Everyone is obsessed with how fast tools like Cursor, Claude Code, Replit and Lovable let you ship apps.
But almost nobody is asking the obvious question: Can your users see someone else's data?
Most vibe-coded apps have thousands of permission combinations across roles, APIs, pages, and databases. AI is great at building features, but it doesn't automatically guarantee that every authorization check is correct.
Thanks for making this app really good for people like me that like to (vibe code) build/test apps. I use cursor to build the app and i use other tools, like @Snyk, @CodeRabbit to check if there are some vulnerability in the code, and your app is a great addition to my security check stack.
Thanks again.
P.S. I just tested one of my apps, and all good. 😌
This is exactly the gap in a lot of AI-built apps: the UI looks done before authorization, tenancy, and data boundaries have really been exercised. I like that you are testing the app as a running system instead of just scanning source. For founders, the useful output is not only "found a bug" but "can I ship this change without reopening the same class of door?"
Qutub, that little knot of worry right after you ship something fast is so familiar. Having something quietly watching your back so you can actually breathe afterward feels genuinely kind to the people building.
Release AI
@benjamin_riou
Thank you for putting it that way. That knot of worry is exactly what we're trying to untie.
Shipping fast should feel exciting, not scary. But so many builders hit publish and then lie awake wondering what they missed. Nobody should need a security team just to breathe after launch. That's the whole reason Perfai exists: something quietly watching your back, testing every update, catching the gaps before anyone else does.
Comments like this remind us why we build. Thank you.
If you ever ship something, the free tier at perfai.ai is there, with a full pentest-style report and drift detection as your app grows. We're giving away 50% discount codes for the launch too. And if you need extra credits or help onboarding, just reach out. Happy to help!