The Sunday Sprint
A weekend-sized course for people who shipped with AI. No security career required — plain-language lessons, copy-paste checklists, and audit prompts you hand straight to Cursor or Claude so your own assistant helps close the gaps it left.
One payment. No subscription. Yours forever, updates included. 14-day refund, no questions.
What's inside
Where keys actually belong, which ones are already burned, and the 15-minute rotation ritual.
Read your own app the way an attacker does: network tab, bundles, and the strings you didn’t mean to ship.
Login is not permission. Per-record access control, and the change-the-ID test that settles it.
Stop scripts from draining your API credits or brute-forcing logins — usually one evening of work.
Inventory the personal data you hold, delete what you don’t need, and know what the law already expects of you.
What your provider actually retains, and the test restore that turns hope into a plan.
Server-enforced prices and entitlements — a paywall that survives dev tools.
If something does go wrong: the incident checklist you’ll wish you had bookmarked.
RLS policies that actually restrict · the two keys · storage buckets
Rules that rule · ownership checks · storage & files
The NEXT_PUBLIC_ boundary · API routes that check · middleware truth-testing
Know your platform’s split · your three critical screens · your incident hour
The format
Short written lessons you can finish between coffees, each ending in a checklist you actually run. Every module ships with an AI audit prompt — paste it into your assistant, point it at your codebase, and make the tool that built your app help secure it.
The promise — and its limits
Finish your track in a weekend and you'll have closed the gaps that cause the overwhelming majority of vibe-coded app breaches. What we won't promise: that anything makes your app unhackable. Nothing does, and nobody honest says otherwise.
Haven't taken the free Exposure Check yet? Start there — it maps your findings to exact modules.