Heimdall
Heimdall ScanOpen Beta

Coded by AI.

Secured by Heimdall.

Find the security holes in your AI-built app.
Get the exact prompts that fix them.

No credit card requiredPro plan free during beta

Trusted by builders using

CursorCursor
v0v0
LovableLovable
BoltBolt
ReplitReplit
WindsurfWindsurf
Base44Base44
Claude CodeClaude Code
CodexCodex
DevinDevin
10x10x
TempoTempo
How it works

Connect your repo.
See what's broken.

heimdallscan.com/scan

Choose a repository to scan

Connect your GitHub and pick any repo. Heimdall handles the rest.

Select a repository…
Start Scan
1Step 1

Connect your repo

Sign in with GitHub and pick the repo you built. No installs, no config files, no terminal. The whole setup takes about ten seconds.

Works on private repos too — Heimdall only reads what you point it at.
Scanninguser/vibe-coded-app
0/12 · 0%
Exposed Secrets & API Keys
2s
.env File Exposure & Git Privacy
CORS Policy & Origin Security
HTTPS Enforcement & Secure Transport
Privacy Policy & Legal Trust
Terms of Service / Terms of Use
SEO & Social Visibility
Broken Access Control (IDOR)
PRO
Input Validation on API Routes
PRO
Password Hashing & Storage
PRO
Rate Limiting on API Routes
PRO
Unprotected Sensitive Routes
PRO
2Step 2

Heimdall scans your code

Heimdall runs every check in parallel: exposed API keys, broken auth, missing privacy policy, CORS holes, and a dozen more. You watch each one finish in real time.

A full scan takes about two minutes, even for big repos.
0/100

Could be better

A few real issues left.

Critical

Missing Ownership Check

src/app/api/history/get/route.ts · Broken Access Control (IDOR)

Critical

Missing Ownership Check

src/app/api/history/update/route.ts · Broken Access Control (IDOR)

Critical

Missing Ownership Check

src/app/api/history/save/route.ts · Broken Access Control (IDOR)

Warning

Missing Privacy Policy

src/app/layout.tsx · Privacy Policy & Legal Trust

3Step 3

Fix it with one paste

Every problem comes with a plain-English explanation and a ready-to-paste prompt for Cursor, Lovable, or Bolt. Copy, paste, done.

No security background needed — your AI tool handles the fix.
Coverage

What Heimdall checks.

A glimpse of the 17 checks that run on every scan.

Exposed Secrets & API Keys

Critical

.env File Exposure & Git Privacy

Critical

CORS Policy & Origin Security

Critical

HTTPS Enforcement & Secure Transport

Critical

Privacy Policy & Legal Trust

Warning

Terms of Service / Terms of Use

Warning
Why Heimdall

Built for how you actually code.

You move fast with Cursor, Lovable, Bolt, and v0. Heimdall makes sure nothing dangerous ships with your next deploy.

Catch the gap

Find what AI missed.

AI tools ship code fast, but they don't audit their own work. Heimdall checks for the gaps, misconfigs, and missing protections that slip through.

Scan results17 checks
Exposed API key
Critical
Missing auth check on /api/orders
Critical
Wildcard CORS origin
Warning
HTTPS enforcement
Clear
.env file ignored
Clear
Zero guesswork

Plain English, copy-paste fixes.

Every finding includes a fix prompt written for Cursor, Lovable, or Bolt. Paste, ship, move on.

Fix prompt
Copied

Add an ownership check to DELETE /api/orders/[id]so the route compares the order's owner with the session user before deleting.

Under two minutes

Ship without the 3am panic.

Exposed keys, missing auth checks, broken access control. The kind of stuff that blows up after launch. Caught before you push.

Under 2 minutes per scan
Read-only GitHub access
Your code is never stored
Transparent AI prompts
Pricing

Free to start. No credit card.

Basic
$0/month

Essential protection for side projects before they go live.

  • 3 scans per day
  • Core essentials checks
  • Fix prompts included
  • 1 repository
Free for Beta!
Pro
$19$0/month

Advanced hardening for shipping real products.

  • Everything in Basic
  • 5 pro scans per day
  • Advanced hardening checks
  • 3 repositories
Ultra
Coming soon

Total 360° integrity. No limits, no compromises.

  • Everything in Pro
  • Unlimited ultra scans
  • Full integrity & compliance
  • Unlimited repositories
Support

Frequently asked questions.

Is my code stored anywhere?

Is it safe to connect my GitHub account?

What languages and frameworks does it support?

How is this different from GitHub's built-in security scanning?

Will it find every vulnerability in my app?

I built with Lovable / Bolt / v0. Does Heimdall work with those?

More questions?

Ready to Save Your App?