Hardened

AI-built apps ship with holes. We close them before launch.

Hardened scans apps built with Lovable, Bolt, Replit, and Cursor. Every finding is manually verified. Every fix is reviewed by hand before your app goes live. No report goes out without human confirmation.

Built for AI-generated codebases. Works with apps built in Lovable, Bolt, Replit, and Cursor.

How it works

Four steps. A person on every one of them.

Scanners find candidates fast. A person decides what's real, what to fix, and how.

  • 01

    Scan

    Automated scanners crawl your app's code, dependencies, and endpoints for the issues that show up over and over in apps shipped straight from an AI builder: exposed keys, open database rules, missing auth checks, injectable inputs.

  • 02

    Review

    Every finding is checked by hand. Noise gets discarded. What's left is confirmed exploitable in your specific app before it's reported to you.

  • 03

    Fix

    We write and test the fix. Each patch is reviewed by hand before it touches your app.

  • 04

    Launch

    Once fixes are verified, we help you ship. You get a written record of what was found, what changed, and why.

Free scan

See what's in your repo

Point it at a public GitHub repository. Automated scanners do the work. We never store your source code or the findings. We keep your email and repo URL so we can follow up.

Pricing

One-time projects, priced per app.

Pick how far you want us to go. Every tier includes a full scan with every finding manually verified. See a sample report.

  • Report

    $199

    Find out what's wrong. We don't touch your code.

    • Full scan of your app
    • Every finding manually verified
    • Plain-English report
    • Step-by-step fix instructions
  • Fix

    $499

    Everything in Report, plus we fix what matters.

    • Everything in Report
    • All critical and high-risk issues fixed
    • Re-scan to confirm they're gone
  • Ship-It

    $849

    Everything in Fix, plus we put it live.

    • Everything in Fix
    • Deployment to your domain
    • Privacy policy added
    • Custom 404 page added
    • Cookie banner added
    • Handoff call
  • Recommended

    Ship-It Plus

    $1,199

    Everything in Ship-It, plus room to build.

    • Everything in Ship-It
    • Two features you choose from a menu
    • One round of revisions per feature
    • Full re-scan after the features are built

Ongoing monitoring

Optional subscriptions for apps that keep changing after launch.

Solo$39/mo

Ongoing scans for one app, with alerts when something changes.

Billed $39 per month. Renews automatically every month until you cancel.

Pro$79/mo

Ongoing scans with faster alerts and priority review of new findings.

Billed $79 per month. Renews automatically every month until you cancel.

First month free when bundled with Fix, Ship-It, or Ship-It Plus.

Cancel anytime from the billing page, or by emailing support@hardenedaisecurity.com.

We don't take on apps that store medical or financial account data.

No one can guarantee an app won't be hacked. We reduce risk. We don't eliminate it.

FAQ

Questions people ask

Do you only work with apps built using AI tools?

Apps built with Lovable, Bolt, Replit, Cursor, and similar tools tend to share the same handful of security gaps. Our scanners are tuned for those patterns. If your app was hand-coded, we can usually still help, but it isn't our focus.

What do your scans actually catch?

Exposed API keys and secrets, missing or misconfigured auth, open database rules, injectable inputs, unprotected admin routes, and the other issues that show up repeatedly in apps shipped straight from an AI builder.

Is any of this automated end-to-end?

The scanning is automated. Nothing else is. Every finding is manually verified before we tell you it's real. Every fix is reviewed by hand before it goes anywhere near your app.

Do I need to give you access to my code?

Yes — read access to your repository (or an export) is how we scan and fix your app. We don't need production database access or customer data to do the review.

How long does it take?

Most apps go from scan to launch-ready in a few business days. Larger or messier codebases take longer, and we'll tell you upfront which one you're in.