Developer field guide

Spend one evening closing the five doors real breaches walk through — and see for yourself that they're shut.

Is It Safe to Launch? — A Plain-Language Security Check for Your AI-Built App

24 pages Screen-friendly A5, prints on A4 and US Letter Read on screen, or print Last reviewed July 2026 Version 2026-07

You built something real by talking to an AI, and now there is an app with your name on it — sign-ups, maybe a database, an API key with your card behind it. This 24-page evening's work walks you through five security checks — the same five unlocked doors behind 2026's real breaches — without assuming you can read a line of code: you ask your assistant to do the technical part, then verify the result with your own eyes, in a browser or a dashboard.

Buy now · $11.24

Instant PDF download after checkout on Payhip. Nothing is shipped.

Cover of Is It Safe to Launch?
Previews show each page at reduced resolution; the download is the full print-quality PDF.
Cover of Is It Safe to Launch?
1 / 4

What's inside

  • What Actually Leaks — 2026's public breaches told plainly: the Moltbook leak, the Tea storage-bucket exposure, and the Lovable CVE across 170+ apps — and the five doors they all walked through
  • Check One — Secrets: finding keys in the code your page ships to browsers (the F12 search), in your project's git history (the free gitleaks scanner), and keys that can do too much — plus the spend caps and scoped keys that shrink a future leak
  • Check Two — Who Can Read Your Data: row-level security explained in plain words, the Supabase Security Advisor and Firebase Rules screens, and the "stranger test" — three logged-out probes that settle who can actually read your database
  • Check Three — What Users Can Send You: two magic strings that reveal cross-site scripting in about two minutes, the questions to ask about file uploads, the public form that quietly spends your API budget, and prompt injection when user text reaches a model
  • Check Four — Dependencies, and the packages that don't exist: running the free vulnerability audit, then "slopsquatting" — the invented package names AI assistants predictably suggest — and how to read a package's registry page letter by letter
  • Check Five — Blast Radius: a written inventory of what you actually store, the deletion that is the cheapest security work there is, moving passwords and card data off your own tables, and the backup you have actually restored once
  • The Self-Audit — and Checking It: the prompt that has your assistant audit its own work, the three structural reasons you never stop there, and the independent second pass
  • The Launch-Evening Checklist: all five checks on one page, each with its pass condition — for tonight, and for every relaunch and big feature
  • What a Checklist Can't Catch: the honest limits of one evening, and the thresholds where a paid penetration test becomes due diligence rather than luxury
  • A plain-language glossary of every term used — secret, row-level security, storage bucket, stranger test, XSS, prompt injection, slopsquatting, blast radius, pentest

Who it's for

  • Non-developers about to put an AI-built app in front of strangers
  • Anyone with sign-ups, a database, or an API key with their card behind it

Who it's not for

  • Anyone holding regulated data or moving real money — the book itself says that is when a paid penetration test becomes due diligence
  • Anyone wanting a promise of safety — following every check reduces risk; nothing eliminates it

Every scanner and dashboard it reaches for is free — gitleaks, the npm and pip dependency audits, Cloudflare Turnstile, and Supabase's Security Advisor cost nothing. Some free tiers have honest edges the book flags in writing: GitHub's secret scanning is a paid add-on on private repositories, and some plans reserve automatic backups for paid tiers. Breach accounts, dashboard names, free tiers, and prices were last reviewed July 2026; where the book and a platform's current documentation disagree, the documentation is right. Following every check reduces risk; nothing eliminates it, and no book can promise your app is safe.

Guidance, not gospel — this is a practical organisation tool, not legal, tax, medical, or religious authority.

Held to The CalmKit Standard

Last reviewed July 2026 ·

Drafted with AI assistance and then reviewed and curated by a real person who's been through it.

Where rules can change, this guide points you to the source that decides:

  • GitHub
  • Supabase

What the Standard commits us to →

Is It Safe to Launch?
24 pages · Instant PDF · $14.99$11.24