The Sunday Sprint

Everything on your list,
fixed by Sunday night.

A weekend-sized course for people who shipped with AI. No security career required — plain-language lessons, copy-paste checklists, and audit prompts you hand straight to Cursor or Claude so your own assistant helps close the gaps it left.

The scan and the check are free and stay free. This is the other half — and it isn't one report about one app. The prompts and the modules work on the next thing you build too.

One payment, no subscription. Access for at least 12 months. Seven days to change your mind.

What's inside

Or compare it against what the free check gives you →

Eight core modules. Your stack's track. Zero filler.

Core 1 · Secrets & Keys

Where keys actually belong, which ones are already burned, and the 15-minute rotation ritual.

Core 2 · What the Browser Sees

Read your own app the way an attacker does: network tab, bundles, and the strings you didn’t mean to ship.

Core 3 · Authn vs Authz

Login is not permission. Per-record access control, and the change-the-ID test that settles it.

Core 4 · Abuse & Rate Limits

Stop scripts from draining your API credits or brute-forcing logins — usually one evening of work.

Core 5 · Your Data Liability

Inventory the personal data you hold, delete what you don’t need, and know what the law already expects of you.

Core 6 · Backups & Recovery

What your provider actually retains, and the test restore that turns hope into a plan.

Core 7 · Payments That Hold

Server-enforced prices and entitlements — a paywall that survives dev tools.

Core 8 · The First Hour

If something does go wrong: the incident checklist you’ll wish you had bookmarked.

Then go deep on your stack

These five get step-by-step, vendor-specific instructions. On anything else — AWS, a server you run yourself — the eight core modules and the audit prompts still apply, but you’d be adapting the specifics. Worth knowing before you buy rather than after.

The five standalone audit prompts — one per stack — are free, right here, and you don't need this page to use them. The Sprint adds what comes next: afix prompt and a proof prompt in every module, plus the one built from your own scan and answers.

Supabase

RLS policies that actually restrict · the two keys · storage buckets

Firebase

Rules that rule · ownership checks · storage & files

Next.js / Vercel

The NEXT_PUBLIC_ boundary · API routes that check · middleware truth-testing

Lovable / Bolt / v0 / Base44 / Replit

Know your platform’s split · your three critical screens · your incident hour

Azure

Row-level security that runs · account keys vs SAS · the container listing switch

The format

Short written lessons you can finish between coffees, each ending in a checklist you actually run. Every module ships with an AI audit prompt — paste it into your assistant, point it at your codebase, and make the tool that built your app help secure it.

The promise — and its limits

Finish your track in a weekend and you'll have closed the gaps that cause the overwhelming majority of vibe-coded app breaches. What we won't promise: that anything makes your app unhackable. Nothing does, and nobody honest says otherwise.

Want a human to sign off?

The Sunday Review — $149

You do the Sprint, re-scan, and send me what you changed. I read it myself, write back within five days, and put my name on a dated note you can hand an investor or a customer. It includes the Sprint. It is not a penetration test, and I don't promise you're safe.

See what the Review covers →

$39. One weekend.
No more wondering.

Get the Sunday Sprint — $39

Haven't run the free Exposure Scan yet? Start there — it maps what it finds to exact modules.