SecurityBeveiliging

AI-built apps and websites still need real security.AI-gebouwde apps en websites hebben nog steeds échte beveiliging nodig.

AI-tools optimise for working code. They don't optimise for code that's safe in the wild. That's our job — scan, fix and protect before launch.AI-tools mikken op werkende code. Wat overblijft is alles wat er níét in zit: veilige defaults, eigen authenticatie, een firewall. Dat regelen wij voor live gaan.

ziptolive · scan results · myapp.zipziptolive · scanresultaten · mijnapp.zip
OpenAI API key in src/config.jsOpenAI-API-sleutel in src/config.jscriticalkritiek
Postgres connection string in .env (committed)Postgres-connection-string in .env (gecommit)criticalkritiek
Login endpoint has no rate limitLogin-endpoint heeft geen rate limithighhoog
/admin reachable without auth/admin bereikbaar zonder authhighhoog
7 dependencies have known CVEs7 dependencies hebben bekende CVE'smediummiddel
HTTPS redirect configuredHTTPS-redirect geconfigureerdokok
Security headers presentBeveiligingsheaders aanwezigokok
CORS configured correctlyCORS correct geconfigureerdokok
Common patternsVeelvoorkomende patronen

What we look forWaar we naar kijken in elke scanin elke scan.

None of these are intentional. They're the side effects of AI tools generating "code that runs" without a model of what an attacker would try.Geen daarvan is opzet. Het zijn de bijwerkingen van AI-tools die "code die draait" genereren zonder een idee van wat een aanvaller zou proberen.

Secrets hardcoded in the codeSecrets hardcoded in de code

API keys, database URLs and signing secrets baked straight into HTML or JS source — public the moment the site goes live. We catch them before the launch tweet.API-sleutels, database-URL's en signing-secrets direct in de HTML of JS, publiek vanaf het moment dat de site live gaat. Wij vangen ze voor de launch-tweet.

No rate limitingGeen rate limiting

Login forms, password resets and contact endpoints with no throttling. Once your URL is public, automated bots find them within hours.Login-formulieren, password-resets en contact-endpoints zonder throttling. Zodra je URL publiek is, vinden geautomatiseerde bots ze binnen uren.

Our approachOnze aanpak

Automated scans, thenAutomatische scans, daarna a human reads the reportleest een mens het rapport.

Scanners catch the known patterns. A person catches the strange ones — like the AI-generated migration that drops your users table on every deploy.Scanners pakken de bekende patronen. Een mens pakt de vreemde, zoals de door AI gegenereerde migratie die je users-tabel dropt bij elke deploy.

1

Automated scanAutomatische scan

Code scan, dependency check and security headers, on every release push.Code-scan, dependency-check en beveiligingsheaders, bij elke release-push.

2

Manual reviewHandmatige review

An engineer reviews authentication, authorisation, data handling and anything the scanner flagged ambiguously.Een engineer reviewt authenticatie, autorisatie, dataverwerking en alles wat de scanner als dubbelzinnig markeerde.

3

Custos firewallCustos firewall

After launch, Custos — our own application firewall — keeps an eye on incoming traffic. Bots, brute-force attempts and known bad signatures get filtered before they reach your code.Na launch let Custos, onze eigen application firewall, op binnenkomend verkeer. Bots, brute-force-pogingen en bekende slechte signatures worden gefilterd voor ze je code raken.

Get a security scanVraag een beveiligingsscan aanbefore you launch.vóór je live gaat.

Send your ZIP or repo. You'll get a scan report within 24 hours — even if you don't move forward with ZipToLive.Stuur je ZIP of repo. Je krijgt binnen 24 uur een scanrapport, ook als je niet verdergaat met ZipToLive.