Kavach

For founders, indie hackers and agencies shipping AI-generated apps

Built your app with AI? Hosted it? Now find out if it is actually secure.

Lovable, Bolt, v0, Replit, Cursor, Claude Code, Windsurf or Base44 wrote the code, picked the defaults and pushed it live. Nobody with a security background read a line of it. Kavach audits the live site the way an attacker would, grades it, and hands you fixes you can paste straight back into your AI tool. Nothing is attacked.

Audit my AI-built app free → See plans

Reviewed? Secure? Still in doubt?

An AI assistant optimises for "it works". It will happily open CORS to the world, leave the session cookie unflagged, skip the Content-Security-Policy and deploy the .env file along with everything else, because none of that stops the demo from running. These are not exotic bugs. They are the defaults, and they are visible from outside.

What usually slips through

How it works

  1. Paste the live URLNo install, no code access, no agent. Kavach only looks at what the public internet can already see.
  2. Get a letter grade in secondsEvery finding comes with the plain-English attack it enables and a severity, weighted for AI-built apps.
  3. Paste the fix back into your AI toolThe Fix Pack is copy-paste config for your stack. Give it to the same assistant that built the app and re-scan.
  4. Keep it that wayVerify the domain, schedule re-scans, and get an alert the moment a new prompt or deploy opens something up.

Also scan the code itself

The live-site audit sees what an attacker sees. Code Scan looks at what the AI wrote: zip the project, upload it, and Kavach streams through every file for string-built SQL, shell commands with user input, unescaped output, credentials in source, wide-open CORS, disabled TLS checks, unsafe deserialisation, debug left on and platform rules (Firebase, Supabase) that let everyone in. Any language, hundreds of thousands of lines, nothing extracted to disk, and the archive is deleted the moment the scan ends. You get a graded report and a remediation prompt to paste into the same AI tool. On any finding you can also Ask Kavach AI: a second opinion (likely real or likely false positive) and a draft of the fixed line. Only that one excerpt is processed, by a model on our own server or by an inference provider that does not train on your data; the answer says which.

Scan my code →

What Kavach does not do

Kavach does not log in, does not test business logic and does not submit data to your forms. The live-site audit is a non-destructive, external check of the controls that stop the most common attacks on AI-built apps; Code Scan is pattern-level static analysis, not a line-by-line human review. A good grade is necessary, not sufficient. Results are observations, not certifications or guarantees; see the disclaimer.

Questions founders ask

Does Kavach review my code?

Two ways. The live-site audit never needs your repository, hosting login or API keys, so it works even for platforms that do not hand you the code. Code Scan takes a zip of the project and runs pattern-level static analysis across every file; the archive is deleted as soon as the scan finishes and only the findings are kept.

Is the scan safe to run on my live app?

Yes. Every check is read-only: it fetches pages and headers, inspects TLS and DNS, and looks for files that should not be public. Nothing is submitted, brute-forced, fuzzed or taken down. Checks that could reveal secrets (.env, .git) only run after you prove you own the domain, and Kavach never stores what it finds there.

I do not understand security terms. Will the report make sense?

That is the point. Each finding says what it is, why it matters, what an attacker would do with it, and the exact text to paste into your config or back into your AI assistant.

Will an A+ mean my app is secure?

No tool can promise that, and Kavach does not. An A+ means the externally visible controls are in place. Authorisation bugs, business-logic flaws and anything behind a login are outside what a non-destructive external scan can see. Treat the grade as the first gate, not the last word.

Can I use it on an app I built for a client?

Yes, if you are authorised to test it. Agencies get client rooms, white-label PDF reports and a public Trust Passport page they can hand to the client.

Scan your site free → Monitor it continuously