Skip to content
ballastGet access

Managed security reviews for AI‑generated code

AI built your app. Who checked it?

Ballast finds the mistakes AI coding tools ship with, like leaked keys, open databases and endpoints that can run up your bill. Each one comes in plain English, with a fix you paste straight back into your AI.

Early access is by request. Once approved, you install our read-only GitHub App in a few clicks. admin@hoangtran.site

  • Read-only GitHub App
  • Checks on every pull request
  • Findings verified by an engineer

acme-portal

  1. Scanning frontend code for secrets1 admin key exposed
  2. Checking database access rules3 of 12 tables open
  3. Testing API routes for login checks1 route unprotected
  4. Checking storage bucketsAll private
  5. Checking limits on AI endpointsNo limit on /api/chat
  6. Checking backups and dependenciesNo backups set up

Launch readiness

38/ 100

Not ready to launch, 3 critical, 2 high, 1 medium

6 fix prompts ready

Sound familiar?

The four worries we hear most from people shipping with AI, and what Ballast does about each one.

  • I can’t read the code, so I have no idea what’s exposed.

    Plain-English report

    Every finding says what’s wrong, what someone could do with it, and how urgent it is. No security background needed.

  • I’m scared of waking up to a $2,000 API bill.

    Cost guard

    We flag AI and API endpoints anyone can call without limits, and Pro alerts you the moment spend suddenly jumps.

  • Every time I ask the AI for a feature, something else breaks.

    Checks on every pull request

    Pro checks every pull request before it merges, so a fix that quietly comes undone is caught before it ships.

  • I’m launching next week and there’s no developer to ask.

    Ultra: engineers on hand

    On Ultra, our engineers walk through the report with you and fix the critical and high issues for you.

How Ballast works.

Request access, install a read-only GitHub App, and Ballast checks every change before it ships, with an engineer verifying what matters.

  1. 1

    Request early access

    Email admin@hoangtran.site with your app’s link and repository. We confirm you own the app, usually within one business day.

  2. 2

    Install the GitHub App

    Install the GitHub App with read-only access and choose your repositories. For live tests, add your project URL and public ballas key. We never ask for service-role keys.

  3. 3

    Checks on every pull request

    Ballast reviews your app in three layers. Code checks run on every pull request, and an engineer verifies live-app and access findings before they reach you.

    • CodeEvery pull request: secrets, vulnerable dependencies and risky patterns.
    • Live appOutside-in tests, such as reading tables with your public key, open storage and exposed files.
    • Access testsTwo test accounts check whether one user can see another’s data.
  4. 4

    Fix and verify

    Fix prompts appear right on the pull request with Pro. On Ultra, your engineer consultant opens a fix pull request for you to approve. The next check confirms the fix.

CriticalFound by: Live app testVerified by an engineer

Row-level security is off on the invoices table

Anyone with your public key can read every customer’s invoices.

Paste into Lovable, Cursor or Bolt

Enable row-level security on the invoices table in Supabase. Add policies so a signed-in user can only select, insert, update and delete rows where user_id = auth.uid(). Don’t change any other tables. When you’re done, show me the SQL you ran.

Fix prompts are included with Pro. Pull requests from your engineer consultant come with Ultra.

What Ballast checks.

Grouped by what could actually go wrong, not by security jargon. Free covers the three that leak data most often. Pro and Ultra run all eight.

  • Leaked secrets

    In Free

    API keys and admin credentials in your frontend code or repo history.

    Risk: Someone uses your keys, and your bill.

  • Database access rules

    In Free

    Row-level security turned off, or rules that let any user see every row.

    Risk: Anyone can read or edit your users’ data.

  • Missing login checks

    API routes and server functions that never check who’s calling.

    Risk: Users can open each other’s orders, invoices or messages.

  • Public storage

    In Free

    Upload, avatar and document buckets that anyone can list.

    Risk: Private files end up downloadable by strangers.

  • Unlimited AI endpoints

    Chat or generation endpoints with no rate limit or spending cap.

    Risk: One script burns your monthly LLM budget overnight.

  • Prompt injection

    User text that can rewrite your AI’s instructions or reach your tools.

    Risk: Your assistant leaks data or does things it shouldn’t.

  • Risky dependencies

    Packages with known vulnerabilities or no maintainer.

    Risk: Attackers use a published exploit against you.

  • Launch basics

    Backups, error monitoring, and separate test and live data.

    Risk: One bad AI edit wipes real data with no way back.

Why not just use a code scanner?

Developer scanners read your code. Ballast checks what a stranger can actually reach in your live app, and explains how to fix it in words you understand.

Built for

Developer scannersDevelopers and DevOps teams

Built-in builder checksUsers of that one platform

BallastFounders and builders, no code knowledge needed

What it examines

Developer scannersCode, dependencies and containers

Built-in builder checksSettings inside its own platform

BallastYour code plus your live backend: database rules, storage and logins

Tests what an outsider can reach

Developer scannersNot the main focus

Built-in builder checksUsually confirms a setting is on

BallastYes, by testing access the way an outsider would

AI-specific risks (LLM costs, prompt injection)

Developer scannersNot the main focus

Built-in builder checksLimited

BallastBuilt into the 8 checks

Setup

Developer scannersCLI or CI pipeline, plus rule tuning

Built-in builder checksAlready built in

BallastInstall a read-only GitHub App. We handle the rest

Results

Developer scannersLong lists of technical alerts

Built-in builder checksAlerts in a dashboard

BallastA short, ranked list in plain language, with fix prompts

Human help

Developer scannersYour own team

Built-in builder checksYour own team

BallastEngineer consultant on Ultra

Already use Snyk or SonarQube? Keep them. Ballast covers what they weren’t built to see.

Based on each category’s typical focus. Individual tools vary by plan and configuration.

A report you can actually read.

Switch between before and after to see the score climb as fixes go in.

38out of 100

Not ready to launch

acme-portal

  • Admin database key is in your frontend code

    Anyone who opens your site can copy it and get full control of your database.

    CriticalFixed
  • Row-level security is off on 3 tables

    invoices, profiles and messages can be read by anyone with your public key.

    CriticalFixed
  • Anyone can open other users’ orders

    Changing the number in /api/orders/123 shows a stranger’s order.

    HighFixed
  • No rate limit on /api/chat

    A simple script could spend your monthly OpenAI budget in an hour.

    HighFixed
  • No database backups set up

    If an AI edit deletes data, there’s no copy to restore.

    MediumFixed
  • 2 packages with known vulnerabilities

    Low risk today. Update them when convenient.

    Low

Sample report. Illustrative findings from a typical AI-built app.

Start free, upgrade when you need more.

Each plan includes everything in the one before it. Early access pricing: request access by email, then install the GitHub App.

  • Free

    A security baseline before you launch.

    $0forever

    • 1 app monitored
    • Monthly security scan
    • 3 core checks: secrets, database access and storage
    • Launch-readiness score
    • Plain-language findings report
  • Early access price

    Pro

    Continuous protection as you keep shipping with AI.

    $19per month

    Everything in Free, plus

    • Up to 3 apps monitored
    • Checks on every pull request, plus unlimited scans
    • All 8 security checks
    • AI-ready fix prompt for every finding
    • Alerts for new critical issues
    • Pre-launch readiness checklist
    • LLM and API spend monitoring (coming soon)
  • Ultra

    Hands-on help from our security engineers.

    $199per month

    Everything in Pro, plus

    • Up to 10 apps monitored
    • Engineer consultant who fixes critical and high findings through pull requests
    • Monthly 45-minute security review call
    • Security sign-off letter for customers and investors
    • Priority support with same-business-day response

Compare plans

FeatureFreeProUltra
Apps monitored1310
Scan frequencyMonthlyUnlimitedUnlimited
Security checks3 coreAll 8All 8
Plain-language findings reportIncludedIncludedIncluded
AI-ready fix promptsNot includedIncludedIncluded
Checks on every pull requestNot includedIncludedIncluded
Alerts for new critical issuesNot includedIncludedIncluded
Engineer consultantNot includedNot includedIncluded
Monthly review call and sign-off letterNot includedNot includedIncluded
Support levelStandardStandardPriority

Prices in USD. Cancel paid plans anytime. To start any plan, email admin@hoangtran.site.

We’re careful with your app, too.

  • Read-only by default

    The GitHub App only reads the repositories you choose. Write access is needed only for Ultra fix pull requests, and only if you turn them on.

  • Scanned, then deleted

    Code is scanned in an isolated environment and removed after your report. Ask us to delete your data anytime.

  • Every permission shown

    GitHub lists exactly what the Ballast App can access before you install it, and you can remove it at any time.

  • Real engineers behind it

    Built by a team that builds and secures AI systems for small companies.

Frequently asked questions.

How do I get started?

Email admin@hoangtran.site with a link to your app and repository. We confirm you own the app, then send an invitation to install the GitHub App. Your first report arrives within 24 hours of installation.

What do I need to install?

Only the GitHub App, installed from GitHub in a few clicks once your early access is approved. It has read-only access to the repositories you select. There is nothing to download and no separate account to manage. Results appear on your pull requests and in an emailed report.

How do Free, Pro and Ultra differ?

Free covers one app with a monthly scan across the three core checks. Pro covers up to three apps, runs all eight checks on every pull request and includes an AI-ready fix prompt for each finding. Ultra adds an engineer consultant who fixes critical and high findings through pull requests, along with a monthly security review call and a sign-off letter.

Do I need technical knowledge to use Ballast?

No. Every finding is written in plain language, with a clear explanation of the risk and how urgent it is. Pro and Ultra also include a fix prompt you can paste directly into the AI tool you already use.

Will Ballast make changes to my code or data?

Scanning is strictly read-only. On Free and Pro, you decide which fixes to apply and when. On Ultra, our engineers submit fixes as pull requests, and nothing is merged without your approval.

How do you handle my code and data?

Access is limited to what the scan requires, and you approve every permission before we connect. Code is scanned in an isolated environment and removed once your report is delivered. You can ask us to delete your data at any time.

My builder already includes a security scan. Why do I need Ballast?

Built-in scans are a useful first step, but they typically confirm that a setting is enabled rather than whether it actually protects your data. Ballast tests what an outsider could access in practice.

How does Ballast compare with Dependabot or Snyk?

Those tools are built for developers and focus mainly on code and third-party packages. Ballast also tests your live backend configuration and AI endpoints, and reports in plain language. See “Why not just use a code scanner?” above for the full comparison.

Which tools and stacks are supported?

Apps built with Lovable, Bolt, Cursor, Replit, v0 or by hand, running on Supabase, Firebase, Vercel or Netlify and written in JavaScript or TypeScript. Support for additional stacks is on our roadmap.

Who is behind Ballast?

Ballast is built by AI Implementation Studio, a team of engineers based in Singapore who design and secure AI systems for growing companies.

Launch knowing it’s safe.

Request early access by email. Once approved, install our read-only GitHub App and get your first report within 24 hours.

Request early access

Reach out to us: admin@hoangtran.site