauce

You built it with AI in a weekend. Let's make sure it doesn't get breached on Monday.

48-hour turnaround · flat fee, no sales call · plain English, not a scanner dump.

Proof

The numbers that should worry you

Independently verifiable. Linked. In a market full of unverifiable claims, checked numbers are the positioning.

Failure modes

What actually goes wrong

Failure modes common in vibe-coded apps — and what they mean for a non-technical founder.

  1. 01

    Missing or misconfigured row-level security

    Any user can read every other user’s data

  2. 02

    API keys in client-side JavaScript

    Anyone can view-source and run up your bill

  3. 03

    Client-side-only authentication

    The “admin only” check is a suggestion, not a lock

  4. 04

    Broken object-level authorization

    Change an ID in the URL, see someone else’s records

  5. 05

    Exposed .env or .git on the deployed site

    Your entire configuration, publicly downloadable

  6. 06

    Unauthenticated admin routes

    /admin works for everyone

Process

How it works

Three steps. No sales theater.

  1. 01

    Grant read access

    Repo and/or staging URL — only after the engagement letter and authorization to test are signed.

  2. 02

    I audit

    Automated scan (SAST, secrets, dependencies) plus manual review of auth, authorization, and config.

  3. 03

    Report + walkthrough in 48h

    Prioritized plain-English findings, paste-back fix prompts, and a short video walkthrough.

Pricing

Human audits

Transparent fixed fees. Explicit scope — and explicit out-of-scope. No “contact us for pricing.”

Most booked

Launch Readiness Audit

$1,500 flat

48 hours

Includes: Automated scan (SAST, secrets, dependencies) + manual review of auth/authorization/config + prioritized plain-English report + paste-back fix prompts + 15-min walkthrough video

Not included: Remediation, formal pentest, compliance certification, infrastructure/cloud review, load testing

Best for: Pre-launch, or first real users

Buy — Launch Readiness Audit

Deep Audit + Remediation

$3,500–$5,000

5–7 business days

Includes: Everything in Launch Readiness, plus authenticated multi-tenant testing, architecture review, hands-on remediation of Critical/High findings, and one re-test

Not included: Formal pentest, compliance certification

Best for: First enterprise deal, fundraise diligence

Buy — Deep Audit + Remediation

Continuous Hardening

$500–$1,500 /mo

Ongoing

Includes: Re-scan on every deploy, secrets + dependency monitoring, monthly findings digest, async access

Not included: New feature security design

Best for: Post-audit, shipping weekly

Subscribe — Continuous Hardening

Self-serve scanner

Optional hosted scanner plans — not a substitute for a human audit, and not the same as Continuous Hardening. Limits below match the enforced API entitlements. Free scans stay available without an account.Sign in to subscribe, or create an account if you’re new.

Free

$0

No account: 3/hour · 10/day · 5/domain/day. Free account: 5/hour · 15/day · 8/domain/day.

Public URL scan. Full findings via email unlock. Free accounts get higher quotas and saved history — registration does not auto-unlock reports.

Run a free scan

Scanner Solo

$49 /mo

10/hour · 30/day · 15/domain/day

Higher quotas and auto-unlocked full reports on owned scans. Saved history is included with any free account.

Sign in to subscribe

Scanner Startup

$99 /mo

20/hour · 100/day · 40/domain/day

More scans per day for a shipping product, plus auto-unlocked reports.

Sign in to subscribe

Team / Enterprise: Custom quotas and billing. Email hello@cybersauce.io — not available via self-serve Checkout.

Prefer to talk first? Optional 20-minute scoping call— not required to purchase. Or send an inquiry.

Deliverable

See the deliverable

A full sample report on a deliberately vulnerable demo app we own — real findings, paste-back fix prompts, prioritized roadmap. Almost no competitor publishes one.

Open sample report →

Founder

Who’s behind this

CyberSauce is the brand. You’re buying Michael Keenan’s judgment — cybersecurity credentials, veteran background, and infrastructure held to the same standard sold to clients.

The shop floor is dogfooded: hardened DigitalOcean VPS, key-only SSH, A+ TLS and security headers, off-vendor backups with tested restores. Full background and credentials live on the personal site.

michaelkeenan.com — who’s behind this →

Lead magnet

Free URL scanner

Consent-gated, read-only checks for security headers, exposed secrets and paths, and common vibe-code failure tells. Full results are email-gated. Auth logic and multi-tenant isolation stay in the paid audit.

Run a free scan →

FAQ

FAQ

Is this a penetration test?

No. This is a security audit: automated analysis plus manual review of failure patterns specific to AI-generated code, delivered in 48 hours. A formal pentest is a different, longer, more expensive engagement (typically $5,000–$30,000 over 1–3 weeks). You need a pentest when a customer, insurer, or regulator requires one — or after you’ve fixed the audit findings and want adversarial validation.

Why should I give a stranger my code?

Isolated no-network analysis. Code is never executed. It is never sent to any AI provider outside zero-retention terms. Deleted after 30 days. NDA signed before access.

Can’t I just run a free scanner?

Yes — and you should. Automated tools catch roughly the first layer. What they miss is authorization logic, multi-tenant isolation, and business logic — where the breaches in the news actually came from.

What if you find nothing?

You get a written report you can show enterprise prospects and investors, plus a hardening roadmap. In practice, finding nothing is rare.

What do I actually receive?

See the sample report — executive summary, severity-ranked findings with paste-back fix prompts, and a prioritized roadmap.

How fast, really?

48 hours from access granted, for the Launch Readiness Audit.

Contact

Request an audit

Prefer not to buy via Stripe yet? Send details and I’ll reply within 4 business hours. No sales call required.