Patchable

Free live session · 45 min · online

Your app works. But is it safe?

You shipped it with Lovable, Bolt or Cursor. In 45 minutes you’ll check it live, with us, and find out. No code, nothing to install.

Hosted by Ahmet Özışık & Leonardo Romanello. 10+ years building and securing production apps, in your ecosystem.

a-real-app.com/customers no login asked
NameEmailPhone
Kertu L.kertu@…+372 5…
Mikko S.mikko@…+358 4…
Anna T.anna@…+372 5…
+ 240 more people
A real app’s customer list, opened in a plain browser, no account, no password (we only changed the names). The first thing you’ll do in the session is run this exact check on your own app, and see what loads.
Date
Thu 16 July2026
Time
18:00 EESTTallinn / Helsinki
Length
45 min+ open Q&A
Seats
Limitedsmall live room

For people who build with

  • Lovable
  • Bolt
  • v0
  • Cursor
  • Claude Code
  • Replit

Apps built just like yours are already in the news, for leaking user data.

This has already happened, more than once. In the last year, apps built with the same tools and backends spilled their users’ data in public, because nobody checked the back door.

  • 170+

    Lovable apps readable by anyone

    Databases (user lists, home addresses, even secret keys) served to anyone with the public link, because row-level security was off by default. Lovable’s own scan called them safe. They weren’t.

    CVE-2025-48757 · NVD ↗

  • 72k

    Selfies & IDs, no password

    A dating-safety app left users’ verification photos in a bucket anyone could open. Days later, 1.1 million private messages leaked too. Backend: Firebase, set up the way the tools set it up.

    The “Tea” breach · Security.org ↗

  • 70%

    Shipped with the door open

    Seven in ten apps built this way ship with row-level security off on at least one table. The very first thing we check together.

    May 2025 study · The Next Web ↗

Every one was a founder who thought they were fine. Forty-five minutes is how you make sure you’re not next.

Three things you’ll learn at this session.

You already built the app — now we show you around it. What it’s actually made of, in plain words. A simple way to think about keeping it safe. And a few real examples so it all clicks. Every term explained as it comes up, nothing to prepare.

PART 01

The anatomy of a web app, in plain words

When someone opens your app, three things work together: the page in their browser, the machine doing the thinking, and the place your data lives. We’ll walk that map together and translate the jargon your AI keeps using — frontend, backend, database, keys. Ten minutes in, the words stop being mysterious.

What your app is made ofthe map
  • Frontend the page that runs in the visitor’s browser in their hands
  • Backend the machine that does the thinking and enforces the rules in your hands
  • Database where every user’s data actually lives worth protecting
Three parts, one rule: anything in the visitor’s hands can be read and changed by the visitor.

PART 02

How to approach web security

Simpler than it sounds. Security isn’t a list of hacks to memorize — it’s one question, asked out of habit: who can do this, and did I decide that on purpose? Once you have the habit, it comes free with every feature you ship after tonight.

The questions to ask, every timemindset
  • Who can read this? not who should — who actually can, right now
  • Who can change this? data, settings, other people’s accounts
  • What if I lie? about who I am, what I paid, what I’m allowed to do the one people forget
Three questions, no code. Ask them once per feature and you’re ahead of most funded startups.

PART 03

Where things go wrong, on real examples

Then we make it real, with the handful of spots AI tools genuinely tend to miss — like a database door left open, or a key shipped where anyone can copy it. None of them mean you built it wrong. Each takes about two minutes to check, and you’ll check your own app for every one, live.

Your app, signed outno account
FromPrivate message
anna@…“here’s my new home address…”
jaan@…“invoice attached — please don’t share”
+ every private message in the app
The kind of thing we’ll spot together — and once you’ve seen it, checking for it takes two minutes.

You don’t watch us check an app. You check yours, live, with two people who do this for a living telling you exactly what you’re looking at.

And when you fix what you find, you’ll know how to tell it’s actually fixed, not just that your AI said so.

45 minutes, your app open the whole time.

It’s a working session, not a lecture, with your own app on screen the whole time.

18:005 MIN

The back door nobody mentioned

Where your data really lives, and why AI tools ship that door open.

18:0515 MIN

Your first check, live

You open your app in a private window and see what a stranger can reach. The question you came with, answered.

18:2012 MIN

The other two, and how to trust a fix

The exposed key and the free-Pro leak, plus how to tell if your AI actually fixed it.

18:328 MIN

What you can handle, and when to call someone

The honest line between what you fix yourself and the few things that need a person. No pitch.

18:40OPEN END

Your app, your questions

Bring what you found. We stay till the questions run out.

Made for the person who built it themselves.

Come if you

  • Shipped something real with Lovable, Bolt, v0 or Cursor, with actual users.
  • Handle real sign-ups, payments or data on Supabase, Firebase or similar.
  • Can’t say “it’s safe” with a straight face, and want to fix that.

Skip it if you

  • Want a deep technical talk full of acronyms and threat models.
  • Already have a developer or security person who owns this.
  • Just want a scanner to run once and forget.

If you could build the app, you can check it. We explain every word as we use it.

Two people, not a platform.

We build production software for a living, and companies pay us to find the leaks in apps like yours, in the same ecosystem you’re building in. For 45 minutes it’s just the two of us on the line: small room, no sales team, and we stay till the last question.

Ahmet Özışık

Engineering · Tallinn

A decade-plus shipping production software; runs a Tallinn studio building for teams across Europe, the UK and the US, on systems that carry real money and user data.

ahmet.ee ↗

Leonardo Romanello

Product & security · Nordics

Shipped products across eight-plus Nordic-Baltic countries; co-founded and exited a venture-backed platform. Works where product meets security, where these leaks live.

leonardo.tech ↗

Honest answers, up front.

“I’m not technical. Will I actually follow this?”

Yes, it’s built for exactly you. Every check is clicking, not coding, and every term gets explained as it comes up. If you could build the app, you can check it.

“Can’t I just ask my AI to check it?”

It can help, but only with what you already know to ask, and you can’t prompt for a risk you’ve never heard of. The one-click “scan” buttons pass wide-open apps; that’s how 170+ Lovable apps stayed exposed. What you leave with isn’t a better prompt; it’s an eye for where and how these holes form, so you can spot them yourself on this app and the next, and tell whether any answer, from a tool or a person, is actually true.

“Do I have to show my app to anyone?”

No, you run the checks on your own screen; nobody sees it, not even us. Any live demo is our own broken app. Just have yours open in another tab, or watch and take the checklist home.

Right now you’re hoping your app is safe. Leave the session knowing.

Forty-five minutes against the alternative: finding out from an angry user, or never. Walk out able to check any app you build in two minutes: this one, and every one after.

Reserve a seat

Thursday 16 July · 18:00 EEST · online, live
Free · limited seats · bring your app · no pitch