Service 05 · AI Security

Only users can read the database. In theory.

Also promised, in theory: The keys aren’t in the bundle. The model only does its job. The rules got tightened after the demo. The defaults are safe.

The promises came with the build. Maybe the app is live, maybe the pilot stalled, maybe a vendor built it and handed you the keys. Either way you’ve had the thought: what else can this thing do, for someone who isn’t me? Good question. It deserves an answer before somebody else asks it.

Let’s talk
CLIENT APP API MODEL DATA KEYS PUBLIC NO RULES in the bundle? wide open placeholder · the security assessment

Every one of those breaches
started as a working app.

You’ve read the stories. The Tea app took off, and within days tens of thousands of user selfies and government IDs were spilling out of a storage bucket nobody had locked. CVE-2025-48757 documented the same gap as a genre: vibe-coded apps shipping with their databases readable by anyone who thought to ask. The pattern is public record and it keeps repeating, because the same tools keep building the same gaps.

These weren’t careless people, they were fast, and fast is a real advantage. But the tools that wrote the code care about one thing: does it work. Safe never came up.

The gap between working and safe is where the breach lives.

Secrets in the open

API keys pasted where the code needed them: the client bundle, the repo, a config file the whole internet can fetch.

The unlocked database

The demo needed permissive rules to work, and the rules never got tightened. Any signed-in user, sometimes any visitor at all, can read rows that were never theirs.

The model’s own door

If your product talks to a model, the model is an entrance. Prompt injection is a stranger talking your own AI into using its tools and its data on their behalf.

Dependencies nobody chose

AI picked the packages, the versions, and the defaults, and no human reviewed the choice. Whatever is wrong with them is now wrong with your product.

None of this means you built wrong. You built fast, and nobody has looked yet.

Someone is going to read your app
like an attacker. Let it be us.

AI is confident whether it’s right or wrong. The review exists to know the difference before someone hostile finds it for you.

01
Reviewread it like an attacker
We go through the system the way someone hostile would: the code, the config, the keys, the data paths, what the model is allowed to touch. Every finding gets ranked by what it would actually cost you. No theater, no hundred-page report of warnings that don’t matter.
02
Hardeningfix what the review found
The keys come out of the bundle, the database rules get tightened so a user only reads their own rows, the model gets scoped to its actual job, and dependencies get reviewed instead of inherited. You get every change with the reasoning behind it, so the next build doesn’t repeat the gap.
03
Watchbecause systems drift
Models change underneath you, dependencies update, a new feature reopens an old door. The watch keeps eyes on it: monitoring, alerts, and a named human who answers when something looks wrong. No orphans, and that includes security.

A security credential is a thing
you turned down. Here is ours.

For a decade at ShapeShift, this shop never touched customer key custody. That work was available and we did not take it: hold the keys and one mistake ends somebody else’s money with our name on it. The judgment was made against our own commercial interest, which is the only kind worth citing. The engagement is on the record, refusal included.

Behind that, the record it came from. We have shipped where being wrong costs money rather than embarrassment: an exchange from 2013, a lending platform holding collateral with Phil as fractional CTO through its launch, and fund rails moving real money for WallStreetBets. None of those were allowed to work only on the demo.

And we build with AI every day. That counts for more here than a certificate would: the tools that wrote your code are the tools that write ours, and we know where they cut corners because we watch them do it.

You can’t price a fix
you haven’t found.

01
Free Assessment$0 · two days
You tell us what you have and what worries you: a live app, a stalled pilot, a vendor build you inherited, a plan you haven’t run yet. Send context, not code, and never credentials. Two days later you have a straight answer, worth a scope or not. If not, we say so and you keep the answer.
02
Production Audit$5,000 · within 5 business days
The security review runs inside the scope: evidence, ranked findings, what to fix first, acceptance criteria, a hardening plan, signed. It stands alone; take it anywhere, including to someone else’s security team.
AI Securityreview · hardening · watch

The scope stands whether we do the fixes or not. Take the ranked findings to your own engineers or to another firm; the document is built to survive that trip. If you want the people who found the gaps to close them, hardening and watch are priced on the same page, and you decide with the list in hand.

Nothing you send is used to train any model. The scope runs under NDA, signed before any code moves. When the work is done, your artifacts are deleted on request.

Shipping production systems
since 2011.

Innovation Theory has been at this since 2011, through several waves of new tech. We were shipping production systems before AI wrote a line of code.

DISNEYPIXARUNIVERSALSHAPESHIFTSALTWALLSTREETBETS

25 years in the craft · 140+ engagements · in business since 2011

In theory, it’s secure.
Let’s find out.

Let’s find out

Ten minutes with Phil about what you have. A straight answer in two days, from the person whose name goes on the scope. Free. Send context, not code, and never credentials.

Think it’s already open? Don’t wait two days. First, revoke any key you believe is exposed; that costs nothing and closes the fastest door. Then email phil@innovationtheory.com with URGENT in the subject. That word puts it ahead of everything else on the desk.