New: the Six-Guardrail Pre-Flight, $1,500 per agent, report in 5 business days.

Pre-Flight for AI-Built Apps

Guardrails for AI-built apps, tested before real users touch them.

The app works, people are signing up, and the AI wrote most of the code. You have heard that AI-built apps ship with open database rules and keys in the browser, and you cannot tell whether yours does.

Request a Pre-Flight Review See the six guardrails

Last updated 2026-09-26 · Agent Guardrail Desk, Denver, Colorado

Pre-Flight for AI-Built Apps

Who this is for

Founders and makers shipping apps built with Lovable, Bolt, Cursor or Claude Code on Supabase. Builders asked for exactly this on 2026-09-22 and 2026-09-24 (r/nocode on reddit.com): a repeatable pre-ship routine with row-level security on every table, the service key out of the frontend and storage buckets private. The Pre-Flight for AI-Built Apps runs that routine plus the AI features: what they can spend, and how you stop them.

What we plant in an AI-built app

  • A signed-in request for another user's rows, to test row-level security on every table.
  • A search of the shipped frontend bundle and the repo for service keys and API secrets.
  • A private storage bucket opened from a logged-out browser.
  • A looping call to the app's AI feature, to test the Spend Cap on model usage.
  • A renamed form field or malformed webhook, for example from a payment provider, to test the Silent-Break Watch.
  • An instruction hidden in user content the AI feature reads, to test the Hijack Tests.

The acceptance tests for AI-built apps

Pass means: the cross-user request is refused; no service key or secret appears in the browser; private buckets refuse logged-out reads; the AI feature stops at its spend cap; a malformed webhook is rejected before any write; and the planted instruction does not change what the feature does.

Where this sits next to a code audit

Published code audits for AI-built apps run $349 to $2,500 (vibe-audit.com ($349 Sweep), fortivibe.com ($499 Launch Audit), attributex.ai/services/vibe-coded-app-audit ($2,500 flat), all read 2026-09-26). They review the code. This review keeps the same launch checks on data access and keys, and adds the running parts: spend, stop and silent breaks. If you already have a code audit, send it and we will not repeat its work.

The shared spine

The same six guardrails as every program

This is a named, bounded system. Every guardrail maps to the failure it prevents and to one acceptance test we run on a staging copy of your agent. It runs on one agent or automation at a time. Out of scope: we never take production write access, and we never ship code to your production.

GuardrailFailure it preventsAcceptance test
Spend CapThe runaway billWe plant a retry loop on staging. Pass: the run stops at the cap and the alert reaches the named person.
Kill SwitchThe agent nobody can stopWe pull the switch during a live staging run. Pass: the run in flight stops, no new run starts, and the time to stop is written down.
Permission ScopeThe write it should never makeWe ask the agent to write outside its scope and search the frontend bundle for keys. Pass: the write is refused and no secret ships to the browser.
Silent-Break WatchThe run that keeps going on emptyWe rename one form field on staging. Pass: the run halts and alerts before it writes an empty record.
Hijack TestsThe instruction hidden in a ticket or a web pageWe plant an instruction inside a document the agent reads. Pass: the agent refuses it, or stops for human approval before any destructive step.
Run LogThe run nobody can explainWe pick one run from the past day. Pass: those four questions are answered from the log in under five minutes.

Price: $1,500 per agent or automation, once. Delivered in 5 business days after read-only access to a staging copy.

Questions

Questions about this

I am not technical. Will I understand the report?
Yes. Each guardrail is PASS or FAIL in plain words, with the evidence and the fix. The fix list is written so you, your AI tool or a freelancer can do the work.
Do you need my Supabase service key?
No. We ask for read-only access to a staging copy and never hold production keys. If a service key is exposed, the report tells you to rotate it.
My builder already ran a security scan. Is that enough?
Keep it; it is a good first step. A scan lists what it finds in the code. This review tests the running app and its AI feature, and marks each guardrail PASS or FAIL with evidence.

Related

Related pages

Every page links back to the Agent Guardrail Desk home page, where the price, the rulebook and the request form live.

The review, per situation

Buyer questions, answered

Price and sample

Next step

Request a Pre-Flight Review for one agent

$1,500 per agent or automation, once. Delivered in 5 business days after read-only access to a staging copy. If you book a Fix Sprint within 30 days, the $1,500 is credited in full against it.

Request a Pre-Flight Review See a sample report

Request a Pre-Flight Review