I will security review your ai built or vibe coded app before launch

J
joshuapole
J
joshuapole
Joshua

About this gig

Built your app with Lovable, Bolt, Cursor, Replit or Claude? AI tools ship fast, but they repeat the same security mistakes: API keys in the frontend, open Supabase or Firebase rules, and API routes where one user can read another user's data.


I'm Joshua from Zenkai, an OSCP certified security specialist from the Netherlands. I review your app and tell you exactly what is wrong, how serious it is and how to fix it, in plain English.


WHAT I CHECK

  • Secrets and API keys exposed in code or the browser
  • Supabase RLS policies / Firebase security rules
  • Login, sessions and access control (can user A see user B's data?)
  • Security headers, HTTPS, cookies and CORS
  • Dependencies with known vulnerabilities


WHAT YOU GET

  • A clear PDF report, findings ranked Critical to Low
  • Copy-paste fixes for your stack
  • A short summary you can show to investors or customers


HOW IT WORKS

You give me read access to your repository (or a zip). I only work on your own app, within the scope we agree on. Testing a live app is only done with your written permission.


Message me your stack before ordering and I'll confirm it fits.

Get to know Joshua

Joshua

OSCP Certified Ethical Hacker Pentester

  • FromNetherlands
  • Member sinceJul 2018
  • Languages

    English, Dutch
I'm Joshua Pole, a cybersecurity specialist with over 3 years of experience. I perform professional penetration tests and vulnerability assessments for web applications and networks. I specialize in OSCP methodologies, clear reporting, and hands-on security advice. Ready to take your security to the next level!

My Portfolio