A scan of a client codebase, headed Not launch ready: the top finding is a Supabase edge function any anonymous caller can run, with the evidence, why verify_jwt is not the fix, and a paste-ready prompt to fix it

Rhomn Scan

CLIENT

Rhomn Scan

YEAR

2026

INDUSTRY

Developer security

SERVICES

Product & SaaS

Key Highlights

Shipped fast, broken the same way every time

A huge number of apps are now built by people prompting an AI. They ship quickly and fail in the same predictable places: exposed keys, row-level security left off, unprotected API routes, no rate limit on paid model calls. The people shipping them often cannot audit their own code, and nobody else is looking before it goes live.

A rule is not done until it is proven

The first production rule reliably finds unauthenticated Supabase edge functions, a problem its own first draft missed ten times out of twelve because it trusted a token check as a security boundary when the key satisfying it ships in the browser bundle. The rewrite and its 34-case fixture set, mined from real codebases, is what turns a hunch into proof.

Audits for apps built by AI, without running their code

Rhomn Scan reads a codebase for security and launch-readiness problems across a set of scanners that share one rule contract and one engine, an engine structurally forbidden from executing anything it scans.

How a scan works

The path a person actually takes through it, start to finish.

  1. Run the scanner against your repo from the command line

  2. The engine reads every file and installs or executes nothing

  3. Rules match file and repo-wide patterns against known failures

  4. A free report shows the score and severity counts

  5. Unlock the full report with paste-ready fix prompts

Works

Explore More Works

The Pitaj assistant, ready to answer a question about doing business in Montenegro
Body Heal, image coming soon