guides
Everything we've written down
New here? Start with the checklist. The rest is sorted by what you'd search for: an idea, a key, your platform or your host. Looking for how to fix one specific finding? That's /fix.
Learn
/learn →The ideas behind the most common gaps, explained once, properly, with what to tell your agent.
API keys
/keys →Some keys are meant to sit in your front end. Others hand over your account. Each guide shows what the key looks like, whether it is safe to expose, and what to do if it leaked.
Platforms
/check →The platforms are usually solid. The app you built on top of them is a separate question. Pick yours to see what apps on that stack tend to miss, where the fix goes, and how to check your live site.
- Is your Lovable app secure?
- Is your Supabase app secure?
- Is your Replit app safe?
- Is your Netlify site safe?
- Is your Vercel app safe?
- Is the app Claude Code built secure?
- Is the app Cursor built secure?
- Is your Base44 app safe?
- Is your Bolt app secure?
- Is your v0 app secure?
- Is your Firebase app secure?
- Is the app Windsurf built secure?
Security headers
/headers →Every host sets response headers in a different place. Pick yours for a config block you can paste, then check the result on your live site.