The Sunday Sprint
A weekend-sized course for people who shipped with AI. No security career required — plain-language lessons, copy-paste checklists, and audit prompts you hand straight to Cursor or Claude so your own assistant helps close the gaps it left.
The scan and the check are free and stay free. This is the other half — and it isn't one report about one app. The prompts and the modules work on the next thing you build too.
One payment, no subscription. Access for at least 12 months. Seven days to change your mind.
What's inside
Or compare it against what the free check gives you →
Where keys actually belong, which ones are already burned, and the 15-minute rotation ritual.
Read your own app the way an attacker does: network tab, bundles, and the strings you didn’t mean to ship.
Login is not permission. Per-record access control, and the change-the-ID test that settles it.
Stop scripts from draining your API credits or brute-forcing logins — usually one evening of work.
Inventory the personal data you hold, delete what you don’t need, and know what the law already expects of you.
What your provider actually retains, and the test restore that turns hope into a plan.
Server-enforced prices and entitlements — a paywall that survives dev tools.
If something does go wrong: the incident checklist you’ll wish you had bookmarked.
These five get step-by-step, vendor-specific instructions. On anything else — AWS, a server you run yourself — the eight core modules and the audit prompts still apply, but you’d be adapting the specifics. Worth knowing before you buy rather than after.
The five standalone audit prompts — one per stack — are free, right here, and you don't need this page to use them. The Sprint adds what comes next: afix prompt and a proof prompt in every module, plus the one built from your own scan and answers.
RLS policies that actually restrict · the two keys · storage buckets
Rules that rule · ownership checks · storage & files
The NEXT_PUBLIC_ boundary · API routes that check · middleware truth-testing
Know your platform’s split · your three critical screens · your incident hour
Row-level security that runs · account keys vs SAS · the container listing switch
The format
Short written lessons you can finish between coffees, each ending in a checklist you actually run. Every module ships with an AI audit prompt — paste it into your assistant, point it at your codebase, and make the tool that built your app help secure it.
The promise — and its limits
Finish your track in a weekend and you'll have closed the gaps that cause the overwhelming majority of vibe-coded app breaches. What we won't promise: that anything makes your app unhackable. Nothing does, and nobody honest says otherwise.
Want a human to sign off?
You do the Sprint, re-scan, and send me what you changed. I read it myself, write back within five days, and put my name on a dated note you can hand an investor or a customer. It includes the Sprint. It is not a penetration test, and I don't promise you're safe.
See what the Review covers →Haven't run the free Exposure Scan yet? Start there — it maps what it finds to exact modules.