Free · read-only · results in about a minute

See exactly what your app is exposing.

Built your app on Lovable? Get a free, read-only production audit in plain English — a stranger’s-eye view of your app, with the proof, so you can fix what matters before your customers find it.

No login to start. We only look — we change nothing.

Read-only We never see your secret keys Insured, real company You own everything
Why this matters

Apps built fast can leak in ways you’d never see.

Tools like Lovable let you ship a real app in days — that’s the point, and it’s great. But the same speed can leave the back door open in ways that look completely normal from the front. Here are three we find often.

Customer records anyone can read

A misconfigured database can hand your full customer list — names, addresses, invoice amounts — to anyone with the web address. No login required.

Private files that can be listed

Contracts, photos, and invoices your customers uploaded can sometimes be listed and fetched by name — by people who were never meant to see them.

Payments that can be faked

If a payment webhook isn’t verifying its sender, someone can fake a “paid” signal and mark invoices settled without any money arriving.

How it works

Paste your address. Read what we found. Fix what matters.

No install, no account to start, nothing to configure. The whole first pass takes about a minute.

STEP 01

Paste & scan

Drop in your app’s web address. We look at it from the outside, exactly the way anyone on the internet could — read-only.

Always free
STEP 02

Read it in plain English

Get a calm, scannable report. Every finding says what it is, what it means for your business, and comes with the actual proof — no jargon, no scare tactics.

STEP 03

Verify to see full proof

Confirm you own the app to unlock the checks we won’t run on someone else’s live site. Then, if you want, we fix the serious items for a fixed price.

What we check

A stranger’s-eye view of the things that actually go wrong.

We focus on the exposures that hurt small businesses — the ones that leak data, files, or money — not a 200-item checklist you’ll never read.

Secure connection

Is traffic encrypted and protected from downgrade (HTTPS, HSTS, TLS)?

Who can read your data

Can a stranger query your database tables directly, with no login?

File storage exposure

Can uploaded contracts, photos, and invoices be listed or fetched?

Payment exposure

Does your payment webhook verify who’s really sending it?

Backups & recovery

If something goes wrong, is there a snapshot to restore from?

Keys left in the open

Are any powerful keys accidentally shipped in your app’s page source?

See the proof

Every finding comes with real evidence.

This is what a serious finding looks like in your report — plain enough for you, concrete enough for whoever helps with your app. (Values are always mocked and redacted; we never show real customer data.)

Exposed Confirmed · read-only

Anyone can read your customer records

What we found
Evidence · captured on your scan · read-only probe customers table
# A request anyone on the internet can make — no login, no key of yours:
GET /rest/v1/customers?select=* HTTP/2

HTTP/2 200 OK
content-range: 0-999/4,214   ← 4,214 customer rows returned to a stranger
  { "name": "xxxxxxxxxxx", "address": "xxxxxxxx, Worcester, MA",
    "balance_due": "$x,xxx.00" }, … 4,213 more
Values are mocked and redacted. We never store, display, or keep your customers’ real data.

Anyone with the web address can pull your full customer list — every name, home address, and invoice amount — without logging in.

Want to see the whole thing? Here’s a full sample report.View a sample report
Why you can trust it

A careful, honest second opinion — not a scare tactic.

We’re an independent assessment, built to be forwarded to whoever helps with your app. Here’s the deal, plainly.

Read-only, always

We look at what’s already public, the way anyone could. We never log in, change, or download anything.

We never see your keys

Your secret keys stay yours. Every piece of evidence in your report is mocked and redacted.

An honest snapshot

Every report says what we tested and what we didn’t — no grade to game, no false “all clear.”

A real person answers

ZB is a real, insured company. Reply to any report and Dana — a human — answers, usually same day.

Pricing

The diagnosis is free. The fix is a fixed price.

We tell you exactly what’s wrong for nothing. If you want us to fix the serious items, we quote a flat price up front — no hourly billing, no surprises. No pressure either way; the report is yours to keep.

The auditFree

Everything you need to understand your risk, in plain English.

  • Full plain-English findings
  • Real, redacted proof for every finding
  • An honest scope box — what we tested and didn’t
  • A shareable report, built to forward

No login to start. Yours to keep, whatever you decide next.

The fix$1,900 flat, typical

Optional. We close the serious items cleanly, without breaking your app.

  • We fix the critical exposures first
  • Before/after proof each item is closed
  • You own everything — leave anytime, no retainer
  • Backed by a real, insured company

Fixed price quoted up front after your audit. Typical jobs land around $1,900. If you later want us to keep watching it for you, that’s a simple monthly option — never required.

Questions

The things people ask first.

Is it safe to run this on my live app?
Yes. The whole audit is read-only — we look at what’s already public from the outside, exactly the way any visitor could. We don’t log in, we don’t change anything, and we don’t download your files or records.
Do you see my customers’ data or my secret keys?
No. We never touch your secret keys, and every piece of evidence in your report is mocked and redacted — we show that a problem exists (like a row count or an endpoint) without ever displaying real customer information.
What if the app isn’t mine?
The free result only uses what’s already public. Anything that would touch a live app more directly — like confirming a payment webhook — stays locked until you verify you own it. It’s the same read-only promise, applied to your money.
Do I have to pay for the fix?
Never. The audit is free and the report is yours to keep. If you’d like us to fix the serious items, we quote a flat price up front — but plenty of people take the report to their own developer, and that’s completely fine.
Are you part of Lovable?
No — we’re independent and not affiliated with Lovable. We think Lovable is a great way to build; we’re just a careful second opinion on what your finished app exposes to the world.
Who’s behind this?
ZB Production Audit is a real, insured company. Every report is signed by a named person — Dana Ortiz — who reads and answers replies directly, usually the same day.
From the founder
DO

“I started ZB after watching great little businesses get burned by apps that looked finished but quietly leaked. You shouldn’t need to be technical to know whether your customers’ information is safe. So we made the check free, wrote it in plain English, and put the proof right next to it — so you, and whoever helps with your app, can both see exactly what’s going on.”

Dana Ortiz — Founder, ZB Production Audit · real person, replies to you directly · insured

See what your app is showing strangers.

Free, read-only, and about a minute. Paste your address and find out — before your customers do.

Read-only No login to start Insured & independent