Assurly
Find the security holes in your live app before strangers do. Ask Claude "Is my app safe to launch?" with your URL, and Assurly scans the deployed app from the outside, the way anyone on the internet sees it. It is built for apps made with AI builders and coding agents such as Lovable, Bolt, v0, Replit and Cursor, where secret keys and database access often end up in public code. What Assurly finds • Leaked secret keys in your page or JavaScript bundle: Stripe secret keys, AWS access keys, Google API keys and Supabase service-role keys • An exposed Supabase database: your public key reaches it straight from the browser, the setup where a single table without row-level security (RLS) leaks user data • Missing security headers: Content-Security-Policy, Strict-Transport-Security and X-Content-Type-Options • A dead or broken deployment that should not get a green light What you get • A ship verdict: Ready to ship, Review recommended or Not ready to ship • A Ship Score from 0 to 100 • For every problem, what it means for your users and a concrete fix, including the exact headers to add on Vercel Try asking • "Is my Lovable app safe to launch? my-app.lovable.app" • "Scan my site for leaked API keys before I go live" • "I rotated the key and redeployed. Check again." Safe by design The scan is passive and needs no signup. Assurly loads your public page and scripts like a browser does; it never logs in, submits forms or reads your data. When a firewall or deployment protection keeps it from seeing the app, it says so instead of guessing. To prove whether your Supabase tables are actually readable, verify ownership at assurly.dev and run the full active test there.
Details
https://assurly.dev/api/mcp · streamable-http
