Managed security reviews for AI‑generated code
AI built your app.
Who checked it?
Ballast finds the mistakes AI coding tools ship with, like leaked keys, open databases and endpoints that can run up your bill. Each one comes in plain English, with a fix you paste straight back into your AI.
Early access is by request. Once approved, you install our read-only GitHub App in a few clicks. admin@hoangtran.site
- Read-only GitHub App
- Checks on every pull request
- Findings verified by an engineer
ballast scan acme-portal
- Scanning frontend code for secrets1 admin key exposed
- Checking database access rules3 of 12 tables open
- Testing API routes for login checks1 route unprotected
- Checking storage bucketsAll private
- Checking limits on AI endpointsNo limit on /api/chat
- Checking backups and dependenciesNo backups set up
Launch readiness
38/ 100
Not ready to launch, 3 critical, 2 high, 1 medium
Sound familiar?
The four worries we hear most from people shipping with AI, and what Ballast does about each one.
I can’t read the code, so I have no idea what’s exposed.
Plain-English report
Every finding says what’s wrong, what someone could do with it, and how urgent it is. No security background needed.
I’m scared of waking up to a $2,000 API bill.
Cost guard
We flag AI and API endpoints anyone can call without limits, and Pro alerts you the moment spend suddenly jumps.
Every time I ask the AI for a feature, something else breaks.
Checks on every pull request
Pro checks every pull request before it merges, so a fix that quietly comes undone is caught before it ships.
I’m launching next week and there’s no developer to ask.
Ultra: engineers on hand
On Ultra, our engineers walk through the report with you and fix the critical and high issues for you.
How Ballast works.
Request access, install a read-only GitHub App, and Ballast checks every change before it ships, with an engineer verifying what matters.
- 1
Request early access
Email admin@hoangtran.site with your app’s link and repository. We confirm you own the app, usually within one business day.
- 2
Install the GitHub App
Install the GitHub App with read-only access and choose your repositories. For live tests, add your project URL and public ballas key. We never ask for service-role keys.
- 3
Checks on every pull request
Ballast reviews your app in three layers. Code checks run on every pull request, and an engineer verifies live-app and access findings before they reach you.
- CodeEvery pull request: secrets, vulnerable dependencies and risky patterns.
- Live appOutside-in tests, such as reading tables with your public key, open storage and exposed files.
- Access testsTwo test accounts check whether one user can see another’s data.
- 4
Fix and verify
Fix prompts appear right on the pull request with Pro. On Ultra, your engineer consultant opens a fix pull request for you to approve. The next check confirms the fix.
Row-level security is off on the invoices table
Anyone with your public key can read every customer’s invoices.
Paste into Lovable, Cursor or Bolt
Enable row-level security on the invoices table in Supabase. Add policies so a signed-in user can only select, insert, update and delete rows where user_id = auth.uid(). Don’t change any other tables. When you’re done, show me the SQL you ran.
Enable row-level security on invoices #42
Awaiting your approvalballast/fix-invoices-rls → main
+ alter table public.invoices enable row level security; + create policy "Users manage own invoices" + on public.invoices for all + using (user_id = auth.uid()) + with check (user_id = auth.uid());
What Ballast checks.
Grouped by what could actually go wrong, not by security jargon. Free covers the three that leak data most often. Pro and Ultra run all eight.
Leaked secrets
In FreeAPI keys and admin credentials in your frontend code or repo history.
Risk: Someone uses your keys, and your bill.
Database access rules
In FreeRow-level security turned off, or rules that let any user see every row.
Risk: Anyone can read or edit your users’ data.
Missing login checks
API routes and server functions that never check who’s calling.
Risk: Users can open each other’s orders, invoices or messages.
Public storage
In FreeUpload, avatar and document buckets that anyone can list.
Risk: Private files end up downloadable by strangers.
Unlimited AI endpoints
Chat or generation endpoints with no rate limit or spending cap.
Risk: One script burns your monthly LLM budget overnight.
Prompt injection
User text that can rewrite your AI’s instructions or reach your tools.
Risk: Your assistant leaks data or does things it shouldn’t.
Risky dependencies
Packages with known vulnerabilities or no maintainer.
Risk: Attackers use a published exploit against you.
Launch basics
Backups, error monitoring, and separate test and live data.
Risk: One bad AI edit wipes real data with no way back.
Why not just use a code scanner?
Developer scanners read your code. Ballast checks what a stranger can actually reach in your live app, and explains how to fix it in words you understand.
- Built for
Developer scannersDevelopers and DevOps teams
Built-in builder checksUsers of that one platform
BallastFounders and builders, no code knowledge needed
- What it examines
Developer scannersCode, dependencies and containers
Built-in builder checksSettings inside its own platform
BallastYour code plus your live backend: database rules, storage and logins
- Tests what an outsider can reach
Developer scannersNot the main focus
Built-in builder checksUsually confirms a setting is on
BallastYes, by testing access the way an outsider would
- AI-specific risks (LLM costs, prompt injection)
Developer scannersNot the main focus
Built-in builder checksLimited
BallastBuilt into the 8 checks
- Setup
Developer scannersCLI or CI pipeline, plus rule tuning
Built-in builder checksAlready built in
BallastInstall a read-only GitHub App. We handle the rest
- Results
Developer scannersLong lists of technical alerts
Built-in builder checksAlerts in a dashboard
BallastA short, ranked list in plain language, with fix prompts
- Human help
Developer scannersYour own team
Built-in builder checksYour own team
BallastEngineer consultant on Ultra
Already use Snyk or SonarQube? Keep them. Ballast covers what they weren’t built to see.
Based on each category’s typical focus. Individual tools vary by plan and configuration.
A report you can actually read.
Switch between before and after to see the score climb as fixes go in.
Not ready to launch
acme-portal
Admin database key is in your frontend code
Anyone who opens your site can copy it and get full control of your database.
CriticalFixedRow-level security is off on 3 tables
invoices, profiles and messages can be read by anyone with your public key.
CriticalFixedAnyone can open other users’ orders
Changing the number in /api/orders/123 shows a stranger’s order.
HighFixedNo rate limit on /api/chat
A simple script could spend your monthly OpenAI budget in an hour.
HighFixedNo database backups set up
If an AI edit deletes data, there’s no copy to restore.
MediumFixed2 packages with known vulnerabilities
Low risk today. Update them when convenient.
Low
Sample report. Illustrative findings from a typical AI-built app.
Start free, upgrade when you need more.
Each plan includes everything in the one before it. Early access pricing: request access by email, then install the GitHub App.
Free
A security baseline before you launch.
$0forever
- 1 app monitored
- Monthly security scan
- 3 core checks: secrets, database access and storage
- Launch-readiness score
- Plain-language findings report
Early access price
Pro
Continuous protection as you keep shipping with AI.
$19per month
Everything in Free, plus
- Up to 3 apps monitored
- Checks on every pull request, plus unlimited scans
- All 8 security checks
- AI-ready fix prompt for every finding
- Alerts for new critical issues
- Pre-launch readiness checklist
- LLM and API spend monitoring (coming soon)
Ultra
Hands-on help from our security engineers.
$199per month
Everything in Pro, plus
- Up to 10 apps monitored
- Engineer consultant who fixes critical and high findings through pull requests
- Monthly 45-minute security review call
- Security sign-off letter for customers and investors
- Priority support with same-business-day response
Compare plans
| Feature | Free | Pro | Ultra |
|---|---|---|---|
| Apps monitored | 1 | 3 | 10 |
| Scan frequency | Monthly | Unlimited | Unlimited |
| Security checks | 3 core | All 8 | All 8 |
| Plain-language findings report | Included | Included | Included |
| AI-ready fix prompts | Not included | Included | Included |
| Checks on every pull request | Not included | Included | Included |
| Alerts for new critical issues | Not included | Included | Included |
| Engineer consultant | Not included | Not included | Included |
| Monthly review call and sign-off letter | Not included | Not included | Included |
| Support level | Standard | Standard | Priority |
Prices in USD. Cancel paid plans anytime. To start any plan, email admin@hoangtran.site.
We’re careful with your app, too.
Read-only by default
The GitHub App only reads the repositories you choose. Write access is needed only for Ultra fix pull requests, and only if you turn them on.
Scanned, then deleted
Code is scanned in an isolated environment and removed after your report. Ask us to delete your data anytime.
Every permission shown
GitHub lists exactly what the Ballast App can access before you install it, and you can remove it at any time.
Real engineers behind it
Built by a team that builds and secures AI systems for small companies.
Frequently asked questions.
How do I get started?
Email admin@hoangtran.site with a link to your app and repository. We confirm you own the app, then send an invitation to install the GitHub App. Your first report arrives within 24 hours of installation.
What do I need to install?
Only the GitHub App, installed from GitHub in a few clicks once your early access is approved. It has read-only access to the repositories you select. There is nothing to download and no separate account to manage. Results appear on your pull requests and in an emailed report.
How do Free, Pro and Ultra differ?
Free covers one app with a monthly scan across the three core checks. Pro covers up to three apps, runs all eight checks on every pull request and includes an AI-ready fix prompt for each finding. Ultra adds an engineer consultant who fixes critical and high findings through pull requests, along with a monthly security review call and a sign-off letter.
Do I need technical knowledge to use Ballast?
No. Every finding is written in plain language, with a clear explanation of the risk and how urgent it is. Pro and Ultra also include a fix prompt you can paste directly into the AI tool you already use.
Will Ballast make changes to my code or data?
Scanning is strictly read-only. On Free and Pro, you decide which fixes to apply and when. On Ultra, our engineers submit fixes as pull requests, and nothing is merged without your approval.
How do you handle my code and data?
Access is limited to what the scan requires, and you approve every permission before we connect. Code is scanned in an isolated environment and removed once your report is delivered. You can ask us to delete your data at any time.
My builder already includes a security scan. Why do I need Ballast?
Built-in scans are a useful first step, but they typically confirm that a setting is enabled rather than whether it actually protects your data. Ballast tests what an outsider could access in practice.
How does Ballast compare with Dependabot or Snyk?
Those tools are built for developers and focus mainly on code and third-party packages. Ballast also tests your live backend configuration and AI endpoints, and reports in plain language. See “Why not just use a code scanner?” above for the full comparison.
Which tools and stacks are supported?
Apps built with Lovable, Bolt, Cursor, Replit, v0 or by hand, running on Supabase, Firebase, Vercel or Netlify and written in JavaScript or TypeScript. Support for additional stacks is on our roadmap.
Who is behind Ballast?
Ballast is built by AI Implementation Studio, a team of engineers based in Singapore who design and secure AI systems for growing companies.