Built for AI-shipped apps

Know if your app is safe to launch.

NullFault scans your live app for leaked secrets, exposed configs, and missing protections — the mistakes AI-shipped apps make — before attackers find them.

No signup requiredRead-only accessCopy-paste fixes

See exactly what a scan returns

A readiness score, prioritized findings, and a ready-to-paste fix prompt for every issue.

Example report

https://your-app.com

Sample
42/ 100
Passive configuration auditAction required

1 critical issue blocks launch

Policy blockers
1
Critical
1
Findings
3
Checks run
25
  • Exposed .env file with live API keys

    Secret exposure

    Critical
  • Missing Content-Security-Policy header

    Security headers

    Medium
  • Public source maps reveal application source

    Source map exposure

    Low

Every finding ships with a ready-to-paste fix prompt for Copilot, Claude, or Cursor.

  1. Step 1

    Paste your URL

    No signup, no install, no agent. Just your live app's address.

  2. Step 2

    We scan, live

    Secrets, configs, headers, endpoints, and TLS — checked passively in real time.

  3. Step 3

    Get a readiness score

    Prioritized findings, each with a copy-paste fix prompt for your AI tools.

What NullFault finds

Every scan is passive and read-only — we look at what your live app already exposes to the public internet.

Leaked secrets & source

The mistakes that ship with AI-generated apps.

  • Exposed .env & API keys
  • Public .git & source maps
  • Readable client bundles
  • Hardcoded credentials

Security posture

The protections attackers check first.

  • Missing security headers
  • Weak auth & session cookies
  • CORS misconfiguration
  • TLS / HTTPS issues

Exposed surface

What you accidentally left reachable.

  • Leaked config files
  • Open debug & admin routes
  • GraphQL introspection
  • Tech & version fingerprint

Backend & AI exposure

The endpoints that cost you money.

  • Public Supabase / Firebase
  • Exposed AI endpoints
  • Unprotected API routes
  • Leaked service keys

Stop guessing. Know if your application is ready for production.

Run a free, read-only scan and see exactly what your live app exposes — no signup required.

Start free scan