Example · made-up app, not a real client
What the report says about your app.
A made-up AI-generated app, a services marketplace. The report shows what we found, in what order to fix it and one recommendation.
Before GET /api/customers · signed out 200 OK[ { "name": "Ana M.", "email": "ana@example.test" }, { "name": "Rui P.", "email": "rui@example.test" }, … ]After the fix GET /api/customers · signed out 401 Unauthorized
Made-up data. Anyone, without signing in, could download the customer list. After the access rule, the same request is refused.
Findings
From most to least severe
6 findings, 8.5 days of work in the example. Open one to see what we saw, the effect and the fix.
1Tables readable without signing inCritical2 days
What we saw. The public API returns the customer list with no credential.
Effect. Anyone downloads the personal data of every customer.
Fix. Turn on row-level access rules and test with and without signing in.
2Secret payment key in the browser codeHigh1 day
What we saw. The key appears in the bundle the browser downloads.
Effect. Anyone who opens the inspector can use the payments account.
Fix. Replace the key and move the call to the server.
3Release straight to production, no testsHigh3 days
What we saw. Every change from the generator goes live at once.
Effect. A generator mistake takes the app down for every customer.
Fix. A test environment, minimal tests and an approval before production.
4Payment notice accepted without checking the signatureMedium1 day
What we saw. The address that receives the notice accepts any call.
Effect. Someone can mark an order as paid without paying.
Fix. Check the provider's signature on every notice.
5No database copy that can be restoredMedium1 day
What we saw. There is no scheduled copy and no restore test.
Effect. A data mistake cannot be undone.
Fix. A daily copy and one tested restore.
6No alert if the app goes downLow0.5 days
What we saw. Nobody is told when the app stops.
Effect. The customer finds out before you do.
Fix. An external check and an email alert.
Recommendation
Two paths, one choice
The decision is yours. The report recommends one, in writing.
Recommended
Harden
Keeps the stack and closes the holes.
- The structure holds today's product
- The flaws are configuration, not design
- 8.5 days of work, in the example
If the product changes
Rebuild
Moves to a standard stack built to reach a million users.
- Makes sense if the next feature needs a different data model
Why the diagnosis starts with access rules: CVE-2025-48757 records apps generated by an AI builder whose database tables could be read and written without signing in. The record at NVD
Your diagnosis, on your app.
One discovery week, one report, one recommendation.